Malware

Win32:TeslaCrypt-GV [Trj] removal tips

Malware Removal

The Win32:TeslaCrypt-GV [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:TeslaCrypt-GV [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32:TeslaCrypt-GV [Trj]?


File Info:

name: D75D5490343D34F8A80F.mlw
path: /opt/CAPEv2/storage/binaries/920e1a5524fe18d2044c5a1a3bda9803ebb1f314f75e97a90649ec6d3c33ecc9
crc32: CA6BE629
md5: d75d5490343d34f8a80fd26c8000912a
sha1: 8111dc8ef153ecb613633a95faa46d282afc4668
sha256: 920e1a5524fe18d2044c5a1a3bda9803ebb1f314f75e97a90649ec6d3c33ecc9
sha512: 17205de64bbcb0185ebcf66147c457900f55578e0028c2c0aab76d1136217a54cb4be2fc75fa7c7c1ef6511d14adcff97597c8b2de8f343a6b3a4a73ce549db4
ssdeep: 6144:FIRjn6O/9cWgwLv2KpXal+YtvNxTPPHLnT6h:FItnb/9cuLv2KpXy1J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A34E0C296F64932F02F5BF54C4B0A62C142A4397D66B9C397BAF96848C1170F1FE53A
sha3_384: 6d1c56c90b11cd259540e649483a2c0f902089bcd154ad6f5e388fb19c303a9b259b55903643c24b5ff1b2e5b33686a3
ep_bytes: 558bec6aff681071430068e06a430064
timestamp: 2006-03-28 10:59:39

Version Info:

Comments:
CompanyName: Microsoft
FileDescription: Disillusion
FileVersion: 208, 158, 69, 237
InternalName: Lameness
LegalCopyright: Flanges © 1823
OriginalFilename: Elation.exe
ProductName: Microsoft Imagined

Win32:TeslaCrypt-GV [Trj] also known as:

LionicTrojan.Win32.Deshacop.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Cripack.Gen.1
FireEyeGeneric.mg.d75d5490343d34f8
CAT-QuickHealRansom.Tescrypt.MUE.A4
McAfeeTeslaCrypt!D75D5490343D
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.655
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004d82721 )
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 004d82721 )
Cybereasonmalicious.0343d3
BitDefenderThetaGen:NN.ZexaF.34212.oq0@a0ivo4ni
VirITFraudTool.WinRecovery.D
SymantecRansom.TeslaCrypt
ESET-NOD32Win32/Filecoder.TeslaCrypt.D
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
Paloaltogeneric.ml
KasperskyTrojan.Win32.Deshacop.jz
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.Deshacop.dvelkx
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
APEXMalicious
TencentMalware.Win32.Gencirc.10c73d70
Ad-AwareTrojan.Cripack.Gen.1
SophosMal/Generic-R + Mal/Tinba-N
ComodoMalware@#3w1mvufj3qwf6
DrWebTrojan.DownLoader15.41813
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103BL20
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.Cripack.Gen.1 (B)
IkarusTrojan.FileCryptor
GDataTrojan.Cripack.Gen.1
JiangminTrojan/Deshacop.bm
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1246128
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.13622DF
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ViRobotTrojan.Win32.U.Agent.237568.F
MicrosoftRansom:Win32/Tescrypt!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Teslacrypt.R163688
Acronissuspicious
TACHYONTrojan/W32.Deshacop.237568
VBA32Trojan.Deshacop
MalwarebytesTrojan.Backint.CRPGen
AvastWin32:TeslaCrypt-GV [Trj]
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.Deshacop!edGqKxFpUZc
SentinelOneStatic AI – Malicious PE
FortinetW32/Bublik.DA!tr
AVGWin32:TeslaCrypt-GV [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:TeslaCrypt-GV [Trj]?

Win32:TeslaCrypt-GV [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment