Trojan

UDS:Trojan-Dropper.Win32.Convagent (file analysis)

Malware Removal

The UDS:Trojan-Dropper.Win32.Convagent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Dropper.Win32.Convagent virus can do?

  • Dynamic (imported) function loading detected
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine UDS:Trojan-Dropper.Win32.Convagent?


File Info:

name: 8C7F7AB7B926AEF3452E.mlw
path: /opt/CAPEv2/storage/binaries/96a8d30576004e20dd2bc60b250bf90fb7d1fca02843a2bd84b396286a097232
crc32: 726F5FC4
md5: 8c7f7ab7b926aef3452e5d3e327a09ba
sha1: f74d7ad0e568dcdff7a66291b7553662e3edad47
sha256: 96a8d30576004e20dd2bc60b250bf90fb7d1fca02843a2bd84b396286a097232
sha512: ef8c326166efd0e8bd4e0c475db00e251d042d7912924ebb7445788eb7239eec3e00c03bad7c1e53ad3cb855429b8ff80c9d5d7889ad30eaa21deb0e0894a7df
ssdeep: 3072:xZ7NokRcbG0kB4JeKnXLUaRpQstA0CfZvpovQYtWSzjHEckt+/x53I:xZ7NJebcaJtXYacstABZvaQFEjkcO+jI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A704120868DDCB47C71E52BDC369A61423239A339243D2D7B8847283772B767AA1F753
sha3_384: 77f7d28943db64fcb9fcf6d34dfd4c8c125c25df68959c783daf60e2c42b61fe5c4843c0f1d97fac42426b80c77cf6c5
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-05-31 14:47:47

Version Info:

Translation: 0x0000 0x04b0
Comments: Keymaker
CompanyName: TEAM LAXiTY 2020
FileDescription: Keymaker
FileVersion: 1.0.0.0
InternalName: keygen.exe
LegalCopyright: Bauer Lindemann 2020
LegalTrademarks:
OriginalFilename: keygen.exe
ProductName: patch01
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

UDS:Trojan-Dropper.Win32.Convagent also known as:

LionicTrojan.Win32.Convagent.b!c
MicroWorld-eScanGen:Variant.MSILPerseus.188497
FireEyeGeneric.mg.8c7f7ab7b926aef3
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.MSILPerseus.188497
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.MSILPerseus.188497
K7AntiVirusUnwanted-Program ( 00536fff1 )
K7GWUnwanted-Program ( 00536fff1 )
CyrenW32/Application.MRLN-7571
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Keygen.AK potentially unsafe
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Tool.Msilperseus-7437353-0
KasperskyUDS:Trojan-Dropper.Win32.Convagent.gen
BitDefenderGen:Variant.MSILPerseus.188497
NANO-AntivirusTrojan.Win32.Convagent.iqlphs
AvastWin32:Malware-gen
SophosKeygen (PUA)
ZillyaDropper.Convagent.Win32.566
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Variant.MSILPerseus.188497 (B)
IkarusPUA.PSWTool.Chromepass
WebrootW32.Hacktool.Riskware
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmUDS:Trojan-Dropper.Win32.Convagent.gen
GDataMSIL.Application.Keygen.B
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C3492332
McAfeeGenericRXAA-FA!8C7F7AB7B926
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
MalwarebytesMachineLearning/Anomalous.95%
TrendMicro-HouseCallTROJ_GEN.R002H0CGR21
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:VpAd8gXFzR2NrhSw/BEVHA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZemsilF.34182.lm0@a8w4D8c
AVGWin32:Malware-gen
Cybereasonmalicious.7b926a
PandaTrj/GdSda.A

How to remove UDS:Trojan-Dropper.Win32.Convagent?

UDS:Trojan-Dropper.Win32.Convagent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment