Ransom Trojan

VHO:Trojan-Ransom.Win32.Convagent malicious file

Malware Removal

The VHO:Trojan-Ransom.Win32.Convagent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-Ransom.Win32.Convagent virus can do?

  • A process created a hidden window
  • Drops a binary and executes it
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine VHO:Trojan-Ransom.Win32.Convagent?


File Info:

crc32: D831D07C
md5: b1ad9afd96168db991f79eb546d6b79a
name: B1AD9AFD96168DB991F79EB546D6B79A.mlw
sha1: 9fbfbe72774b9cc3d174daa7b8be76bf8cb57ecf
sha256: 307a8158e698680c7186e3c1481b29186d8b265bb83662397a54f235b0c9a3d1
sha512: 677f25200f29b010895a335ac2171fdea359e9d59d4f91fa2d8c46b89c9933582f3e46ecf0026e4fb247d5acb430d74fec54368f7e27e74ff201385b77e65d13
ssdeep: 1536:wGqpGHfxs9iP3lFHij/2iuf5FCKf9JrOQeNgAY1xZx56tmb1j2RI9afG2ErdQMs:ZzzHGWffic9zZx56cb1q6jJ6cxT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VHO:Trojan-Ransom.Win32.Convagent also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Mikey.118406
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.d96168
ESET-NOD32a variant of Win32/Filecoder.Ryuk.N
APEXMalicious
AvastWin32:Ryuk-A [Trj]
KasperskyVHO:Trojan-Ransom.Win32.Convagent.gen
BitDefenderGen:Variant.Mikey.118406
MicroWorld-eScanGen:Variant.Mikey.118406
Ad-AwareGen:Variant.Mikey.118406
SophosML/PE-A + Troj/Ryuk-BH
BitDefenderThetaGen:NN.ZexaF.34670.jqW@aSNhp3b
McAfee-GW-EditionRansom-Ryuk!B1AD9AFD9616
FireEyeGeneric.mg.b1ad9afd96168db9
EmsisoftGen:Variant.Mikey.118406 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Ruyk.A!ibt
ArcabitTrojan.Mikey.D1CE86
GDataGen:Variant.Mikey.118406
AhnLab-V3Trojan/Win.Ryukran.R374607
McAfeeRansom-Ryuk!B1AD9AFD9616
MAXmalware (ai score=81)
MalwarebytesMachineLearning/Anomalous.100%
RisingMalware.Heuristic!ET#81% (RDMK:cmRtazq4j8py0TxMP4xq9ijXdQOE)
IkarusTrojan-Ransom.Ryuk
FortinetW32/Mikey.118406!tr.ransom
AVGWin32:Ryuk-A [Trj]
Qihoo-360HEUR/QVM10.1.6793.Malware.Gen

How to remove VHO:Trojan-Ransom.Win32.Convagent?

VHO:Trojan-Ransom.Win32.Convagent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment