Ransom

Ransom:Win32/Tescrypt malicious file

Malware Removal

The Ransom:Win32/Tescrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Tescrypt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Tescrypt?


File Info:

crc32: 1A2FC149
md5: 573bf2a20a164b4df6a20e7a43bafd40
name: 573BF2A20A164B4DF6A20E7A43BAFD40.mlw
sha1: f322d1bc6209f4be208f8e30f3343087e31cafb3
sha256: ca99233f8dc00443efca9337ea2b781d91b946ca87dd3bf24cfa4c7b12521351
sha512: ae638f681a12ba0cba0607429151e83537f5c027de045c54a5220a60b3b9804e51980180c4550b9e8603909da1726e5d823b58f7f3b9efafece10960c596d57c
ssdeep: 6144:hWNoEFfGzyG7zdUM2zZnA4jrCivvTtxJ7iDGnd/sDmwaW:hgoEFfbUUMkFYin39eSfW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Tescrypt also known as:

BkavW32.FamVT.RazyNHmC.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.3090992
FireEyeGeneric.mg.573bf2a20a164b4d
CAT-QuickHealRansom.Locky.S5
ALYacTrojan.Ransom.TeslaCrypt
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3ef1 )
BitDefenderTrojan.GenericKD.3090992
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.20a164
BitDefenderThetaGen:NN.ZexaF.34590.uuW@a0Imc1hO
CyrenW32/Rovnix.C.gen!Eldorado
SymantecPacked.Generic.521
BaiduWin32.Trojan.Kryptik.ws
APEXMalicious
AvastWin32:Mutex-E [Trj]
ClamAVWin.Ransomware.Lethic-7554792-0
KasperskyTrojan-Ransom.Win32.Bitman.qlg
AlibabaRansom:Win32/Bitman.4ef507fd
NANO-AntivirusTrojan.Win32.Encoder.eawyid
AegisLabTrojan.Win32.Bitman.j!c
TencentMalware.Win32.Gencirc.10c1ec70
Ad-AwareTrojan.GenericKD.3090992
SophosMal/Generic-S
ComodoMalware@#3mccronzdka65
F-SecureHeuristic.HEUR/AGEN.1128848
DrWebTrojan.Encoder.4121
ZillyaTrojan.TeslaCrypt.Win32.76
TrendMicroRansom_HPCRYPTESLA.SM1
McAfee-GW-EditionRansomware-FGI!573BF2A20A16
EmsisoftTrojan.GenericKD.3090992 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Bitman.tk
AviraHEUR/AGEN.1128848
Antiy-AVLTrojan[Ransom]/Win32.Bitman
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Tescrypt
ArcabitTrojan.Generic.D2F2A30
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmTrojan-Ransom.Win32.Bitman.qlg
GDataTrojan.GenericKD.3090992
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Teslacrypt.C1346930
McAfeeRansomware-FGI!573BF2A20A16
MAXmalware (ai score=88)
VBA32BScope.TrojanRansom.Bitman
MalwarebytesMalware.AI.4246928681
PandaTrj/Genetic.gen
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM1
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.GenAsa!HQ0oCd9CiFY
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.EQFO!tr
WebrootW32.Trojan.Gen
AVGWin32:Mutex-E [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM41.2.Malware.Gen

How to remove Ransom:Win32/Tescrypt?

Ransom:Win32/Tescrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment