Ransom

About “Ransom.Tedy.66” infection

Malware Removal

The Ransom.Tedy.66 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Tedy.66 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine Ransom.Tedy.66?


File Info:

name: 528B4C4890D83A285922.mlw
path: /opt/CAPEv2/storage/binaries/a3298e4d57494d2b61f603d5f9c76f916e32dfa96950720dddb08b1f90d81ade
crc32: F72C32C9
md5: 528b4c4890d83a28592268c07fc3cd27
sha1: d2547ba245cf4c967bae623f83fbb39e8467a917
sha256: a3298e4d57494d2b61f603d5f9c76f916e32dfa96950720dddb08b1f90d81ade
sha512: b5025d57774d3215826f0e9adc56d3dee7a5581f1e6e0b221964172f0c20fe7b7d40128a046ee9a36768084ed98bbae7defa729d3f1d994c5105acdd04e9eb04
ssdeep: 6144:FZ3JiNN0ee2NEgJ4UgUNIFCRIBDdP/QA4EVX+t4TrHB4BF8:FZ3owANYUg8IFAIBmyVX+t4TDBl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18D64BF01BAC189B2D5720D325A799B21697DBC301F25CADBB3EC766DDB312C09631B63
sha3_384: 07f9a9f9b0b3386d4b8a4422ca308bdd018027970ab6bc55dfd170aa88e89cfa96a4be61ba41246fad91574e946d15ab
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2021-10-08 08:51:51

Version Info:

0: [No Data]

Ransom.Tedy.66 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Tedy.4!c
MicroWorld-eScanGen:Variant.Ransom.Tedy.66
FireEyeGen:Variant.Ransom.Tedy.66
McAfeeArtemis!528B4C4890D8
ZillyaTrojan.Bingoml.Win32.7603
SangforPUP.BAT.CleanLog.A
ESET-NOD32BAT/CleanLog.A potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002H09B922
AvastWin32:Malware-gen
BitDefenderGen:Variant.Ransom.Tedy.66
EmsisoftGen:Variant.Ransom.Tedy.66 (B)
ComodoMalware@#2lu0fpt5p3bgx
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
GDataGen:Variant.Ransom.Tedy.66
WebrootW32.Trojan.Gen
GridinsoftRansom.Win32.Gen.sa
CynetMalicious (score: 100)
VBA32BScope.Trojan.Meterpreter
ALYacGen:Variant.Ransom.Tedy.66
MAXmalware (ai score=86)
APEXMalicious
FortinetAdware/CleanLog
AVGWin32:Malware-gen

How to remove Ransom.Tedy.66?

Ransom.Tedy.66 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment