Ransom

Ransom:Win32/Teerac!rfn removal tips

Malware Removal

The Ransom:Win32/Teerac!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Teerac!rfn virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete volume shadow copies
  • A system process is generating network traffic likely as a result of process injection
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Teerac!rfn?


File Info:

crc32: 9D27BAAD
md5: c86a3887813d7c084833973c910b02a4
name: C86A3887813D7C084833973C910B02A4.mlw
sha1: 10f35960a8b8399dd03a30795976222b84505f65
sha256: a96e010f86d38528ff6039c16a36d75feef2471df9b6b3955a1f4c51d82fbf7d
sha512: 427a27cd6e08e453116243d76f7a6cab15fccfc664f72b07c5b9b33bf231b052677f6ba536381b4acd9ede4b69e1ae9b18a6f05f74ace68685b77b8a202302df
ssdeep: 6144:EAsBZ7WEysj09jdWQKDP9+roqRStG1s6ZIaw1JgpxiGCn3mFb0+EhOYh+NjwI4Vg:WWM87fSc1smEJgXUn3gXGOYhswIJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Ransom:Win32/Teerac!rfn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4549
MicroWorld-eScanTrojan.GenericKD.3240422
ALYacTrojan.GenericKD.3240422
CylanceUnsafe
ZillyaTrojan.Onion.Win32.1095
SangforTrojan.Win32.GenericKD.4
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Androm.6d437a3b
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.7813d7
SymantecRansom.TorrentLocker
ESET-NOD32Win32/Filecoder.TorrentLocker.A
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Androm.gen
BitDefenderTrojan.GenericKD.3240422
NANO-AntivirusTrojan.Win32.Encoder.ecnlxe
ViRobotDropper.S.Agent.380007
TencentWin32.Trojan.Filecoder.Syrq
Ad-AwareTrojan.GenericKD.3240422
SophosMal/Generic-R + Mal/Cerber-Z
ComodoMalware@#sdotzqvaqep8
BitDefenderThetaGen:NN.ZedlaF.34628.du8@aCbE@Nbi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRILOCK.CBQ165G
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.c86a3887813d7c08
EmsisoftTrojan.GenericKD.3240422 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Teerac!rfn
ArcabitTrojan.Generic.D3171E6
AegisLabTrojan.Win32.Androm.4!c
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
GDataTrojan.GenericKD.3240422
AhnLab-V3Trojan/Win32.ZBot.C1442030
McAfeeArtemis!C86A3887813D
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Onion
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRILOCK.CBQ165G
RisingTrojan.Injector!8.C4 (CLOUD)
IkarusTrojan.Win32.Injector
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
Qihoo-360Win32/Backdoor.Androm.HyoDEpsA

How to remove Ransom:Win32/Teerac!rfn?

Ransom:Win32/Teerac!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment