Ransom

How to remove “Ransom:Win32/Teerac”?

Malware Removal

The Ransom:Win32/Teerac is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Teerac virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Ransom:Win32/Teerac?


File Info:

crc32: EE6B90EA
md5: 17ad6ee473b2c0de0de1fd6aa672cd02
name: 17AD6EE473B2C0DE0DE1FD6AA672CD02.mlw
sha1: cbbcf3fdc2e29ed2df28cfa1db3b6a992de7ca86
sha256: f914b02c6de92d6bf32654c53b4907d8cde062efed4f53a8b1a7b73f7858cb11
sha512: 338388930247eab39d531a23f6921c81a17b7766a5ce8711998255e333b159cdd65591418b8c039b83a8c3d2b1bf97154c9042b4be0d73c35fe827f033ca00b8
ssdeep: 6144:WMMYNXqBBRWzw7j8i1IFzCMdlFBcWCrswD6pJADZGWAohM7RASYTksVxTFL01D:6nRWYj8SezR/cp6p6cWAKdFL01D
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Ransom:Win32/Teerac also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.761
MicroWorld-eScanTrojan.GenericKD.4502427
ALYacTrojan.Ransom.cryptolocker
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.4502427
K7GWTrojan ( 005073901 )
K7AntiVirusTrojan ( 005073901 )
ArcabitTrojan.Generic.D44B39B
BitDefenderThetaGen:NN.ZedlaF.34804.cu8@aakIg3hi
CyrenW32/Injector.URBI-1547
SymantecRansom.TorrentLocker
ZonerTrojan.Win32.55211
TrendMicro-HouseCallRansom_CRYPTLOCK.DLFLVS
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Inject.wnfq
AlibabaRansom:Win32/Enestedel.a8d016bf
NANO-AntivirusTrojan.Win32.DLYF.eniozb
AegisLabTrojan.Multi.Generic.4!c
RisingRansom.Enestedel!8.E513 (TFE:5:xsynKvNU5vI)
Ad-AwareTrojan.GenericKD.4502427
SophosMal/Generic-R + Mal/Cerber-Z
ComodoMalware@#2d7tsu2wg94x8
F-SecureTrojan.TR/Injector.wwevx
TrendMicroRansom_CRYPTLOCK.DLFLVS
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.17ad6ee473b2c0de
EmsisoftTrojan.GenericKD.4502427 (B)
SentinelOneStatic AI – Suspicious PE – Ransomware
AviraHEUR/AGEN.1116907
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Teerac
SUPERAntiSpywareRansom.CryptoLocker/Variant
ZoneAlarmTrojan.Win32.Inject.wnfq
GDataTrojan.GenericKD.4502427
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Ransom_.C1829840
McAfeeGeneric Trojan.df
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Enestedel
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Agent.JRB
APEXMalicious
ESET-NOD32a variant of Win32/Injector.DLYF
TencentWin32.Trojan.Inject.Dzkn
YandexTrojan.Injector!Waovky67AVU
IkarusTrojan.Win32.Injector
eGambitGeneric.Malware
FortinetW32/Injector.DLYF!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360HEUR/QVM42.2.3A03.Malware.Gen

How to remove Ransom:Win32/Teerac?

Ransom:Win32/Teerac removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment