Ransom

Ransom:Win32/Tescrypt.O removal

Malware Removal

The Ransom:Win32/Tescrypt.O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Tescrypt.O virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Tescrypt.O?


File Info:

crc32: ED30DD13
md5: 4c797c97311407c5a96a1aa7f08e9db0
name: 4C797C97311407C5A96A1AA7F08E9DB0.mlw
sha1: 5e85936ba9886c67c340b51588569636a1ffc520
sha256: 4cc9dc0fd4c34008f5cd90a2b7ed5f3ff1b1e69ed96ba709a089cacd868bb36b
sha512: ef1ece39891066206c91ca5af5489109038865308a126a938404cc2307b2cd4fd136b1e6f26346fdec02cff0dd50b564528cf5a1a565224e49f75a39acea5b5e
ssdeep: 6144:vB8iFYYFywXwM1d0FkmFT1zTM6bDf0HFr3grgciKwQ7dkDRpMH4H6dd6:DF8w91d0FkmFTl1fCBIP6MH4HS
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2000 - 2001 S3/Diamond Multimedia
InternalName:
FileVersion: 1.0.2.1
CompanyName: S3/Diamond Multimedia
PrivateBuild:
LegalTrademarks:
Comments: Media Device Manager for Rio 800 device
ProductName: Diamond Rio800
SpecialBuild:
ProductVersion: 1.0.2.1
FileDescription: MDM Device Interface for Rio 800 device.
OriginalFilename: spRio800.dll
Translation: 0x0409 0x04b0

Ransom:Win32/Tescrypt.O also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004dfff61 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4116
CynetMalicious (score: 100)
CAT-QuickHealRansomware.Gen.WR1
ALYacGen:Variant.Razy.29119
CylanceUnsafe
ZillyaTrojan.Bitman.Win32.1852
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Tescrypt.94763b59
K7GWTrojan ( 004dfff61 )
Cybereasonmalicious.731140
CyrenW32/S-06a6b9c6!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EQLZ
APEXMalicious
AvastWin32:TeslaCrypt-HS [Trj]
ClamAVWin.Malware.Razy-7076941-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.29119
NANO-AntivirusTrojan.Win32.Encoder.eawpup
ViRobotTrojan.Win32.U.Agent.483328.J
MicroWorld-eScanGen:Variant.Razy.29119
TencentMalware.Win32.Gencirc.10bfea2b
Ad-AwareGen:Variant.Razy.29119
SophosML/PE-A + Mal/EncPk-ANR
ComodoTrojWare.Win32.Crypmod.EQL@6b1qbt
BitDefenderThetaGen:NN.ZexaF.34628.Dy0@aqIirxgi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SMCP
McAfee-GW-EditionRansom-Tescrypt!4C797C973114
FireEyeGeneric.mg.4c797c97311407c5
EmsisoftGen:Variant.Razy.29119 (B)
JiangminTrojan.Generic.dwhgr
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1108573
eGambitGeneric.Malware
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tescrypt.O
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Razy.29119
AhnLab-V3Trojan/Win32.Teslacrypt.R175991
McAfeeRansom-Tescrypt!4C797C973114
MAXmalware (ai score=100)
VBA32Hoax.Bitman
MalwarebytesTrojan.Pseudo
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CRYPTESLA.SMCP
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.GenAsa!+v9zDBE/Los
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EQAA!tr
AVGWin32:TeslaCrypt-HS [Trj]
Qihoo-360Win32/Ransom.Tescrypt.HxQBEpsA

How to remove Ransom:Win32/Tescrypt.O?

Ransom:Win32/Tescrypt.O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment