Trojan

Trojan.Agent.CSYO removal guide

Malware Removal

The Trojan.Agent.CSYO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CSYO virus can do?

  • Injection (inter-process)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Agent.CSYO?


File Info:

crc32: FEE0BA12
md5: 5ed8f2904cf634fd254528bc4e989149
name: 5ED8F2904CF634FD254528BC4E989149.mlw
sha1: f225ecf2471017db5b98c89310191a89332dd1b0
sha256: 5f2baa38a2db7657b7397ac8d1a618040a8931bfeb1a75ee91669f6f4aa3911e
sha512: 7a6c1c6fa1a726a9a9eae6558181edf2103c144f207e407de2a38044ef51a9565950f07dd7fb288efebe7d7c5fa518af0072090e32abf1b30159105c282f3413
ssdeep: 98304:gfmQrmlMuglv0bLCJ5+rE8161RnrLrIR0OCvtDdgo6N5a/3jp6mHA0xQBg8LO3yV:Ncmlxuj+g8ErLuvCTgokEbpPgJBg8iho
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: gggggggggg
InternalName: nnnnnnnnnnnn
FileVersion: 55.45.3.4138
LegalTrademarks: gfjhers
Comments: yyyyyyyyyy
ProductName: herths
ProgramID: twtrjtrh
ProductVersion: 466.554.53.73
FileDescription: ykkkkkkkkkkkkkkk
OriginalFilename: rrrrrrrrrrrrrrrr
Translation: 0x0c6b 0x04e4

Trojan.Agent.CSYO also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.InstallMonster.1549
CynetMalicious (score: 99)
CAT-QuickHealSwBndlr.InstlMnstr.YY1
ALYacTrojan.Agent.CSYO
CylanceUnsafe
ZillyaTrojan.Agent.Win32.872182
SangforTrojan.Win32.Save.a
Cybereasonmalicious.04cf63
CyrenW32/InstallMonster.KH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/InstallMonstr.UX potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Inject.aiaml
BitDefenderTrojan.Agent.CSYO
NANO-AntivirusTrojan.Win32.InstallMonster.ewujtn
MicroWorld-eScanTrojan.Agent.CSYO
TencentMalware.Win32.Gencirc.10b333e9
Ad-AwareTrojan.Agent.CSYO
SophosInstall Monster (PUA)
ComodoApplication.Win32.InstallMonster.UH@7gqlad
BitDefenderThetaAI:Packer.58D0A17916
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GKE21
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.tc
FireEyeGeneric.mg.5ed8f2904cf634fd
EmsisoftApplication.InstallMon (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.adtt
AviraADWARE/InstMonster.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.23FC24B
MicrosoftTrojan:Win32/Trickbot!ml
ArcabitTrojan.Agent.CSYO
GDataTrojan.Agent.CSYO
AhnLab-V3PUP/Win32.InstMonster.R217849
Acronissuspicious
McAfeeArtemis!5ED8F2904CF6
MAXmalware (ai score=97)
VBA32Trojan.Inject
MalwarebytesMalware.Heuristic.1003
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0GKE21
YandexTrojan.GenAsa!6akOkbAJZjs
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CTWA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Agent.CSYO?

Trojan.Agent.CSYO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment