Ransom

Ransom.TeslaCrypt information

Malware Removal

The Ransom.TeslaCrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.TeslaCrypt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Appends a known Sage ransomware file extension to files that have been encrypted
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.TeslaCrypt?


File Info:

crc32: 3FBBE05B
md5: 85eb41ac7b9252482b6ff3660471c39d
name: 85EB41AC7B9252482B6FF3660471C39D.mlw
sha1: 162e68cfa635228e541021bb790a0e17f23fe3a8
sha256: f25a5671305816619dc3b9d69ddf5ef5350132cc013b48553b9c5c63bbe6d0bd
sha512: 88cb31a257f347117ae233eb7eb094dd7f672e819dc93c75b77f0bd6a700315eea166a6d837251033995abf1e0c979d74b3371b4c9ee46815332b87c564cf08e
ssdeep: 3072:/PsCM8YiTNqS1HgQxDV/4uCUyDGhKsim+bWo9wKBT73IjFM/GH0UuIr:/P1NqSgwDlCPahKsx+71V73Ipq1g
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 cowey fwtk
InternalName: Cvjlfb
FileVersion: 1.114
CompanyName: Buoorhn x
ProductName: Tn flerwgc
ProductVersion: 1.114
FileDescription: Oynrkl eixqt pkmpm ruzvf
OriginalFilename: Cvjlfb
Translation: 0x0000 0x0009

Ransom.TeslaCrypt also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Sage.30
FireEyeGeneric.mg.85eb41ac7b925248
CAT-QuickHealTrojan.Deshacop
McAfeeRansom-FCJ!85EB41AC7B92
CylanceUnsafe
VIPRETrojan.Win32.Skintrim.c (v)
AegisLabTrojan.Win32.Deshacop.4!c
SangforVirus_Suspicious.Win32.Sality.ae
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ransom.Sage.30
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c7b925
CyrenW32/S-ba03db07!Eldorado
SymantecRansom.Cry!g1
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Sage-5744913-0
KasperskyTrojan.Win32.Deshacop.dir
NANO-AntivirusTrojan.Win32.Deshacop.elnliu
RisingRansom.Cerber!8.3058 (TFE:dGZlOgU7ahK3BJo1Dw)
Ad-AwareGen:Variant.Ransom.Sage.30
EmsisoftGen:Variant.Ransom.Sage.30 (B)
ComodoTrojWare.Win32.Genasom.A@70kb9g
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.MulDrop7.9067
ZillyaTrojan.Deshacop.Win32.751
TrendMicroRansom_HPMILICRY.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosML/PE-A + Troj/Ransom-EDF
IkarusTrojan-Ransom.Sage
JiangminTrojan.Deshacop.tn
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Deshacop
MicrosoftRansom:Win32/Cerber!rfn
ArcabitTrojan.Ransom.Sage.30
ZoneAlarmTrojan.Win32.Deshacop.dir
GDataGen:Variant.Ransom.Sage.30
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cerber.R192009
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.kq1@aiVgRYgi
ALYacGen:Variant.Ransom.Sage.30
VBA32SScope.TrojanRansom.WannaCry
MalwarebytesRansom.TeslaCrypt
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FJHH
TrendMicro-HouseCallRansom_HPMILICRY.SM1
TencentMalware.Win32.Gencirc.10b1fbf3
YandexTrojan.Deshacop!rvvGucB2Rtc
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.FNGP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Generic.HwcBUFcA

How to remove Ransom.TeslaCrypt?

Ransom.TeslaCrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment