Trojan

How to remove “Trojan:Win32/Cystea”?

Malware Removal

The Trojan:Win32/Cystea is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cystea virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools

How to determine Trojan:Win32/Cystea?


File Info:

crc32: BDF0664E
md5: e34cf17871b7476a1cd064a3a7043224
name: E34CF17871B7476A1CD064A3A7043224.mlw
sha1: b04faf953fa9a35fd4ac4c506df6f168f90d3cac
sha256: 083e096c90ce5dcbcce2e47f9992f3debf1bc468e3c4998d355432be88382e7a
sha512: b1486c917f6a034577d623dfe8051363abd3bdcf1841153663690ea21c825a327ed69590b1991fc031dbce639b2b2a159fe81b63b896954846fd48b705ff916a
ssdeep: 6144:a9VF/aEGWgAsk5eQdcSYclhPeOyzDM0hyL6oHG1AZ:EVF/lGWgAsk5eQdcSNgzDM0cRZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) Ubisoft
InternalName: Uplay game launcher
FileVersion: 3.0.1.1
CompanyName: Ubisoft
LegalTrademarks1: Ubisoft Uplay
LegalTrademarks2: Ubisoft Uplay launcher
ProductName: Uplay
ProductVersion: 3.0.1.1
FileDescription: Uplay launcher
OriginalFilename: upc.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Cystea also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004d3c641 )
Elasticmalicious (high confidence)
DrWebTrojan.Swrort.41
McAfeeGeneric Trojan.bz
CylanceUnsafe
ZillyaTrojan.Rozena.Win32.59006
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Snojan.d5fba677
K7GWTrojan ( 004d3c641 )
Cybereasonmalicious.871b74
SymantecTrojan.Gen.2
ESET-NOD32Win32/Rozena.PP
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Snojan.bmxl
BitDefenderTrojan.GenericKD.5230110
NANO-AntivirusTrojan.Win32.Snojan.epqqrq
MicroWorld-eScanTrojan.GenericKD.5230110
TencentWin32.Trojan.Snojan.Ahya
Ad-AwareTrojan.GenericKD.5230110
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34678.pq0@ayq40Zgi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.StartPage.dh
FireEyeGeneric.mg.e34cf17871b7476a
EmsisoftTrojan.GenericKD.5230110 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1127900
MicrosoftTrojan:Win32/Cystea
AegisLabTrojan.Win32.Snojan.4!c
GDataTrojan.GenericKD.5230110
AhnLab-V3Win-Trojan/Sagecrypt.Gen
Acronissuspicious
VBA32Trojan.Snojan
MAXmalware (ai score=100)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DDG21
RisingTrojan.Rozena!8.6D (CLOUD)
IkarusTrojan-Ransom.GandCrab
eGambitUnsafe.AI_Score_99%
FortinetW32/Rozena.PP!tr
AVGWin32:Malware-gen

How to remove Trojan:Win32/Cystea?

Trojan:Win32/Cystea removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment