Ransom

Ransom:Win32/Tescrypt.H removal

Malware Removal

The Ransom:Win32/Tescrypt.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Tescrypt.H virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
conspec.us
tmfilms.net

How to determine Ransom:Win32/Tescrypt.H?


File Info:

crc32: 317E75B1
md5: cb5515d0d61ed8bb1604b7b61250d8ef
name: CB5515D0D61ED8BB1604B7B61250D8EF.mlw
sha1: e879872fef8ca8a99acdfc17dfe4f80fbad37759
sha256: 5d5d5ca94886962ef0703f8bafa57ce7e933617af64a86dc98cb0e5252728944
sha512: bb000a4554c77e45de10445ae153b99afd011c57780bc3a59d2a9c1243fb0dcb64c567ca5c41d88c35ae3374dea5470e235e164b78a27fbb52166e7d6f4ffc57
ssdeep: 6144:fBRsBw3umrDUp0yrAl7oZW1T754vu28Koxgh7F2liTHSLxs0:pRgmr4p0vhoqT754vH8KKUJAUH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: Validates
FileVersion: 0.199.68.219
CompanyName: AMA Soft
LegalTrademarks: Wakens
ProductName: Topologies Strong
ProductVersion: 0.186.48.126
FileDescription: Tube Vocalised Sniper
OriginalFilename: Telexesl.EXE

Ransom:Win32/Tescrypt.H also known as:

BkavW32.Common.6FF422F5
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.60383
MicroWorld-eScanTrojan.Agent.BRJN
CAT-QuickHealRansom.Teslacrypt.OL4
McAfeeRansomware-FFR!CB5515D0D61E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3991 )
BitDefenderTrojan.Agent.BRJN
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.0d61ed
BitDefenderThetaGen:NN.ZexaF.34590.tq0@auwmH1ci
CyrenW32/Teslacrypt.I.gen!Eldorado
SymantecRansom.TeslaCrypt
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
ClamAVWin.Ransomware.Teslacrypt-7170628-1
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Tescrypt.9b5f3a07
NANO-AntivirusTrojan.Win32.AVKill.eaweai
ViRobotTrojan.Win32.TeslaCrypt.Gen.D
AegisLabTrojan.Win32.Bitman.tpUF
RisingRansom.Tescrypt!8.3AF (CLOUD)
Ad-AwareTrojan.Agent.BRJN
TACHYONTrojan/W32.Bitman.319488
EmsisoftTrojan.Agent.BRJN (B)
ComodoMalware@#d6zmyt928jx1
F-SecureHeuristic.HEUR/AGEN.1113545
ZillyaTrojan.CryptGen.Win32.1
TrendMicroRansom_HPCRYPTESLA.SM2
McAfee-GW-EditionRansomware-FFR!CB5515D0D61E
FireEyeGeneric.mg.cb5515d0d61ed8bb
SophosMal/Generic-R + Mal/Ransom-EG
IkarusTrojan.Win32.Filecoder
JiangminTrojan.Bitman.sj
AviraHEUR/AGEN.1113545
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tescrypt.H
ArcabitTrojan.Agent.BRJN
SUPERAntiSpywareTrojan.Agent/Ransom-TeslaCrypt
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Agent.BRJN
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Teslacrypt.C1344928
VBA32BScope.Trojan.AVKill
ALYacTrojan.Ransom.TeslaCrypt
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HDJF
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM2
TencentMalware.Win32.Gencirc.10c08d7b
YandexTrojan.Bitman!MdnXFR71r6M
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/TeslaCrypt.I!tr
WebrootW32.Trojan.Gen
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Rootkit.Generic.HwcBbucA

How to remove Ransom:Win32/Tescrypt.H?

Ransom:Win32/Tescrypt.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment