Ransom

About “Ransom:Win32/Sherminator.YL” infection

Malware Removal

The Ransom:Win32/Sherminator.YL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Sherminator.YL virus can do?

  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Clears Windows events or logs
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Sherminator.YL?


File Info:

crc32: F01D6996
md5: c8b726b3a94820b7088cad7d78c53659
name: C8B726B3A94820B7088CAD7D78C53659.mlw
sha1: a81722336d3d670e1fdb63e9a10fa93587616d29
sha256: aa5b453aff1269c83e758e8bc49c1d9ca9dc858e0b9885d8d28133c844af25d7
sha512: 28e1644cf881b287b0784c180d7b18e2ebc496f47b83a58bc4790799c0dc412b45a8a4f627db1e855bf555ce59743cb9b194d66cc2435d48b2d36566744c0ff3
ssdeep: 384:zKaBbaT0KDL3BQjKPj1bZOSuOfyF5gJzRvRUrZO04IY2qZWpU+wQS39KATEL/k:KLxQjKPjOPgNRcqIVqZWFiKE6
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Sherminator.YL also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Generic.Malware.SBg.5BC020F7
FireEyeGeneric.mg.c8b726b3a94820b7
McAfeeArtemis!C8B726B3A948
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
BitDefenderDropped:Generic.Malware.SBg.5BC020F7
K7GWTrojan ( 0055676a1 )
K7AntiVirusTrojan ( 0055676a1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.AntiAV
AlibabaRansom:Win32/Sherminator.e4d9fa1e
NANO-AntivirusTrojan.Win32.AntiAV.fwesht
RisingTrojan.Filecoder!8.68 (CLOUD)
Ad-AwareDropped:Generic.Malware.SBg.5BC020F7
EmsisoftDropped:Generic.Malware.SBg.5BC020F7 (B)
ComodoMalware@#xfg7t5kgbc4n
F-SecureTrojan.TR/FileCoder.inpfr
DrWebTrojan.Encoder.29388
ZillyaTrojan.Filecoder.Win32.9976
McAfee-GW-EditionBehavesLike.Win32.Dropper.mm
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.AntiAV.bue
MaxSecureTrojan.Malware.425.susgen
AviraTR/FileCoder.inpfr
MAXmalware (ai score=85)
MicrosoftRansom:Win32/Sherminator.YL
ArcabitGeneric.Malware.SBg.5BC020F7
ZoneAlarmHEUR:Trojan.Win32.AntiAV
GDataDropped:Generic.Malware.SBg.5BC020F7
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3468644
BitDefenderThetaAI:Packer.8953A47A1E
ALYacDropped:Generic.Malware.SBg.5BC020F7
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32Win32/Filecoder.NXL
TencentWin32.Trojan.Filecoder.Taot
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Filecoder.NXL!tr.ransom
AVGWin32:Trojan-gen
Cybereasonmalicious.3a9482
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Anti.afe

How to remove Ransom:Win32/Sherminator.YL?

Ransom:Win32/Sherminator.YL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment