Worm

Worm.ConvagentRI.S26707679 malicious file

Malware Removal

The Worm.ConvagentRI.S26707679 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.ConvagentRI.S26707679 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Worm.ConvagentRI.S26707679?


File Info:

name: 37C030456818878AF1DC.mlw
path: /opt/CAPEv2/storage/binaries/25f87c65a793186c7a9e1d8680ad7f32acb9bae4cb7284b98781b3a15f810ba2
crc32: 40B85A25
md5: 37c030456818878af1dc8ce7928a504f
sha1: c084099d00921d9a0fd4d95b0affbb70b8ed345f
sha256: 25f87c65a793186c7a9e1d8680ad7f32acb9bae4cb7284b98781b3a15f810ba2
sha512: 71be4c0afc937a51f42eb27da185d0399ef4ea58edca07d9230d17cec19f659f4beb5b0b72d7b584dea68c960e67f2d85cf2f7708de4ce22b462244e75448f36
ssdeep: 6144:r7F8IqhvzRG1HWgbMMyd6/CcDFLe8Ys4NU5IQPcq8Xdd0XnwzPUEyDsiIgq2RsVn:r7F8tvzhdnkRnwzLV0e+txKXBt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A946D03B7428092C4D277FD9891932955782A782FB588C3EEF99F51BD650F2D336A0B
sha3_384: fa4c06632af5234fd2e037074b06785135427f9779f62fadd1d082a8ba28b71180d08627b724aa4f71e6f269e28d1e69
ep_bytes: e89b9f0100e8449e010033c0c3909090
timestamp: 2020-09-22 16:29:21

Version Info:

FileVersion: 1.0.0.0
FileDescription: Clinent Server Runtime Process
ProductName: Clinent Server Runtime Process
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: Clinent Server Runtime Process
Translation: 0x0804 0x04b0

Worm.ConvagentRI.S26707679 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Scar.mip4
MicroWorld-eScanTrojan.GenericKD.39239564
FireEyeGeneric.mg.37c030456818878a
CAT-QuickHealWorm.ConvagentRI.S26707679
ALYacTrojan.GenericKD.39239564
CylanceUnsafe
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusAdware ( 00506e8d1 )
AlibabaBackdoor:Win32/BLACKMOON.7df6ced4
K7GWAdware ( 00506e8d1 )
Cybereasonmalicious.568188
CyrenW32/Trojan.RKFY-7371
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderTrojan.GenericKD.39239564
NANO-AntivirusTrojan.Win32.iarcnl.jmurdb
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Malware.Vukj
Ad-AwareTrojan.GenericKD.39239564
EmsisoftTrojan.GenericKD.39239564 (B)
ComodoMalware@#icvns4f77ajl
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.BlackMoon.15
ZillyaDropper.BlackMoon.Win32.1
TrendMicroBackdoor.Win32.BLACKMOON.E
McAfee-GW-EditionGenericRXRR-CM!37C030456818
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusBackdoor.BlackMoon
GDataWin32.Trojan.Agent.WP
JiangminBackdoor.Agent.kdb
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=87)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D256BF8C
ZoneAlarmUDS:Trojan.Multi.GenericML.xnet
MicrosoftPWS:Win32/Zbot!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R357556
Acronissuspicious
McAfeeGenericRXRR-CM!37C030456818
VBA32BScope.TrojanPSW.QQPass
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallBackdoor.Win32.BLACKMOON.E
RisingTrojan.DDOS!1.D540 (CLASSIC)
YandexRiskware.BlackMoon!PN8EEJhPfio
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.110599047.susgen
FortinetW32/Agent.WP!tr
BitDefenderThetaGen:NN.ZexaF.34742.Aq0@aWmlqhpb
AVGWin32:TrojanX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.ConvagentRI.S26707679?

Worm.ConvagentRI.S26707679 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment