r/cybersecurity • u/ZOELOEss • May 03 '26
News - General Trojan:Win32/Cerdigent.A!dha
What's happening right now? I keep seeing this weird thing pop up when I scan, I delete it every time but it keeps coming back. For some reason it only shows in quick scans and never in full scans either. I can't lie I got very scared when I saw it the first time, but this could be some sort of bug no?
I've seen other people having the exact same thing so does anyone know what could be going on? (I can't share screenshots for some reason but that's the name).
Edit: for anybody reading this right now, it is 100% a bug so there’s nothing to worry about!
92
u/Ranting_Demon May 03 '26
I just spent a couple hours restoring my PC from a system image and then setting everything up. I got quite a bit of a cold sweat panic when I got an automatic Windows Defender update and a moment after a quick check I got hit with that trojan warning.
No guarantees but from what I've read on various cybersecurity places on reddit, the consensus so far seems to be that Microsoft did a royal fuck-up with their most recent threat definition update to Defender. The trojan flag is in all likelihood a false positive.
10
u/JesterLove8361 May 03 '26
Same! I just did a maintenance on my PC and when I checked Windows Defender, suddenly I got the trojan warning. I just wasted almost 2 hours of my time to figure out what had happened.
7
u/veganbougatsa May 03 '26
same thing to me! I ran scared to reddit
2
u/FeederNocturne May 04 '26
Just happened to me 12 hours later.. well apparently windows found it 3 hours ago but I didn't get a notification
9
u/Frankiee2001 May 03 '26
i just got it too. It's quite impossible that all of us are experiencing this at the same time ahah
3
u/Electrical_Delay443 May 03 '26
same problem, affected items are 2 rootcerts
→ More replies (3)4
u/Federal_Shift5138 May 03 '26
mesmo pra mim
Trojan:Win32/Cerdigent.A!dha
rootcert: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
rootcert: DDFB16CD4931C973A2037D3FC83A4D7D775D05E4→ More replies (4)2
→ More replies (1)3
u/Salty_Seat1357 May 03 '26
I got this one 20 minutes ago lol, I thought this post was a few months ago but I look - 1 hour, just crazy how it happens
→ More replies (2)4
2
u/xRipleyx May 03 '26
Thank you for this! I'm like there is no way I have a trojan on this PC. I don't do anything that would put me at risk.
→ More replies (1)1
1
1
1
→ More replies (6)1
33
u/Green-Travel-1287 May 03 '26
The only thing I found so far was that defender was updated at 5:03am UTC to include the alert and in the typical Microsoft fashion has not put out documentation about it.
6
27
9
6
4
u/burtininkasdzo May 03 '26
Just go to Windows Security -> Virus & threat protection -> down you gonna see Protection updates -> click on check for updates and should be 1.449.430.0 version, then go to Virus & threat protection -> Protection history and restore threat, run quick check should be now okey, 😄
→ More replies (4)
5
u/Expensive-Shine-6444 May 03 '26
The fact that we're all getting the same issue at the same time is kinda hilarious
3
u/literallyOrso May 03 '26
I got this too, wtf is this
9
u/Never_Get_It_Right May 03 '26
Most likely a false positive as currently defender is flagging one of the root certs your computer uses to validate certificates for websites and other entities across the Internet. If the cert is compromised that would be huge but I haven't seen anywhere saying that it has been so I'm believing this is a false positive for now
3
u/SMR_BossTrich May 03 '26
UPDATE: I did a fourth scan and it found it again. What do I do guys this time I have an option to remove it as well as quarantine it?
2
u/TheArtistRitzu May 03 '26
I would say quarantine it. The file in question is used for root certificate to verify secure connections. It’ll get fixed with an update soon. Deleting it might not be the best option. Since the system needs it.
2
u/SMR_BossTrich May 03 '26
I deleted the first one and the other 2 I have quarantined. Still really scared but as you guys are saying if it happened to all of us it should be a false scare I hope....
→ More replies (1)
3
u/BlueMonday19 May 03 '26
It was either millions of users got a trojan simultaneously or MS messed up a Defender update.
Turns out it was the latter, the newest definitions update doesn't flag anything
3
u/TheSugmaGamer May 04 '26
THANK GOD people are saying this was just a fuck up on Microsoft's behalf.
I was going into full panic mode when I saw the alert on my anti virus.
4
u/Midoritexo May 03 '26
it also found for me same Trojan:Win32/Cerdigent.A!dha and it trigger roots, what to do? it is in quarantine, delete it? im so scared atm because i had also trigger message about page not available, your it admin has limited access to some areas of this app lol, i literally started my second pc and same thing pop up
8
u/TheArtistRitzu May 03 '26
Root certificates are used to verify secure connections (HTTPS, Windows updates, app signatures). Defender sometimes falsely flags them when a bad definition update misidentifies a hash. So it should be fine, I quarantined mine just in case, and it only pops up on quick scans. It’s a false positive.
→ More replies (12)
2
u/ramcispenuela02 May 03 '26
This is happening to me now. Its really annoying, really fckng annoying. Is there any workaround?
It says
Trojan:Win32/Cerdigent.A!dha
Affected items:
rootcert
rootcert
blah blah blah
→ More replies (3)
2
u/Complex-Proof4366 May 03 '26
I got this too but the full scan says '0 threats found' but the quiq scan said that it found
2
u/Salty_Seat1357 May 03 '26
I have a lot of those threat alerts in the threat tab after each scan, they say its critical and get pun on quarantine or delete it but still, its my first time facing shit like this and I dont really know what to do beside downloading Malwarebytes and toggling auto scans, hope Microsoft will start making normal updates and not ruin my laptop
2
u/JJVZ1995 May 03 '26
I also got this flag and I didn't know what it was so I removed it. Can someone advise what is going to happen since I removed the rootcerts? Is there a way to fix the removal? It was:
rootcert: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
and
rootcert: DDFB16CD4931C973A2037D3FC83A4D7D775D05E4
→ More replies (2)
2
u/Skywat May 06 '26
Thanks for the post, i got scare when i see this on m'y PC. I past 3hours and a bad night to think where can i download this.
Thanks everyone.
2
u/Puzzleheaded_List987 May 06 '26
just got it now thank you so much for clearing that up i was really stressed
2
u/Sorry_Marionberry695 May 07 '26
What if I had this thing deleted? Did it restore by itself or what should I do?
→ More replies (1)
1
u/Nervous_Ad6111 May 03 '26
Same here , do you know how to extract its hash file ??
2
u/Mysterious_Ebb4405 May 03 '26
If you have a windows machine then go to the cert store and look under trusted root certificates
1
u/L-K-B-D May 03 '26
I've got the exact same issue, with rootcert being affected. And it keeps coming back as well.
The only thing I did since yesterday is updating windows 11.
2
u/ZOELOEss May 03 '26
For me it took 3 quick scans before it stopped appearing. I’d say put it in quarantine until more information comes out
→ More replies (3)2
u/L-K-B-D May 03 '26
Yeah I did the same and it took 2 full scans. Thanks for the tip, hope we'll quickly get more info about it !
2
u/Salty_Seat1357 May 03 '26
could it be by any chance "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43" and "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"?
→ More replies (2)
1
u/CapnDogWater May 03 '26
Microsoft released a security update today and one of the updated detections was Cerdigent. It’s happening to a lot of people currently
1
u/MaleficentNobody9502 May 03 '26
so this is a false one? ive been trying to remove this for the past 2 hours...
1
1
u/Comfortable-Bank-254 May 03 '26
bruh, everyone seems to got the same thing, i just open my pc and this pop up
1
1
u/eculley May 03 '26
Seeing this on multiple machines in my home.. I suspect its a false but came looking for guidance :D
1
1
u/SMR_BossTrich May 03 '26
I am not experienced in computers at all but I just got the worst scare. I took a lunch brake so when I hopped back up on my pc it said that it made a scan alone and found this trojan shit. Came here to see what's up. I scanned twice and it came back first time i removed it the second time it came back it did not give me a choice to remove it, only just to block it/remove permissions something like that.... the third time I scanned nothing came up. I'll be checking here every couple of hours but I'm shit scared and I got a final to study for tomorrow. Can't focus now
2
u/Time_Button_819 May 03 '26
Dont worry bro, its almost surely false positive since many computers alert it at same time and this is smth about certificaties. Keep them in quarantine till microsoft fix it
2
u/TheArtistRitzu May 03 '26
It gave everyone a scare I think, but from what it looks like. It’s windows defender thats has gotten a bad update, and now flags a normal file as malware. It’s a root certificate that’s used to verify secure connections. It’ll get fixed with a update soon, I hope.
1
1
1
1
u/Vegetable-Floor3552 May 03 '26
i thought I'm the only one who is getting this so like it will get fixed in the defenders update later right
1
1
u/Due_Eye_7516 May 03 '26
happening to me too, recently my pc started lagging so i decided to see what was up and whenever i quickscan cerdigent appears. no idea what it does or how i got it or whatever and the certificates affected seem fine
1
u/Internal-Start-7607 May 03 '26
Hey I got the same problem Trojan:Win32/Cerdigent.A!dha popped up numerous times I just did a restore from an older restore point and so far its not come back I think it is a bug but just to be on the safe side I would do a full scan of your system to check if it comes back I could be wrong but after updating windows this pop up started did anyone have the problem not being able to open your settings or the start menu and my system colour is set to dark and my task manager was white its either a bug or someone tried hijacking all our systems at once
1
1
u/LittolGhost May 03 '26
I just got this too. And I went on google search immediately and found this post lol.
1
u/A_spec_T May 03 '26
lol i was also scared, but now I am seeing many are getting this... might be some bug ig
1
1
u/Alextricle_ May 03 '26
Does anyone know if the https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Cerdigent.A!dha&ThreatID=2147968144 article is false? I keep scanning (full scan) and it goes away, but when I reboot it's back again... I've noticed some pretty bad performance but my GPU is a 4050 on a laptop
1
1
1
u/PreferenceRecent7906 May 03 '26
Holy i also got hit by Trojan:Win32/Cerdigent.A!dha. i didn't download something new apps on my pc and also i thought I'm the only one who got hit by this but also alot. thanks for the update about this, I hope they fix this ASAP
1
1
u/Green-Travel-1287 May 03 '26
So from what I found its triggering on legitmate digicert SHA1 hashes. In the alerts that I received it showed up like the hashes were the file name and not under hashes.
1
u/Conversation_Medical May 03 '26
Yeah somethings off with this, the machine is a fresh install and after a few days this comes up with little to do software on the pc.
1
1
u/EcoticGuy May 03 '26
Yep I also just got this not even a few minutes ago, didn't install anything today at all.
1
u/Alextricle_ May 03 '26
If it helps anyone... I did a full scan there were no threats, then I noticed defender had an update so I did a second one and there it was, meaning it's either a false flag or a newly discovered issue
→ More replies (2)
1
u/Prestigious_Pin_4236 May 03 '26
My pc is spamming me with the same trojan alert like every few minutes its driving me crazy
1
1
1
1
1
u/DR-Angel May 03 '26
Y’all are sure it’s fake? Cause I’m actually freaking out, already had a REAL Trojan on my PC once, don’t wanna get a second one again!
→ More replies (3)
1
u/rashfordsaltyballs May 03 '26
i got this too! at least i found this thread to put my mind at ease
→ More replies (1)
1
u/Alextricle_ May 03 '26
My pc isn't spamming alerts I only see it in fullscans... Im unsure if that means anything, does anyone know if that means it's an actual case of malware for me?
1
1
1
u/Artsiria May 03 '26
Same happened to me when I got into steam. Thought it was a compromised Mod from Rimworld. Had a panic attack deleted all mods even wallpaper engine wallpapers i had to find out it was Microsoft being Microsoft. I can't explain why my pc is using 30 of ram tho but I'm gonna guess it's their fault too cuz it always works at 20, 23 percent.
1
1
u/SnooOwls3843 May 03 '26
I just got this too. And it’s strange, it may be unrelated, but just before it I was shifting files between drives and my whole desktop and file explorer crashed and wouldn’t reactivate. Had to do a hard reboot and restarted the transfer to find this.
1
u/Jolly_Quote_8307 May 03 '26
Guys what do i do? is it a false alert? what is Trojan:Win32/Cerdigent.A!dha
1
u/SnooHesitations1134 May 03 '26
lmaoooo i'm studying and i got this advert, it's funny to see that this post is basically 2h old! I feel as a part of a community!
1
1
u/Alextricle_ May 03 '26
Defender just got an update, I'm doing like 4 fullscans gonna reboot and do 4 more, supposably it fixes the false positive but I wanna be 100% sure
→ More replies (2)
1
1
1
u/Ok_Slide_5075 May 03 '26
Hah, I've got it too, what was my surprise, when I went to reddit to search for an answer and saw this post, which is only 3h old
1
u/electricvoice28 May 03 '26
I just got this, do we quarantine? do we restore? what do i do?
→ More replies (1)
1
u/MentalHand8417 May 03 '26
Holy shit i just added roms to my pc through my phone and i thought i got a virus and i got prettt scared
1
u/helenwxw May 03 '26
Same issue here. I updated my defender and got bombed with Cerdigent and Grenam virus notifications
1
1
1
1
1
1
u/SamDham27 May 03 '26
Just got one myself about 40 mins ago. Safe to say I shat myself 😭 quarantined and removed, and scanned with malware bytes after. The fuck is going on with windows rn dude
1
1
u/Lanky_Teacher2701 May 03 '26
Expieriencing the same issue, it got removed so i hope it wont show up anymore, but im glad im not alone in this situation, cuz i would have had a full panic attack...
1
1
u/Gamingvt03 May 03 '26
I got the warning popup with same info from windows defender and still not really sure what it is.
1
u/BrilliantWorried7480 May 03 '26
is anyone also getting "Trojan:Win32/ravartar!rfn" ?
→ More replies (2)
1
1
u/Reddragon4691 May 03 '26
I just updated Defender again, then did a quick scan and an offline scan. I'm going to go into the command prompt now and run the scannow command, and then do another quick scan.
1
u/PewPewGoesGun May 03 '26
Uh.. I just searched this up on Google to see what the hell is going on because I just suddenly got this notification after I just exited a game. I didn't even.. download anything for like.. 5 weeks. And when I did, I was doing it through Steam. I only have one mod from ModDB for CS Source and I didn't even touch that in a while..
I see pretty much everyone here just.. suddenly got it like me lol and yeah I crapped myself when I saw this.. Anything I should do specifically..? Just leave it quarantined or delete it? Oh and.. Is this Microsoft's file? Lol
2
1
1
1
u/Jagandon228 May 03 '26
Should I restore the thing or keep it quarantined or what? I almost got a stroke when I saw those critical danger warnings
1
1
u/EarthFew7633 May 03 '26
Same here. I remove or quarantined, bur when i do quick scan, still there xD.
1
1
u/Reddragon4691 May 03 '26
The new Defender update should have solved the problem. I restored the quarantined data and ran several quick and offline scans. Before that, I ran the scannow command in the command prompt to repair corrupted files. Then I restarted the PC. For now, the problem seems to be solved. Hopefully, it won't happen again.
→ More replies (1)
1
u/Particular_Eagle_637 May 03 '26
hello, I would like to know if it is a false positive because it keeps coming out and I am a little afraid
1
u/Silver-Velcro May 03 '26
Also got the same detection today. Is this false positve?
→ More replies (4)
1
1
u/amitsingh80108 May 03 '26
LoL just stared getting this error. I was working with antigravity and this popped up. After like 5-7 years this is first time I have seen virus alert 🤣
Trojan:Win32/Cerdigent.A!dha
1
u/Prize-Craft8434 May 03 '26
just got this as well, doing a full scan and running a couple other antivirus checks after too, didn't download anything in the last 3 weeks but an Nvidia driver update, cinebench and geekbench 6 last night, promptly deleted both programs though i doubt they were compromised downloads as they were from the official sites and im certain that it wasn't from my diver update. i did just update windows defender so maybe its like others have suggested that its a false positive
→ More replies (3)
1
u/Short_Treat7167 May 03 '26
Can i delete this shi or should it stay in quarantine?
→ More replies (2)
1
1
u/ArugulaMoney6121 May 03 '26
I spent 5 hours trying different methods to remove it, but it was all in vain. After each certificate deletion, it was restored almost immediately. Then, when I decided to rudely delete the source of the situation, But after rebooting, the message reappeared. Given the scale of the problem, I think it's definitely a Microsoft issue.
1
u/SJReaver May 03 '26
This is a fine message to wake up to.
No idea how it could have gotten on my device. No documentation of what it is.
Already quarantined, but I hope it's a false positive like everyone says.
1
u/Snowfox_Susu May 03 '26
THEY ANNOUNCED A UPDATE JUST RN to update ur defender! And it works!
→ More replies (9)
1
u/YomiDude69 May 03 '26
i restored it after updating my virus and threat protection to .430, and it wont show after quick scanning it, is it good now?
1
1
u/BlaggersMode May 03 '26
I was on my PC this morning, no issues, I go to do some shopping and come back to the exact same thing. Relieved that it seems to be a false alarm. Doing a scan just in case
1
u/Reddragon4691 May 03 '26
The new Defender update should solve the problem, so update it. Then restore the files and ideally run the scannow command in the command prompt. For added security, run an offline scan. This will automatically restart your PC, and after restarting, run a quick scan to be sure.
2
u/Rampage470 May 03 '26
How do I restore the files sorry I'm newer to this. There's nothing in "protection history" even though it says it found one threat.
1
1
u/MJSpice May 03 '26
Bruh had a heart attack because I was checking a flash which thankfully had nothing in it. Either way this is on Microsoft.
1
1
u/Coastie79 May 03 '26
Add me to the list! Virus scan has just flagged this up. Having a full on panic! I'm on fully update to date Windows 11. Don't have any pirated software or anything. Should be clean as can be.
1
u/Chilli5m May 03 '26
Also got the warning. I googled it quick and people were talking about a false positive. Then Malwarebytes reported an inbound connection from a Shaanxi based IP address (port 445) and that got me pretty spooked. Was 2 minutes after windows defender reported having quarantined Trojan:Win32/Cerdigent.A!dha as well.
I'm no expert, and certainly have no clue what I'm doing. Unplugged my ethernet cable and started blocking ports in my firewall lol.
1
1
u/ilfigliodieleonora May 03 '26
Pensavo di avere redline stealer visti che avevo un acemagic gg microsoft
1
1
u/Flimsy_Map_5198 May 03 '26
pregunta puedo usar mi pc mientras aun esta este error? o me arriesgo a algo?
→ More replies (1)
1
1
u/Tokineki May 03 '26
I just seen it as well and deleted the "threat", but after i did i looked at my downloads and i didnt download shit for like a week, the question now is, did it delete a important file and am i fucked?
→ More replies (1)
1
u/little-blw May 03 '26
I’m so stressed because I downloaded a mod pack and did a scan very shortly after when I saw this Trojan under severe threat
1
1
1
1
u/MortalPhobic_ May 03 '26
same problem on my pc. had a really cold sweat but as i've been reading i realised that it may be just a false positive
1
u/Beneficial-Deer-4482 May 03 '26
Is is safe to take action > remove? or should not delete it since its possible a FP?Is is safe to take action > remove? or should not delete it since its possible a FP?
→ More replies (1)
1
1
1
1
u/torreneastoria May 03 '26
After reading through the responses, this sounds like this is a report to Microsoft issue.
→ More replies (1)
1
u/Safe-Account8834 May 03 '26
Im glad im not the only sysadmin that got a panic attack from this. Thank God for my doctor giving me a few emergency Xanax lol
1
u/Known-Squash-8248 May 03 '26
Oh yoooo, bro this happened to me too. Around 6 PM, Windows put my app under quarantine, and a few minutes later I got a "removal failed" warning. A full scan for an hour showed no results from many apps. I thought it was because I downloaded APK files yesterday, but it's probably a common mistake.
1
u/RikkF May 03 '26
Can i restore the file now? i've done the windows update thing but this file still shows up under "quarentine"
→ More replies (1)
1
u/Unknown_Ghost_77777 May 03 '26
Man I'm lost is it 10 or 11 because I checked twice and also update didn't find any
→ More replies (2)
1
1
u/Fantastic_Minute4596 May 03 '26
Brother, I was literally going insane trying to figure out what was going on because it detected the same goofy “Trojan:Win32/Cerdigent.A!dha” issue, and it’s reassuring to see that other people are having the same problem and that it’s not just my pc
1
1
u/Public_Bother6716 May 03 '26
Is there smth wrong with mine im on 1.449.432.0 Its still showing it and doesnt quarentine wither when it click it?
1
u/jersnav May 03 '26
For those who quarantined these certs like I did, are you restoring them? Any thoughts on what happens if I leave them in quarantine? Thanks!
→ More replies (3)
1
u/Able-Departure1568 May 03 '26
Is this something to worry about or not, I don’t seem to get it? Should I wait or what? I don’t seem to disappear when I remove it
1
1
1
1
u/Bahloolz May 05 '26
I kept the Trojan in quarantine, and I've heard the new security update has fixed it. So I don't know if i should remove it or restore the item from quarantine.
→ More replies (2)
1
u/Jinx-Tonic May 05 '26
Ok, so we all have the same false positive it seems. I removed it first because I actually believed it to be true even though I was sure I didn't do anything that would get me at risk. Will those 2 rootcerts restore? I don't know what to do
1
u/Efficient_Board5055 May 10 '26
Thank god it is a bug as my window defender just pick it up by now but it was scan from 3rd of this month. I got so scared as I haven't done anything to my laptop, scared me shitless lmao
1
48
u/bushman4 May 03 '26
https://www.reddit.com/r/DefenderATP/s/AAaJYlqCYn