Ransom

Should I remove “Ransom:Win32/Tescrypt.I”?

Malware Removal

The Ransom:Win32/Tescrypt.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Tescrypt.I virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ip.tyk.nu
dawnlogistics.com
www.hugedomains.com
ocsp.digicert.com
yavuzturk.com
thevictorianmotel.com
elle-ectric.com
f1autobody.com
nicasitios.com

How to determine Ransom:Win32/Tescrypt.I?


File Info:

crc32: 5B68AD7E
md5: ab249a23f23eec7532e1ce034c486498
name: AB249A23F23EEC7532E1CE034C486498.mlw
sha1: f58f264fd091e88d111f4a780953ec7c860e57f8
sha256: aff9e3174a112323427b82a8d7ce5235a268d2c57da1a255e5fa960f868dfc73
sha512: 7ecbdb6ade08926efb56d06f406843a8c0129aa7ea987b43450061fe38c842948a5fe544f6727356a53c9a02f0f1a87b0ffde96213f69fb5cc6b61a9565ddbf5
ssdeep: 6144:5FPSyBz5/5P/6BctZO2FWewkZrjx4a6p:5BSypP/6BctZOZewkdNx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: TODO:
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: TODO:
Translation: 0x0011 0x04b0

Ransom:Win32/Tescrypt.I also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.59705
CynetMalicious (score: 99)
ALYacGen:Heur.Ransom.RTH.1
CylanceUnsafe
ZillyaTrojan.Bitman.Win32.2943
SangforTrojan.Win32.Heuristic.ET
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.3f23ee
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.TeslaCrypt.I
APEXMalicious
AvastWin32:CryptoWall-AI [Trj]
KasperskyTrojan-Ransom.Win32.Bitman.etq
BitDefenderGen:Heur.Ransom.RTH.1
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Heur.Ransom.RTH.1
TencentMalware.Win32.Gencirc.114c3f60
Ad-AwareGen:Heur.Ransom.RTH.1
SophosMal/Generic-R + Troj/Tescrypt-C
ComodoMalware@#3ht7856lobuok
BitDefenderThetaGen:NN.ZexaF.34758.su0@aKvGSsfk
VIPRETrojan.Win32.Tescrypt.a (v)
TrendMicroRansom_CRYPTESLA.F116KN
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
FireEyeGeneric.mg.ab249a23f23eec75
EmsisoftGen:Heur.Ransom.RTH.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Bitman.gb
AviraHEUR/AGEN.1101649
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.16BFB93
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tescrypt.I
GDataGen:Heur.Ransom.RTH.1
AhnLab-V3Trojan/Win32.Teslacrypt.R174308
McAfeeGenericR-GOW!AB249A23F23E
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Bitman
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTESLA.F116KN
RisingTrojan.Generic@ML.93 (RDML:tcSqXg7iFF8zXG5BsQjFSg)
IkarusTrojan-Ransom.TeslaCrypt
FortinetW32/TeslaCrypt.I!tr
AVGWin32:CryptoWall-AI [Trj]
Paloaltogeneric.ml

How to remove Ransom:Win32/Tescrypt.I?

Ransom:Win32/Tescrypt.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment