Ransom

Ransom.Tescrypt (file analysis)

Malware Removal

The Ransom.Tescrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Tescrypt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Tescrypt?


File Info:

crc32: D86A23B7
md5: 7893e294cb13b2648668d1971f6089f8
name: 7893E294CB13B2648668D1971F6089F8.mlw
sha1: eaa60e14dd09a8b313196eede09184fa8b2e60c0
sha256: b7068cebf662dca27abc0e02dddf40c6b0effa8ffc1362b97fbee0d1d835a1e7
sha512: 059356c5e251d15174d5949f9293dde5c0b8516d457db434dc3bf239d957cf4adc31df10c4b77788267253788c392170e229603e33cbb987aaa2e5456c10f51e
ssdeep: 6144:Ph8/WfmLyAxOgrneQT2QtOQuDEseVWGQLrMnfUoROhxxpeTr/ekI:S/xfxOgre6tntsRttzxp6L
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sajbmianozu.iya
ProductVersion: 2.4.59.42
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0127 0x007a

Ransom.Tescrypt also known as:

K7AntiVirusRiskware ( 0049f6ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.42131
CynetMalicious (score: 100)
CAT-QuickHealRansom.Tescrypt
ALYacGen:Heur.Mint.Zard.52
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0049f6ae1 )
Cybereasonmalicious.4dd09a
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMSO
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Zenpak-9901247-0
KasperskyHEUR:Trojan.Win32.Strab.gen
BitDefenderGen:Heur.Mint.Zard.52
MicroWorld-eScanGen:Heur.Mint.Zard.52
TencentTrojan.Win32.Chapak.wa
Ad-AwareGen:Heur.Mint.Zard.52
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34266.xq0@aGK8EEai
McAfee-GW-EditionBehavesLike.Win32.Emotet.fc
FireEyeGeneric.mg.7893e294cb13b264
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Mokes.epp
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/StopCrypt.MOK!MTB
GDataGen:Heur.Mint.Zard.52
AhnLab-V3Ransomware/Win.StopCrypt.R443932
Acronissuspicious
McAfeeGenericRXQG-VB!7893E294CB13
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazpmnO+aVyTBeB73uUQwaElP)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMSO!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Ransom.Tescrypt?

Ransom.Tescrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment