Malware

What is “Troj/Tesla-ZP”?

Malware Removal

The Troj/Tesla-ZP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Tesla-ZP virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Troj/Tesla-ZP?


File Info:

name: 5594564D65AC500AB1B9.mlw
path: /opt/CAPEv2/storage/binaries/041dd48ef83f4bc22d0d3511ba6ff4516d93597a6dd8ee5dbd4e2cc9aeee428e
crc32: CDAEE0D2
md5: 5594564d65ac500ab1b966ed517efefc
sha1: ee99cdefabb6c4d19fb56012f797b154eaecf1e1
sha256: 041dd48ef83f4bc22d0d3511ba6ff4516d93597a6dd8ee5dbd4e2cc9aeee428e
sha512: 3e083f2d13645e6dce1e9a74a7e3fc6ea79da8dad7838ad08dbda3d88e055f1a9344c6d2bfafc520e49f359c072cddc225bdd1a050a6d445705edc141ec75c02
ssdeep: 24576:Wjy8yEVyjW2w9mvO2Lcu4brUZ+94w4cgd81SzY5YvL:cyjWQvyuKbgdkSM5YvL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B55481821B5086BE9790A3544214B377EF26C39BB77F3CD3748315B4AB668C4A273E9
sha3_384: 23757fd7fac85db54085ab534a4f389cd439f81dcce945ea21f4137c85ab09fa71627b9c937ca6d4af13fa6c4ecc2214
ep_bytes: ff250020400000000000000000000000
timestamp: 2040-03-09 03:48:05

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Joshua Doore
FileDescription: Fine arts Photography
FileVersion: 1.0.0.0
InternalName: IsolatedStorageFilePermissionAttribu.exe
LegalCopyright: Joshua Doore © 2020 - 2022
LegalTrademarks:
OriginalFilename: IsolatedStorageFilePermissionAttribu.exe
ProductName: Fine arts Photography
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Troj/Tesla-ZP also known as:

LionicTrojan.MSIL.Taskun.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.21448
MicroWorld-eScanTrojan.GenericKD.38201045
FireEyeGeneric.mg.5594564d65ac500a
ALYacTrojan.GenericKD.38201045
CylanceUnsafe
K7AntiVirusTrojan ( 0058b7231 )
AlibabaTrojanPSW:MSIL/Agensla.e7821846
K7GWTrojan ( 0058b7231 )
BitDefenderThetaGen:NN.ZemsilF.34062.on0@aSyBync
CyrenW32/MSIL_Kryptik.GFU.gen!Eldorado
SymantecMSIL.Packed.19
ESET-NOD32a variant of MSIL/Kryptik.ADQS
TrendMicro-HouseCallTROJ_GEN.R002C0PL621
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.38201045
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKD.38201045
SophosTroj/Tesla-ZP
TrendMicroTROJ_GEN.R002C0PL621
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
GDataGeneric.Trojan.PSEB.BRLV6U
AviraTR/Kryptik.eoprr
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.34E63DC
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:MSIL/AgentTesla.SMVQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Infostealer.R456493
McAfeePWS-FCUF!5594564D65AC
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt.MSIL
APEXMalicious
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.FOMF!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A

How to remove Troj/Tesla-ZP?

Troj/Tesla-ZP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment