Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Sep 2017

How to remove Cyron ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

Cyron ransomware reminds us old good Ukash viruses

Ransom note by Cyron ransomware virus

Cyron ransomware virus was first discovered on August 2017. However, its methods used for scamming PC users and stealing their money could remind us 2015 when cyber world was attacked by Ukash virus.

These threats were also considered to be ransomware-type viruses, but all what they did was blocking computer system. Once their scared their victim that he or she was noticed viewing pornographic content or similar material, hackers presented themselves as Police representatives or similar governmental authorities and required to pay a ransom.

As soon as Cyron virus infiltrates the system, it appends .CYRON file extension to the targeted data. Of course, it also uses AES encryption and Victims are asked to pay 50 euros via PaySafeCard[1] in order to get back access to the encrypted data.

Cyron ransomware is being distributed via malicious spam emails.[2] When a user opens an infected link or an attachment, malware payload is dropped on the system. Then it connects to Command and Control (C&C) server and downloads other malicious files in order to affect or stop particular Windows processes.

Malware might also delete Shadow Volume Copies to make data recovery impossible. However, Cyron virus might fail to do this task because of doing that it needs to get administrative privileges on the affected device.

Before starting data encryption, it also modifies or creates new entries in Windows registry to run on system startup. It is expected to target Run and RunOnce keys that are located in these locations:

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

When Cyron settles in, it starts data encryption procedure using a sophisticated AES cryptography and locks files with .CYRON file extension. Furthermore, it delivers a lock-screen ransom note that claims that computer is locked by Police which supposedly detected children porn sites in user’s browser’s history.

Victims are expected to contact criminals via ProjectCyRoN@candymail.com email address and pay 50 euros using PaySafeCard. Nevertheless, they claim that it’s the only way to restore files; you should not believe in them. This demand is provided not by police but cyber criminals that are not reliable, so you have to remove Cyron and do not even think about following their demands.

For Cyron removal, you will need a reputable antivirus or malware removal program because it’s the only safe way to get rid of the virus safely and quickly. We recommend choosing FortectIntego for this task.

The picture of Cyron ransomware virus

You can get infected by falling for spam

Authors of crypto-malware take advantage of the most popular, and unfortunately, effective ransomware distribution method – malspam. They send numerous misleading emails that include either malicious links or infected attachments.

Cyron most likely is downloaded and activated when a user activates Macros in Microsoft Office documents. These files are presented as important documents, such as bank statements, invoices and similar.

Therefore, you should be careful with received spam emails. Keep in mind that if you do not know the sender or do not expect to get an email from government, bank or delivery service, it might be sent by cyber criminals. Thus, stay away from them!

Removal of Cyron ransomware

Cyron removal requires obtaining reputable and powerful security software. IT experts from Finland[3] warn that attempts to locate and terminate ransomware-related files manually are a straight way to computer damage. The file-encrypting virus often affects legitimate system process, so it’s easy to delete safe files instead of malicious.

In order to remove Cyron automatically, you may need to start your PC with Safe Mode with Networking first. It helps to disable the virus and install/run malware removal tools. We recommend FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes for virus elimination.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.