Categories: Ransom

Ransom.TeslaCrypt.C5 removal tips

The Ransom.TeslaCrypt.C5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.TeslaCrypt.C5 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

myexternalip.com
ocsp.pki.goog
kochstudiomaashof.de
testadiseno.com
diskeeper-asia.com
gjesdalbrass.no
garrityasphalt.com
www.garrityasphalt.com
grassitup.com
crl.pki.goog
crls.pki.goog

How to determine Ransom.TeslaCrypt.C5?


File Info:

crc32: 32B94931md5: ffece722f012ac09e237adf2bf4114baname: FFECE722F012AC09E237ADF2BF4114BA.mlwsha1: a7c7d4fb9875644b0117e0a382e36b8963a30ad5sha256: 406a3102c67d83b76853f3987d82e261a1b5d9142497eb0910307bc6b2f51125sha512: 21f329a9ba931fd9434b86f4f1225ff84436344b152659a8f3be6f4c38e23496166706bedb8dbe8dc3fa48786ddcbea773cd90ef0cd363dd8a09298099a90b57ssdeep: 6144:pKtr++h42w3Z4vIyMuneRjxu9zsrs5AQSNtYuBKmWr3Z4vIyMuneRjxu:8Y3ZIMueRoKQSfjAr3ZIMueRtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2012InternalName: UnamendedFileVersion: 151, 122, 195, 60CompanyName: Helexis Software DevelopmentPrivateBuild: LegalTrademarks: Comments: ProductName: Thresher SeparatingSpecialBuild: ProductVersion: 107, 99, 120, 239FileDescription: Tying Accord WarshipsOriginalFilename: Unmonitoredl.EXE

Ransom.TeslaCrypt.C5 also known as:

Lionic Trojan.Win32.Bitman.j!c
Elastic malicious (high confidence)
DrWeb Trojan.AVKill.59607
CAT-QuickHeal Ransom.TeslaCrypt.C5
ALYac Trojan.EmotetU.Gen.Aq0@hqSqqRli
Cylance Unsafe
Zillya Trojan.Bitman.Win32.601
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
K7GW Trojan ( 0055e3ef1 )
K7AntiVirus Trojan ( 0055e3ef1 )
Baidu Win32.Trojan.Filecoder.k
Cyren W32/TeslaCrypt.A.gen!Eldorado
Symantec Ransom.TeslaCrypt
ESET-NOD32 Win32/Filecoder.TeslaCrypt.I
APEX Malicious
Avast Win32:TeslaCrypt-E [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Trojan.EmotetU.Gen.Aq0@hqSqqRli
NANO-Antivirus Trojan.Win32.AVKill.dzdcfd
ViRobot Trojan.Win32.R.Agent.430080.B
MicroWorld-eScan Trojan.EmotetU.Gen.Aq0@hqSqqRli
Tencent Malware.Win32.Gencirc.10c4ca30
Ad-Aware Trojan.EmotetU.Gen.Aq0@hqSqqRli
Sophos ML/PE-A + Mal/Ransom-EC
F-Secure Heuristic.HEUR/AGEN.1103118
BitDefenderTheta Gen:NN.ZexaF.34170.Aq0@aqSqqRli
VIPRE Trojan.Win32.Generic!BT
TrendMicro Ransom_HPLOCKY.SM1
McAfee-GW-Edition Ransomware-FBK!FFECE722F012
FireEye Generic.mg.ffece722f012ac09
Emsisoft Trojan.EmotetU.Gen.Aq0@hqSqqRli (B)
SentinelOne Static AI – Malicious PE
Jiangmin Trojan.Bitman.ak
Webroot Trojan.Dropper.Gen
Avira HEUR/AGEN.1103118
eGambit Unsafe.AI_Score_100%
Antiy-AVL Trojan/Generic.ASMalwS.1608DBA
Microsoft Ransom:Win32/Tescrypt.C
Arcabit Trojan.EmotetU.Gen.E4B35C
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Trojan.EmotetU.Gen.Aq0@hqSqqRli
AhnLab-V3 Trojan/Win32.Teslacrypt.R173404
Acronis suspicious
McAfee Ransomware-FBK!FFECE722F012
MAX malware (ai score=83)
Panda Generic Suspicious
TrendMicro-HouseCall Ransom_HPLOCKY.SM1
Rising Trojan.Agent!1.A322 (CLASSIC)
Yandex Trojan.Bitman!lg52VE7h3Bk
Ikarus Trojan-Ransom.CryptoWall3
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Agent.F30!tr
AVG Win32:TeslaCrypt-E [Trj]
Paloalto generic.ml

How to remove Ransom.TeslaCrypt.C5?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Barys.27333 malicious file

The Barys.27333 is considered dangerous by lots of security experts. When this infection is active,…

2 seconds ago

How to remove “Win32/Kryptik.GKHS”?

The Win32/Kryptik.GKHS is considered dangerous by lots of security experts. When this infection is active,…

30 seconds ago

What is “Malware.AI.1865006162”?

The Malware.AI.1865006162 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan.Win32.Agent.xbnsym removal guide

The Trojan.Win32.Agent.xbnsym is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Backdoor:Win32/AsyncRAT removal tips

The Backdoor:Win32/AsyncRAT is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Win32:VB-NPD [Wrm] removal instruction

The Win32:VB-NPD [Wrm] is considered dangerous by lots of security experts. When this infection is…

2 hours ago