Trojan

Trojan.Agent.CYCO removal guide

Malware Removal

The Trojan.Agent.CYCO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CYCO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.corp-servers.ru
zonealarm.bit
ns2.corp-servers.ru
ransomware.bit

How to determine Trojan.Agent.CYCO?


File Info:

crc32: 0CB9D673
md5: 2515c12b08e580cd354928390ad8d39c
name: 2515C12B08E580CD354928390AD8D39C.mlw
sha1: a99048b9d2f33311df3705332110678bd7551ab6
sha256: 4e9fcad3c5492acf42e9259e6dbd949b9a50a4c06dbac4a20dcf9e7056747909
sha512: 8174df0852bb360cddd9ca50d78bcaa54fcdd9ec21dee4985e7f3f035d8b0aef54cfc47ac01d4938b1435fc6836b274589b405cfbdfb50ad5a18ec431e38d8ad
ssdeep: 6144:dbwcKGw4GcLzRr0G3+jC6AdRkgiWIE8LxkH/:Fwc4MnRwGOW6Gkq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.CYCO also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
MicroWorld-eScanTrojan.Agent.CYCO
FireEyeGeneric.mg.2515c12b08e580cd
CAT-QuickHealTrojan.Chapak.ZZ6
McAfeeGenericRXFE-EQ!2515C12B08E5
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.GandCrypt.j!c
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 003e58dd1 )
BitDefenderTrojan.Agent.CYCO
K7GWTrojan ( 003e58dd1 )
Cybereasonmalicious.b08e58
BitDefenderThetaGen:NN.ZexaF.34590.suX@aC3uBMj
CyrenW32/S-b2026db7!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Gandcrab-6552923-4
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.NeutrinoPOS.fanckt
ViRobotTrojan.Win32.GandCrab.Gen.A
TencentMalware.Win32.Gencirc.10b49355
Ad-AwareTrojan.Agent.CYCO
TACHYONRansom/W32.GandCrypt.303113
EmsisoftTrojan.Agent.CYCO (B)
ComodoTrojWare.Win32.Chapak.GF@7mc1zz
F-SecureTrojan.TR/AD.GandCrab.ciszu
ZillyaBackdoor.Mokes.Win32.1190
TrendMicroRansom_GANDCRAB.SMJS2
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A + Mal/Agent-AUL
IkarusTrojan.Crypt
JiangminTrojan.Chapak.gt
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.GandCrab.ciszu
Antiy-AVLTrojan[Banker]/Win32.NeutrinoPOS
MicrosoftRansom:Win32/GrandCrab.A
ArcabitTrojan.Agent.CYCO
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Agent.CYCO
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
VBA32BScope.Trojan.Chapak
ALYacTrojan.Agent.CYCO
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GFXY
TrendMicro-HouseCallRansom_GANDCRAB.SMJS2
RisingMalware.Strealer!8.1EF (RDMK:cmRtazpGDp57IVmbdh36PzgShWa4)
YandexTrojan.GandCrypt!nV/PCuPi1h4
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.BFJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.4ff

How to remove Trojan.Agent.CYCO?

Trojan.Agent.CYCO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment