Trojan

Trojan.Agent.CSTA information

Malware Removal

The Trojan.Agent.CSTA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CSTA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.CSTA?


File Info:

name: BA3040A7F55857D22440.mlw
path: /opt/CAPEv2/storage/binaries/44ac5cfa51b5e3ad201a569fb721212616c215ac22190de73e3877e4358bbe4f
crc32: BB4E08CA
md5: ba3040a7f55857d224401c46fc98ad56
sha1: 7f497e614eba670ca01974b693c846bda9cee648
sha256: 44ac5cfa51b5e3ad201a569fb721212616c215ac22190de73e3877e4358bbe4f
sha512: 661b7c915ca1935ec29bbbfcf666c1b7750ca054f861d9023a7add51a5af580665537bf8f3801c8348314bab88a6876d1d73cb11d47e5a836a834b5116210ab0
ssdeep: 12288:P4EcAtbb2MOXOTLwpANrGZlmQUOb1RvpDb37pMqksit8:P4K96OndUZnjvpHr3at8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143F412023EC1C831F5B258754862C96926BFFE825F3619EB276C132F4F362C15D3AA59
sha3_384: e2fc0051545935aa664f1ea5991851509b408cefd981e686cb10b65b6161f93f5d330625ce195e2ed9e702d4fdda84d4
ep_bytes: e831060000e98efeffff558beceb1fff
timestamp: 2018-01-03 12:34:13

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
LegalCopyright: Copyright (C) 2018
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0419 0x04b0

Trojan.Agent.CSTA also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Generic.2!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.CSTA
FireEyeGeneric.mg.ba3040a7f55857d2
CAT-QuickHealAdware.StartSurf.S1791958
SkyhighBehavesLike.Win32.Backdoor.bc
ALYacTrojan.Agent.CSTA
Cylanceunsafe
VIPRETrojan.Agent.CSTA
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaAdWare:Win32/StartSurf.8768346c
K7GWTrojan ( 005180831 )
K7AntiVirusTrojan ( 00528e801 )
ArcabitTrojan.Agent.CSTA
BitDefenderThetaGen:NN.ZexaF.36744.SC0@aKcSAUek
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GBXI
APEXMalicious
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.Agent.CSTA
NANO-AntivirusRiskware.Win32.StartSurf.ewtnvz
AvastWin32:AdwareX-gen [Adw]
TencentMalware.Win32.Gencirc.10b0e007
EmsisoftTrojan.Agent.CSTA (B)
DrWebTrojan.Vittalia.13960
ZillyaAdware.Generic.Win32.19696
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.alb
WebrootW32.Adware.Gen
GoogleDetected
Antiy-AVLGrayWare[AdWare]/Win32.AGeneric
KingsoftWin32.HeurC.KVMH008.a
XcitiumApplication.Win32.IStartSurf.IK@7ghatp
MicrosoftSoftwareBundler:Win32/Prepscram
ZoneAlarmHEUR:Trojan.Win32.Chapak.gen
GDataTrojan.Agent.CSTA
VaristW32/StartSurf.AJ.gen!Eldorado
AhnLab-V3Adware/Win32.StartSurf.R217150
McAfeePacked-XC!BA3040A7F558
MAXmalware (ai score=96)
VBA32AdWare.StartSurf
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!8.8 (TFE:1:SJju7ecrDTP)
YandexTrojan.GenAsa!b/R4FF0ZVOA
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.3771246.susgen
FortinetW32/Kryptik.GBXI!tr
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.14eba6
DeepInstinctMALICIOUS

How to remove Trojan.Agent.CSTA?

Trojan.Agent.CSTA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment