Trojan

About “Trojan.Agent.CYMY” infection

Malware Removal

The Trojan.Agent.CYMY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CYMY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Agent.CYMY?


File Info:

crc32: 941C6CE1
md5: 425e0be80c2029edadb113ae3ca29f18
name: 425E0BE80C2029EDADB113AE3CA29F18.mlw
sha1: cc14d999d2b2f52570861e9c0fbf946e36febbf4
sha256: 2166639f66a691c2e107445e3fda1e1dbbc93718f43b0f2709df5a80086282f4
sha512: 8452e5d063b649c2f9c5bed3adb0ed1545111dfda1e5c1ddfc5b2bf23c0503ab94c1496d15389ce33b3debd418e8369cd7d7bda19244ccaa1ac5def51b9ec766
ssdeep: 6144:PRxEEKVe9rtMuaD/LaHrtpoShl+bPYjtaZqOUW7+Ezi022v1ZBTyLT233q7UmTl:519sLQwShoscPJewtZ9yW330KZNR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C)Qihu 360 Software Co., Ltd. All rights reserved.
InternalName: 360TSLiveUpd.exe
FileVersion: 9,0,0,1000
CompanyName: QIHU 360 SOFTWARE CO. LIMITED
ProductName: 360 Total Security
ProductVersion: 9,0,0,1000
FileDescription: 360 ipdate Module
OriginalFilename: TSLiveUpd.exe
Translation: 0x0409 0x04b0

Trojan.Agent.CYMY also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052f4861 )
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.52148
CynetMalicious (score: 100)
ALYacTrojan.Agent.CYMY
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.68452
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0052f4861 )
Cybereasonmalicious.80c202
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.GGFU
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Cype-7077783-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.CYMY
NANO-AntivirusTrojan.Win32.Yakes.fawjmv
MicroWorld-eScanTrojan.Agent.CYMY
TencentMalware.Win32.Gencirc.10c8ba2e
Ad-AwareTrojan.Agent.CYMY
SophosMal/Generic-S
ComodoTrojWare.Win32.Yakes.FN@7ngy6d
BitDefenderThetaGen:NN.ZexaF.34294.Lq0@aWg5OBhi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.TRICKBOT.SMB.hp
McAfee-GW-EditionBehavesLike.Win32.Ransomware.jh
FireEyeGeneric.mg.425e0be80c2029ed
EmsisoftTrojan.Agent.CYMY (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.zox
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1109183
Antiy-AVLTrojan/Generic.ASMalwS.25EE965
MicrosoftTrojanDropper:Win32/Bunitu.G
GDataTrojan.Agent.CYMY
TACHYONTrojan/W32.Agent.622080.DC
AhnLab-V3Malware/Win32.Generic.R249169
Acronissuspicious
McAfeePacked-FEE!425E0BE80C20
MAXmalware (ai score=99)
VBA32BScope.Trojan.Yakes
MalwarebytesMalware.AI.4031647231
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMB.hp
RisingRansom.Locky!1.AE2E (CLASSIC)
YandexTrojan.Yakes!KD+BXs/Z8S8
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.GWSH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Agent.CYMY?

Trojan.Agent.CYMY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment