Ransom

About “Ransom:HTML/Tescrypt.E” infection

Malware Removal

The Ransom:HTML/Tescrypt.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:HTML/Tescrypt.E virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

mkis.org
tradinbow.com
primasentrausaha.com
masterlegue.com
classemgmt.testbada.com

How to determine Ransom:HTML/Tescrypt.E?


File Info:

crc32: 1BDF2A6A
md5: 3ec286bf3081e954c21fcf8fac322877
name: 3EC286BF3081E954C21FCF8FAC322877.mlw
sha1: 4d82d1b05fdb0cdfdf6d5c159773d776ffe39aaa
sha256: 64feda3ef90aa919d47d426566cda1ea85bc48be46817ce07b28cfc38f07bc81
sha512: 4bf0cd1526548e663f60ee3cfeb4dc4237402774de3b9f4e3ecc19cc3bcae743a2ec9fab2d2a06c4dbcce02a5d16be16a9b898dbb2cdd70619ff92ba844c59cb
ssdeep: 6144:UgEKZx9vFvVMXGW4tkOsyXtmDiMdBQwfQUA5E3i6LFtfJBMQ:UedVMXGztRdXtm9oE3i+mQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Google Inc. 2004-2005
FileVersion: 1.0.25.0
CompanyName: Google Inc.
ProductName: Gmail
ProductVersion: 1.0.25.0
FileDescription: Gmail Notifier
OriginalFilename: gnotify.exe
Translation: 0x0409 0x04b0

Ransom:HTML/Tescrypt.E also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Papras.1984
CynetMalicious (score: 100)
ALYacTrojan.Ransom.TeslaCrypt
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.2201
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/TeslaCrypt.2a87cdc7
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.f3081e
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.TeslaCrypt.K
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
ClamAVBC.Win.Packer.Troll-14
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.BrsecmonE.1
NANO-AntivirusTrojan.Win32.Papras.ebcuuh
ViRobotTrojan.Win32.R.Agent.314368.L
SUPERAntiSpywareTrojan.Agent/Gen-Papras
MicroWorld-eScanTrojan.BrsecmonE.1
TencentWin32.Trojan.Filecoder.Lory
Ad-AwareTrojan.BrsecmonE.1
SophosTroj/Ransom-CTW
ComodoMalware@#123e98s2dgyoi
BitDefenderThetaGen:NN.ZexaF.34690.tu0@amukSDii
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.CBQ163O
McAfee-GW-EditionBehavesLike.Win32.Virut.fc
FireEyeGeneric.mg.3ec286bf3081e954
EmsisoftTrojan.BrsecmonE.1 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1103896
Antiy-AVLTrojan/Generic.ASMalwS.17AA33A
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:HTML/Tescrypt.E
AegisLabTrojan.Win32.Yakes.mEqY
GDataTrojan.BrsecmonE.1
AhnLab-V3Trojan/Win32.Teslacrypt.R177345
Acronissuspicious
McAfeeArtemis!3EC286BF3081
MAXmalware (ai score=83)
VBA32BScope.Trojan.Yakes
MalwarebytesMalware.AI.677407692
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTESLA.CBQ163O
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.Filecoder!Ubs3l6D8R5g
IkarusTrojan-Spy.Banker.Citadel
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder_TeslaCrypt.K!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove Ransom:HTML/Tescrypt.E?

Ransom:HTML/Tescrypt.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment