Crack

VHO:HackTool.Win32.Convagent removal

Malware Removal

The VHO:HackTool.Win32.Convagent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:HackTool.Win32.Convagent virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Anomalous binary characteristics

How to determine VHO:HackTool.Win32.Convagent?


File Info:

crc32: 79261BF0
md5: 587254f69634635fe2dbc23abf33df60
name: 587254F69634635FE2DBC23ABF33DF60.mlw
sha1: 5affb654e8e7fb6c501cb79d7915f7e36a638daf
sha256: 398e3395f45261109aad3bd45f1fe6cb9dc4ca0f6aaefc29e3a8e3e10b6abffb
sha512: f801e8caf5423732c5d935f02b5e0890c6ac78d76b0ece9c791c510aef5edccf3abde47d7ac0c6551facd893649806d2c76ebf498348c5aaef7a981e00263fa5
ssdeep: 49152:B6papF/l2d0uVRlxC/zhlm3+qCAOctMd8Ja:wE/8d0eRlxSj4+qTjWdL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x6d3ex5927x661fQQ:892369441
FileVersion: 4.3.1.1
CompanyName: x6d3ex5927x661fQQ:892369441
Comments: x6d3ex5927x661fx96f7x7535x591ax5f00x52a9x624b
ProductName: x6d3ex5927x661fx96f7x7535x591ax5f00x52a9x624b
ProductVersion: 4.3.1.1
FileDescription: x6d3ex5927x661fx96f7x7535x591ax5f00x52a9x624b
Translation: 0x0804 0x04b0

VHO:HackTool.Win32.Convagent also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Tonmye.2cbdce23
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4e8e7f
CyrenW32/Fujack.U
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyVHO:HackTool.Win32.Convagent.gen
ViRobotBackdoor.Win32.IRCBot.35288
SophosMal/Generic-S
ComodoTrojWare.Win32.Spy.KeyLogger.~P@19qrg4
BitDefenderThetaGen:NN.ZexaF.34690.0j0aa0O3Jlhb
VIPRETrojan.Crypt.AntiSig.b (v)
TrendMicroTROJ_GEN.R005C0DEG21
McAfee-GW-EditionBehavesLike.Win32.VirRansom.tc
FireEyeGeneric.mg.587254f69634635f
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Tonmye.gen!A
GridinsoftTrojan.Heur!.038120E1
AhnLab-V3Win32/MalPackedB.suspicious
McAfeeDownloader-BOP.f!rootkit
VBA32BScope.Trojan.Downloader
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0DEG21
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazprW9BJCiIzmAwLbPuIPuGW)
YandexPacked/RLPack
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/BOP_f.ROOTKIT!tr.dldr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove VHO:HackTool.Win32.Convagent?

VHO:HackTool.Win32.Convagent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment