Trojan

Trojan.TeslaCrypt.EF removal instruction

Malware Removal

The Trojan.TeslaCrypt.EF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.TeslaCrypt.EF virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Maltese
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Executed a process and injected code into it, probably while unpacking
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

diwali2k15.in
samuday.org
maxmpl.com
setprosports.info
masterlegue.com
toolaria.com
www.afternic.com

How to determine Trojan.TeslaCrypt.EF?


File Info:

crc32: 38F894BE
md5: f4a4f123cf09c99c8bd980dac1cabc09
name: F4A4F123CF09C99C8BD980DAC1CABC09.mlw
sha1: dcfaf261aefd6b9dd176143963512a0a87118ccc
sha256: 188ae422779bb5a0c5692848c8b35bd1ea4b7fff3e38bfa86f11b28f99469159
sha512: 2afbec5ce7da2b8f23f683af57f167f733a9258e16dbb42ca5d6a529a8377a469651f98415aca0f29abf792e8dbfbd407cf09ddb9fb6a3e44c56488713e196ae
ssdeep: 6144:HMptDPB7UJVT+NWLDSbU1XzmZ2+GvZXKxAgij8I+KhGuDtmqbc5fz:HCtDpowozB+wZ6+QKgXqGz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010
InternalName: Unsolder
FileVersion: 0.8.52.101
CompanyName: Raxco Software, Inc.
LegalTrademarks: Bread
ProductName: Couriers Aestheticsy
ProductVersion: 0.81.197.204
FileDescription: Concluded Commanding Apartments
OriginalFilename: Upstairsl.EXE

Trojan.TeslaCrypt.EF also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.TeslaCrypt.EF
FireEyeGeneric.mg.f4a4f123cf09c99c
CAT-QuickHealRansom.Teslacrypt.OL4
McAfeeRansomware-FHE!F4A4F123CF09
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004e12bb1 )
BitDefenderTrojan.TeslaCrypt.EF
K7GWTrojan ( 004e12bb1 )
Cybereasonmalicious.3cf09c
BitDefenderThetaGen:NN.ZexaF.34590.xq2@a44Xg2oO
SymantecTrojan.Gen
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM2
AvastWin32:Papras-AT [Trj]
KasperskyPacked.Win32.Tpyn
AlibabaTrojan:Win32/Kryptik.5429e498
NANO-AntivirusTrojan.Win32.AVKill.ebcwrs
ViRobotTrojan.Win32.TeslaCrypt.Gen.D
Ad-AwareTrojan.TeslaCrypt.EF
TACHYONTrojan/W32.Ransom.389120.B
EmsisoftTrojan.TeslaCrypt.EF (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.AVKill.60714
ZillyaTrojan.CryptGen.Win32.1
TrendMicroRansom_HPCRYPTESLA.SM2
McAfee-GW-EditionRansomware-FHE!F4A4F123CF09
SophosML/PE-A + Mal/Ransom-EM
SentinelOneStatic AI – Malicious PE
JiangminPacked.Tpyn.afc
eGambitUnsafe.AI_Score_100%
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Tescrypt!rfn
ArcabitTrojan.TeslaCrypt.EF
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmPacked.Win32.Tpyn
GDataTrojan.TeslaCrypt.EF
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Lockycrypt.Gen
VBA32BScope.Trojan.AVKill
ALYacTrojan.TeslaCrypt.EF
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HDJG
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.Bitman!NxneeS5Ar4w
IkarusTrojan-Ransom.TeslaCrypt4
FortinetW32/Kryptik.ESFA!tr
AVGWin32:Papras-AT [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.Bitman.HwcBZd8A

How to remove Trojan.TeslaCrypt.EF?

Trojan.TeslaCrypt.EF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment