Malware

Troj/Cycler-C removal tips

Malware Removal

The Troj/Cycler-C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Cycler-C virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Troj/Cycler-C?


File Info:

name: C320FB44686417BD3D58.mlw
path: /opt/CAPEv2/storage/binaries/2ef41b2949607182c8a9ee7968f4d525a71ecbe58a4bae113404875a3d57f862
crc32: 6BE3F6F5
md5: c320fb44686417bd3d5849a6262c775c
sha1: 0ee21c62a88f7668210c0c69bff35fda50ffa2c1
sha256: 2ef41b2949607182c8a9ee7968f4d525a71ecbe58a4bae113404875a3d57f862
sha512: e3eefd3a35942e6290cfb2f2330634e0fe2783c09c8ffe4ef161010557b4298b96af6f637f7274dccb30b88667f57b43ca0e7ba91ec953c6afa96dc5489ab0b1
ssdeep: 12288:6mXsloGuVgXgAZgL3YeGKLHdss8rb3VqGCS4cCIkKJajduhvHxb:6mRxlBLHdsn5vP4cCIejduRHR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D125B2A5D96A6B36F76BDA1F4D6E7939CB1123B7BE43B1CB0430E4C50562252AF0240F
sha3_384: c872faeeae739529da28aee7086bbcfb13d49f90fa8da265b7fef112506242ffa49bf0108ddd7e35045ae6f915e53065
ep_bytes: 558bec6aff68c880400068ac58400064
timestamp: 2009-12-11 21:31:37

Version Info:

0: [No Data]

Troj/Cycler-C also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.74189
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Downloader.dm
McAfeeGenericRXKA-HC!C320FB446864
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 001156081 )
K7AntiVirusTrojan-Downloader ( 001156081 )
BaiduWin32.Trojan-Clicker.Cycler.a
SymantecW32.Unruy.A
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Unruy.AY
APEXMalicious
TrendMicro-HouseCallTROJ_UNRUY.SMT
ClamAVWin.Downloader.Unruy-6988793-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.74189
NANO-AntivirusTrojan.Win32.GenKryptik.fnqhed
SUPERAntiSpywareTrojan.Agent/Gen-Unruy
AvastWin32:Unruy-AA [Trj]
TencentTrojan.Win32.Unruy.wa
EmsisoftTrojan.GenericKDZ.74189 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLC.Asdas.22
ZillyaDownloader.Unruy.Win32.7742
TrendMicroTROJ_UNRUY.SMT
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c320fb44686417bd
SophosTroj/Cycler-C
IkarusTrojan-Downloader.Win32.Unruy
JiangminTrojan.Generic.glpgv
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Unruy.U.gen!Eldorado
Antiy-AVLTrojan[Clicker]/Win32.Cycler
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Unruy!pz
XcitiumTrojWare.Win32.TrojanSpy.BZub.~IP@f810f
ArcabitTrojan.Generic.D121CD
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.RSIYTE
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Unruy.1355704
Acronissuspicious
VBA32Trojan.Azden
ALYacTrojan.GenericKDZ.74189
MAXmalware (ai score=87)
Cylanceunsafe
PandaGeneric Suspicious
RisingDownloader.Unruy!1.AE5E (CLASSIC)
YandexTrojan.GenAsa!S4Mv8DNs2+w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/UNRUY.BK!tr
BitDefenderThetaAI:Packer.62FDF2B81D
AVGWin32:Unruy-AA [Trj]
Cybereasonmalicious.468641
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Unruy.A(dyn)

How to remove Troj/Cycler-C?

Troj/Cycler-C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment