Trojan

Trojan.TeslaCrypt.X removal tips

Malware Removal

The Trojan.TeslaCrypt.X is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.TeslaCrypt.X virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by registry key

How to determine Trojan.TeslaCrypt.X?


File Info:

crc32: 09B85158
md5: 08969bf3286213dacfb9d59736e6e1de
name: 08969BF3286213DACFB9D59736E6E1DE.mlw
sha1: e297483419c552773bff90821b920879fc484a84
sha256: 315542b849cefd7d3578f0b61b068baa1ad7b0aa61c913f91865013514603d5e
sha512: e3575a3b45b1058c1c42045db1bf1605ea1393f08ef4bb116d6c410780ad9714f479e6cfbf6c95e6af98ebfd1b1ded08677df29ae9a192120b2cabe33328f7ff
ssdeep: 12288:n5a605fnhBdZcTP+WzyfCMEXkzSZsfqBM6AmVbF:nc6abcTP+oXkzSmqBImVb
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2014
InternalName: Filters
FileVersion: 0.199.255.216
CompanyName: Mz Ultimate Tools
PrivateBuild: 84, 223, 84, 156
LegalTrademarks: Lunar
Comments: Libertarianism
ProductName: Lunatics Hulled
SpecialBuild: 0.78.78.235
ProductVersion: 0.170.47.35
FileDescription: Element Ferreted Ensuring
OriginalFilename: Hummerl.EXE

Trojan.TeslaCrypt.X also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004de5a11 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3933
CynetMalicious (score: 100)
ALYacTrojan.TeslaCrypt.X
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 004de5a11 )
Cybereasonmalicious.328621
BaiduWin32.Trojan.Filecoder.k
SymantecRansom.TeslaCrypt!g4
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Shifu.g
BitDefenderTrojan.TeslaCrypt.X
NANO-AntivirusTrojan.Win32.Shifu.eaiuvx
MicroWorld-eScanTrojan.TeslaCrypt.X
Ad-AwareTrojan.TeslaCrypt.X
SophosMal/Ransom-EC
BitDefenderThetaGen:NN.ZexaF.34110.JmKfaSM@RUob
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SMJ5
McAfee-GW-EditionGenericRXKO-WF!2C09F3C45FD4
FireEyeGeneric.mg.08969bf3286213da
EmsisoftTrojan.TeslaCrypt.X (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.Shifu.dn
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.171EFA7
MicrosoftTrojan:Win32/Ditertag.A
ArcabitTrojan.TeslaCrypt.X
GDataTrojan.TeslaCrypt.X
TACHYONBanker/W32.Shifu.638976
McAfeeArtemis!08969BF32862
MAXmalware (ai score=100)
VBA32TrojanBanker.Shifu
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTESLA.SMJ5
RisingTrojan.Agent!1.A322 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EOVH!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.TeslaCrypt.X?

Trojan.TeslaCrypt.X removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment