Malware

About “Win32:Teerac-BX [Trj]” infection

Malware Removal

The Win32:Teerac-BX [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Teerac-BX [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Harvests information related to installed mail clients
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:Teerac-BX [Trj]?


File Info:

name: 1525EFE350BC16BEC22E.mlw
path: /opt/CAPEv2/storage/binaries/0e2e95351ab654047dd0129d8b53868bbd0e497c160b3445f4a53023fa113c45
crc32: ECD4D642
md5: 1525efe350bc16bec22ebae99722798a
sha1: 39f359c8c7791fb3c13beb1828e5e70e68cd5c3d
sha256: 0e2e95351ab654047dd0129d8b53868bbd0e497c160b3445f4a53023fa113c45
sha512: 50c4877b18cab43c869cc8b40c7fffa8751cf3f98829683a2725fba7b2a6277d8294eaad33122ccb8ef9d671e546242699f4c7e647780f3f245c996593e115c6
ssdeep: 6144:I4jkAI8OLA/sK2MZj2Pp5Ytbn8FxA6iXj+teSNrsOxQbIS+vb:IYLI8OkH2MZjfuclXCmrB+z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16984CEDAF4C0D3A2EB64863054D5E90043B6B8BFAD998D4B78C9620FC462703A437C6F
sha3_384: 26cde4cdf7a8cf657b6445fc47faf17fb7b4fd2fd3039ace8a76b4b240c4eaffcc83fa8aec6af9101857f5eb9587725b
ep_bytes: 558bec6aff6800554100682c3f410064
timestamp: 2006-01-13 14:18:22

Version Info:

Comments: Samplers
CompanyName: ETIAM
FileDescription: Pelicans Menagerie Prostrate
FileVersion: 45, 146, 66, 5
InternalName: Pleasure
LegalCopyright: Copyright (C) 1578
LegalTrademarks: Placentas
OriginalFilename: Outright.EXE
PrivateBuild: Quids
ProductName: Parked Planetarium
ProductVersion: 18, 142, 154, 120
SpecialBuild: Raindrop

Win32:Teerac-BX [Trj] also known as:

LionicTrojan.Win32.Androm.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Cripack.Gen.1
FireEyeGeneric.mg.1525efe350bc16be
Cylanceunsafe
ZillyaBackdoor.Androm.Win32.23621
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Androm.3906690c
K7GWTrojan ( 0055e3ef1 )
K7AntiVirusTrojan ( 0055e3ef1 )
ArcabitTrojan.Cripack.Gen.1
VirITTrojan.Win32.Crypt_s.ITC
SymantecRansom.Cryptolock!gm
ESET-NOD32Win32/Filecoder.TorrentLocker.A
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Androm.hrsk
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.Androm.dumkpl
AvastWin32:Teerac-BX [Trj]
TencentWin32.Backdoor.Androm.Ddhl
EmsisoftTrojan.Cripack.Gen.1 (B)
DrWebTrojan.Encoder.1215
VIPRETrojan.Cripack.Gen.1
TrendMicroTROJ_HPMYAPP.SMB1
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1205652
XcitiumMalware@#y2zxl5vv9o1o
MicrosoftRansom:Win32/Teerac
GDataTrojan.Cripack.Gen.1
GoogleDetected
McAfeeArtemis!1525EFE350BC
MAXmalware (ai score=81)
VBA32Backdoor.Androm
TrendMicro-HouseCallTROJ_HPMYAPP.SMB1
RisingMalware.FakePDF/ICON!1.D51A (CLASSIC)
YandexTrojan.GenAsa!2Eq3NzlPxyA
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Deshacop.XO!tr
BitDefenderThetaGen:NN.ZexaF.36308.wq3@aCY3Isai
AVGWin32:Teerac-BX [Trj]
Cybereasonmalicious.350bc1
PandaTrj/Genetic.gen

How to remove Win32:Teerac-BX [Trj]?

Win32:Teerac-BX [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment