Trojan

Trojan:Win32/Convagent!pz information

Malware Removal

The Trojan:Win32/Convagent!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Convagent!pz virus can do?

  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Convagent!pz?


File Info:

name: 6D2A9ECD74AB433AE338.mlw
path: /opt/CAPEv2/storage/binaries/56eef9284fabafeeb359bc1878b8ef5317be6e6c603d81536e61d11bbdecdb1f
crc32: ACEDCD52
md5: 6d2a9ecd74ab433ae338568c2f30bb9a
sha1: f868ce32f9e3e52a74397f5ed3e2ba127e2bcc83
sha256: 56eef9284fabafeeb359bc1878b8ef5317be6e6c603d81536e61d11bbdecdb1f
sha512: f643797e96d1619672008be3034eac765ffca214a930919f739178749eba0fdfaa46e8fff70fdbbdf8382a985efb01215325cf8b034eb11f411e6b9fc1e5d5e7
ssdeep: 192:njDnswT8MW//21hG5xD2q98SoTJl50TIUOCAW9glFE6hID9CRJghnnnnnnn:nI21hG5xDr9q8IRCyFmD9C4h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123321917ADD294F1FB16427400F96B7CA236CA4512F217A3EFB0CDB19E61265AB5E00F
sha3_384: ac6953f8b6aa8a7ddd8d30f3a4747fed9fdf280c6592fb6180d59cee51e04702454a09ac91830629b9f25eee46f516a9
ep_bytes: e88b080000e82908000033c0c3909090
timestamp: 2023-08-17 14:33:25

Version Info:

0: [No Data]

Trojan:Win32/Convagent!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
MicroWorld-eScanGen:Variant.Fragtor.334300
FireEyeGeneric.mg.6d2a9ecd74ab433a
SkyhighBehavesLike.Win32.Infected.lm
McAfeeGenericRXAA-AA!6D2A9ECD74AB
Cylanceunsafe
ZillyaTrojan.Convagent.Win32.42055
SangforTrojan.Win32.Convagent.V5q7
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
ArcabitTrojan.Fragtor.D519DC
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Fragtor.334300
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Fragtor.334300 (B)
F-SecureHeuristic.HEUR/AGEN.1362554
VIPREGen:Variant.Fragtor.334300
TrendMicroTROJ_GEN.R002C0DHH23
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1362554
Antiy-AVLTrojan/Win32.Convagent
Kingsoftmalware.kb.a.965
MicrosoftTrojan:Win32/Convagent!pz
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
GDataWin32.Trojan.PSE.11N2JTZ
GoogleDetected
ALYacGen:Variant.Fragtor.334300
MAXmalware (ai score=80)
MalwarebytesMalware.AI.868641679
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DHH23
RisingTrojan.Generic@AI.100 (RDML:tdbrs9JCEx4IyHZGIhvqBg)
IkarusAdWare.Win32.BlackMoon
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
BitDefenderThetaGen:NN.ZexaF.36792.amW@au1IZqc
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Convagent!pz?

Trojan:Win32/Convagent!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment