<< Back to Top Threats
K7 Detection Name Affected OS Prevalence AV Definition Version
Spyware ( 005d15041 ) Windows Low 14.3.56838
MD5

ecb62929ff53c2f67271668d86b7c2e7

SHA256

956f7e8e156205b8cbf9b9f16bae0e43404641ad8feaaf5f59f8ba7c54f15e24

File Size

348,344 bytes

Packer Information

N/A

First Seen

27-08-2025

Last Seen

09-09-2026

Aliases

Convagent.gen

Behavior Details

1. Creates Registry:
Adds data
\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x03\x00\x01\x00\x01\x00\x01\x00\x16\x00\x00\x00\x00\x00\x00\x00,\x00\x00\x00\x00\x00\x00\x00:\x00:\x00{\x006\x004\x005\x00F\x00F\x000\x004\x000\x00-\x005\x000\x008\x001\x00-\x001\x000\x001\x00B\x00-\x009\x00F\x000\x008\x00-\x000\x000\x00A\x00A\x000\x000\x002\x00F\x009\x005\x004\x00E\x00}\x00>\x00 \x00 \x00\x00\x00\x16\x00\x00\x00\x00\x00\x00\x00M\x00i\x00c\x00r\x00o\x00s\x00o\x00f\x00t\x00 \x00E\x00d\x00g\x00e\x00.\x00l\x00n\x00k\x00>\x00 \x00|\x00\x00\x00
\x00\x00\x00\x00\x00\x00\x00s\x00u\x00m\x00m\x00a\x00.\x00l\x00o\x00g\x00>\x00 \x00 \x00\x00\x00\x14\x00\x00\x00\x00\x00\x00\x00L\x00e\x00g\x00a\x00c\x00y\x00_\x00P\x00r\x00o\x00j\x00e\x00c\x00t\x00_\x001\x00>\x00\\x00 \x00\x00\x00\x14\x00\x00\x00\x00\x00\x00\x00L\x00e\x00g\x00a\x00c\x00y\x00_\x00P\x00r\x00o\x00j\x00e\x00c\x00t\x00_\x002\x00>\x00\\x00 \x00\x00\x00\x14\x00\x00\x00\x00\x00\x00\x00L\x00e\x00g\x00a\x00c\x00y\x00_\x00P\x00r\x00o\x00j\x00e\x00c\x00t\x00_\x003\x00>\x00\\x00 \x00\x00\x00\x14\x00\x00\x00\x00\x00\x00\x00L\x00e\x00g\x00a\x00c\x00y\x00_\x00P\x00r\x00o\x00j\x00e\x00c\x00t\x00_\x004\x00>\x00\\x00 \x00\x00\x00\x14\x00\x00\x00\x00\x00\x00\x00L\x00e\x00g\x00a\x00c\x00y\x00_\x00P\x00r\x00o\x00j\x00e\x00c\x00t\x00_\x005\x00>\x00\\x00 \x00\x00\x00\x14\x00\x00\x00\x00\x00\x00\x00L\x00e\x00g\x00a\x00c\x00y\x00_\x00P\x00r\x00o\x00j\x00e\x00c\x00t\x00_\x006\x00>\x00\\x00 \x00\x00\x00\x14\x00\x00\x00\x00\x00\x00\x00L\x00
under
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop\IconLayouts
Adds data
\x00\x00\x00\x00\x19\x00\x00\x00h\x00\x00\x00

Removal Instructions

1. Update K7 security to the latest version.
2. Open Windows registry editor and delete the following keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop\IconLayouts
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\pzq.rkr
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\JumplistData\e39dcfcc-f3ff-414e-9505-881858e4d7c3
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\GlobalAssocChangedCounter
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count\HRZR_PGYFRFFVBA
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop\IconNameVersion
3. Restart the machine.