Ransom Trojan

Trojan.Ransom.Cerber.YN removal guide

Malware Removal

The Trojan.Ransom.Cerber.YN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Cerber.YN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Writes a potential ransom message to disk
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system

How to determine Trojan.Ransom.Cerber.YN?


File Info:

crc32: A499696A
md5: 1a46c52f37a8ae38537ec8aac6c7bac2
name: 1A46C52F37A8AE38537EC8AAC6C7BAC2.mlw
sha1: eecc99dd3bb7e0fdaca31d79ff3ac40293b62c0e
sha256: 8c9d608e3e4b7c471cfa1e2118b8c8c68264e8f23ca50d8478a23f149d9fb294
sha512: 4e5d60a2869fd63270e4ca232da0eebdb65d76c491eec381a9548a96a11c23da9ee6ccea46160ee5c8eef732a285f7f9b422672accfb9857fdd0dcf8be5edb6d
ssdeep: 3072:njUY89G+MeuxxUAWEA0arFbWqOVoJ0x4nzU6Dk+N154+:nOGz5UAWEA0arkqOVk0x4Y6Dn154
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.Cerber.YN also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00515aa21 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber.YN
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1221013
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 00511ee51 )
Cybereasonmalicious.f37a8a
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.FUHX
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Generic-6332606-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.YN
NANO-AntivirusTrojan.Win32.Zerber.ergxmz
MicroWorld-eScanTrojan.Ransom.Cerber.YN
TencentMalware.Win32.Gencirc.10b52f4d
Ad-AwareTrojan.Ransom.Cerber.YN
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Ransom.Zerber.FUHX@7cc22m
BitDefenderThetaGen:NN.ZexaF.34608.qyW@a4yYzYni
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMALY0
McAfee-GW-EditionBehavesLike.Win32.Worm.dc
FireEyeGeneric.mg.1a46c52f37a8ae38
EmsisoftTrojan.Ransom.Cerber.YN (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1109523
eGambitUnsafe.AI_Score_95%
MicrosoftRansom:Win32/Cerber.L!bit
ArcabitTrojan.Ransom.Cerber.YN
AegisLabTrojan.Win32.Zerber.j!c
GDataTrojan.Ransom.Cerber.YN
TACHYONRansom/W32.Cerber.262144.P
AhnLab-V3Trojan/Win32.Cerber.R204031
Acronissuspicious
McAfeeRansomware-GCB!1A46C52F37A8
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SMALY0
RisingTrojan.Kryptik!1.AC0E (CLOUD)
YandexTrojan.GenAsa!BHPuvwyPSDg
IkarusTrojan.Win32.Crypt
FortinetW32/Agent.CIXD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQB1BgB

How to remove Trojan.Ransom.Cerber.YN?

Trojan.Ransom.Cerber.YN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment