Spy Trojan

Trojan-Spy.Win32.Stealer.yyn removal tips

Malware Removal

The Trojan-Spy.Win32.Stealer.yyn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.yyn virus can do?

  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.

How to determine Trojan-Spy.Win32.Stealer.yyn?


File Info:

crc32: E2E4266A
md5: dad37edf3b190661eb34ad57fc97103f
name: DAD37EDF3B190661EB34AD57FC97103F.mlw
sha1: 781d24ab722ea0e329b50dacea4a45fcee44a334
sha256: d3a7838ae798a5d0271bd35063602eddab284157f1963d1b71812542ba6f92c4
sha512: 7f98b6a979960d352e237489ae2f2e0fedd66003a081da64c5ae49adcd343e01f1def326117151935da83ef42e192c1a1be2db990dfe22c1f7a8485816827cf3
ssdeep: 24576:JuyBQdB8daoYfRjtjRzOpHyqG1GajaVHqzd8uQ2hUHSYvr1AEWAUhgu6U5NY1Cf:7hdnY5jtjRappGM/Kzd8uPkSouFr6U
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.19041.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.19041.1
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE
Translation: 0x0409 0x04b0

Trojan-Spy.Win32.Stealer.yyn also known as:

K7AntiVirusSpyware ( 0057a2c81 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.54776
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37074989
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:MSIL/Generic.d92ea28d
K7GWSpyware ( 0057a2c81 )
Cybereasonmalicious.b722ea
CyrenW32/MSIL_Kryptik.EMM.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Spy.Agent.DFY
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyTrojan-Spy.Win32.Stealer.yyn
BitDefenderTrojan.GenericKD.37074989
MicroWorld-eScanTrojan.GenericKD.37074989
TencentMalware.Win32.Gencirc.10ce5a6c
Ad-AwareTrojan.GenericKD.37074989
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionGenericRXOU-HU!0F12EA30CF69
FireEyeTrojan.GenericKD.37074989
EmsisoftTrojan.GenericKD.37074989 (B)
SentinelOneStatic AI – Malicious SFX
AviraTR/Spy.Agent.knzmf
eGambitUnsafe.AI_Score_99%
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/AgentTesla!ml
GDataWin32.Trojan.BSE.AKETJC
McAfeeArtemis!DAD37EDF3B19
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.PNG.Generic
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DFY!tr.spy
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Trojan-Spy.Win32.Stealer.yyn?

Trojan-Spy.Win32.Stealer.yyn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment