Trojan

Trojan:MSIL/Convagent!atmn removal instruction

Malware Removal

The Trojan:MSIL/Convagent!atmn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Convagent!atmn virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan:MSIL/Convagent!atmn?


File Info:

name: B333F7F26F63140F6BF3.mlw
path: /opt/CAPEv2/storage/binaries/e99e91ed4e661a4471956199c0e521445945101f4d28641a0a3d577616046ffe
crc32: 53E87C27
md5: b333f7f26f63140f6bf3f8716c67809e
sha1: 762d704ba382ff4ccdac879c0e6af4c59831c63d
sha256: e99e91ed4e661a4471956199c0e521445945101f4d28641a0a3d577616046ffe
sha512: 1581f04d62ba1369776283ad9deeee648ccc77e97f733a55452a2fa2b04d83ca4b3d8202dec8e1c808e534c9f27fb3326475178b16e79ce05fb9906574110bfc
ssdeep: 96:dwUQ7fODU9Rl1ra5MLGTXw2jWjP+5/zcWdSpH27GnfcJU/SW5PfXth5wKtK5K:d/UdD+5BXLGG5oH6G0k53XqKE5K
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T185F10A06A7FA0146E0BFCB7C5DF19685D1BAF226AF17E71F2C91828D18732610F51A74
sha3_384: 857078bede4d35975484f74cbe02c97e526c1c92c057d0e328c4935b01a094ebf9a0260e6103da81dd8a2dc9335a98cb
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-11-28 03:18:24

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: fqhbfkdi.dll
LegalCopyright:
OriginalFilename: fqhbfkdi.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan:MSIL/Convagent!atmn also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Rozena.4!c
AVGWin32:TrojanX-gen [Trj]
DrWebTrojan.InjectNET.47
MicroWorld-eScanGen:Variant.Tedy.125806
FireEyeGeneric.mg.b333f7f26f63140f
CAT-QuickHealTrojan.SabsikFC.S24736384
SkyhighGenericRXOD-HW!B333F7F26F63
McAfeeGenericRXOD-HW!B333F7F26F63
MalwarebytesTrojan.Injector
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005aafeb1 )
AlibabaTrojan:MSIL/Convagent.56ed6cea
K7GWTrojan ( 005aafeb1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Rozena.W
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.Rozena-9918685-0
KasperskyHEUR:Trojan.MSIL.Convagent.gen
BitDefenderGen:Variant.Tedy.125806
NANO-AntivirusTrojan.Win32.Convagent.kerkau
EmsisoftGen:Variant.Tedy.125806 (B)
F-SecureTrojan.TR/Rozena.uisff
ZillyaTrojan.RozenaGen.Win32.1
TrendMicroTROJ_GEN.R002C0DL123
SophosTroj/Rozena-AD
IkarusTrojan.MSIL.Rozena
GDataMSIL.Backdoor.Rozena.H
VaristW32/Rozena.DE.gen!Eldorado
AviraTR/Rozena.uisff
MAXmalware (ai score=85)
ArcabitTrojan.Tedy.D1EB6E
ZoneAlarmHEUR:Trojan.MSIL.Convagent.gen
MicrosoftTrojan:MSIL/Convagent!atmn
GoogleDetected
AhnLab-V3Trojan/Win.HW.C4704805
Acronissuspicious
ALYacGen:Variant.Tedy.125806
TACHYONTrojan/W32.DN-Convagent.7680
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DL123
TencentTrojan.MSIL.Rozena.ha
YandexTrojan.Convagent!siDLrpdwh7w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Rozena.W!tr
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Convagent!atmn?

Trojan:MSIL/Convagent!atmn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment