Ransom

What is “Ransom:Win32/Teerac.A”?

Malware Removal

The Ransom:Win32/Teerac.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Teerac.A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete volume shadow copies
  • A system process is generating network traffic likely as a result of process injection
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

edetyc.blasters.biz
ipecho.net
osegudib.blasters.biz
iwahulokyj.blasters.biz
isemo.blasters.biz
emefapozidi.blasters.biz
yhenjvaqul.blasters.biz
osoxol.blasters.biz
ilyxyq.blasters.biz
uzucrb.blasters.biz
kqomugyqoh.blasters.biz
opibogebiv.blasters.biz
usody.blasters.biz
udino.blasters.biz

How to determine Ransom:Win32/Teerac.A?


File Info:

crc32: DAA12D39
md5: bd4ed272dd84316821cc3ad186c9f371
name: BD4ED272DD84316821CC3AD186C9F371.mlw
sha1: b1579478a991c82f00816efc9399bac9da2a44bc
sha256: f20331dd1e2af19d151d7013b6fa05f9f53149aa372cb811e416cc8464289551
sha512: 711171ea56d7c580ca4579eef738592340d274b686424252ede841ec5a956c9505751e587106be6d674858fb391fc76446c65cb0a67e4c195931a12b5f87ecdd
ssdeep: 12288:9Yag0MkRZF5pQiDpqM54kLdqayvVnZa7:9o0Mu5pQIR54wyvVno7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa9 2005-2015
InternalName:
FileVersion: 5.0.3.0
CompanyName: IObit
LegalTrademarks: IObit
Comments:
ProductName: UninstallMonitor
ProductVersion: 5.0.1.0
FileDescription: IObit Uninstaller 5 UninstallMontior
OriginalFilename:
Translation: 0x0409 0x04e4

Ransom:Win32/Teerac.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
FireEyeGeneric.mg.bd4ed272dd843168
McAfeeTrojan-FORL!BD4ED272DD84
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005224381 )
BitDefenderTrojan.Ransom.Cerber.1
K7GWTrojan ( 0051c8ad1 )
BaiduWin32.Trojan.Kryptik.anp
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Vucha.dc
NANO-AntivirusTrojan.Win32.Vucha.evmvky
RisingTrojan.Kryptik!1.AE9C (CLOUD)
Ad-AwareTrojan.Ransom.Cerber.1
SophosMal/Generic-R + Mal/Ransom-EJ
ComodoTrojWare.Win32.Kryptik.FBWM@6gt9t1
F-SecureHeuristic.HEUR/AGEN.1129194
DrWebTrojan.Encoder.761
TrendMicroRansom_CERBER.SMFE
McAfee-GW-EditionTrojan-FORL!BD4ED272DD84
EmsisoftTrojan.Ransom.Cerber.1 (B)
IkarusVirus.Win32.CeeInject
AviraHEUR/AGEN.1129194
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Vucha
MicrosoftRansom:Win32/Teerac.A
ArcabitTrojan.Ransom.Cerber.1
ZoneAlarmHEUR:Trojan.Win32.Vucha.dc
GDataTrojan.Ransom.Cerber.1
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.Gq0@aOoEgBhj
ALYacTrojan.Ransom.Cerber.1
VBA32BScope.TrojanPSW.Papras
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.FZOE
TrendMicro-HouseCallRansom_CERBER.SMFE
TencentWin32.Trojan.Generic.Pgws
YandexTrojan.GenAsa!6xN+I0nuPx4
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/Dridex.DD!tr
AVGWin32:Malware-gen
Cybereasonmalicious.2dd843
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.TorrentLocker.HxQBeukA

How to remove Ransom:Win32/Teerac.A?

Ransom:Win32/Teerac.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment