Trojan

How to remove “Trojan:MSIL/Convagent!atmn”?

Malware Removal

The Trojan:MSIL/Convagent!atmn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Convagent!atmn virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan:MSIL/Convagent!atmn?


File Info:

name: 4095C88BC84D7B0B232C.mlw
path: /opt/CAPEv2/storage/binaries/b38d09dbe97abb2a4334c14f1b37569956a6116c8d2c6e416a907c1f29689a3a
crc32: 6208B8E3
md5: 4095c88bc84d7b0b232c2123d5c64a45
sha1: 0a6322aee6d77ab15c10b7b6e4b4c1dc956d80ad
sha256: b38d09dbe97abb2a4334c14f1b37569956a6116c8d2c6e416a907c1f29689a3a
sha512: a85b7909b47990b6722b7e6e90272f64d45c06a1a4a9c4f86ea4b9597606aa6b55a6e8e61ab2508397b82344f37da8bb1a7ed15c15d6131f7b73a273b762f00e
ssdeep: 96:SwUQ7fODU9Rl1ra5MLGyXwdjWjP+5/zcWdSpH27GnfcJU/SW5PfXWh51YKE:S/UdD+54XcGG5oH6G0k53XY
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T145F1FA06A7FA0146F0BFCB3C5DF19686D1BAF226AF17E61F2C91428D18732610F51A78
sha3_384: 35af2de34e29928fd9c1354e55f2c9b0848d96aa2c5b645292aef19b3cb62f607b88a60e39ee4f465ea50c049d1a5b84
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-02-05 02:19:25

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: qlprdlwx.dll
LegalCopyright:
OriginalFilename: qlprdlwx.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan:MSIL/Convagent!atmn also known as:

BkavW32.AIDetectMalware.CS
DrWebTrojan.InjectNET.47
MicroWorld-eScanGen:Variant.Tedy.125806
ClamAVWin.Packed.Rozena-9918685-0
FireEyeGeneric.mg.4095c88bc84d7b0b
CAT-QuickHealTrojan.SabsikFC.S24736384
SkyhighGenericRXOD-HW!4095C88BC84D
McAfeeGenericRXOD-HW!4095C88BC84D
MalwarebytesTrojan.Injector
VIPREGen:Variant.Tedy.125806
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005aafeb1 )
K7GWTrojan ( 005aafeb1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Rozena.W
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Convagent.gen
BitDefenderGen:Variant.Tedy.125806
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.MSIL.Rozena.ha
EmsisoftGen:Variant.Tedy.125806 (B)
F-SecureTrojan.TR/Rozena.zxheg
ZillyaTrojan.RozenaGen.Win32.1
TrendMicroTROJ_GEN.R011C0DB624
SophosTroj/Rozena-AD
SentinelOneStatic AI – Malicious PE
GDataMSIL.Backdoor.Rozena.H
GoogleDetected
AviraTR/Rozena.zxheg
MAXmalware (ai score=81)
ArcabitTrojan.Tedy.D1EB6E
ZoneAlarmHEUR:Trojan.MSIL.Convagent.gen
MicrosoftTrojan:MSIL/Convagent!atmn
VaristW32/Rozena.DE.gen!Eldorado
AhnLab-V3Trojan/Win.HW.C4704805
Acronissuspicious
ALYacGen:Variant.Tedy.125806
TACHYONTrojan/W32.DN-Convagent.7680
TrendMicro-HouseCallTROJ_GEN.R011C0DB624
RisingTrojan.Rozena!8.6D (TOPIS:E0:M0yOjyJxokM)
IkarusTrojan.MSIL.Rozena
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Rozena.W!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Convagent!atmn?

Trojan:MSIL/Convagent!atmn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment