Malware

Tedy.104681 removal guide

Malware Removal

The Tedy.104681 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.104681 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Tedy.104681?


File Info:

name: E866BE162D5CAE8865D1.mlw
path: /opt/CAPEv2/storage/binaries/726f13ba97025d639e15fc0a998a8b1ad60ecaf86e542c5573d54ada26178442
crc32: 1275C419
md5: e866be162d5cae8865d1871f8ce8a588
sha1: b7db5bd86460cb4292fdf467229fc469e2d7fff6
sha256: 726f13ba97025d639e15fc0a998a8b1ad60ecaf86e542c5573d54ada26178442
sha512: 5e9f5bbeb1f9701e2e8f5ad6d42dfd74942940ebfd0fe8d2b5a2e489538c1c3469d3bb08012d2472b38ff95bd53da8d13140544357f6a576d1473600465f8553
ssdeep: 24576:b8s1dXj862Bu4kAELy/EJDZPieWBIHzeJyM5GDQTYB1zA4:bn862Bu4oLyeZ6eWOHzeJyVD5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8756C03F641C077C2151630987BA7347B78EE664A15DB57B3E9EEB82E333219E1A14B
sha3_384: 40a2f4316939456bafc4c6db5e3d0a99ee5dbbbc169590ec788bbaa8f26e8fd6bf047c498bc047a1a7688a09de4cde3b
ep_bytes: e8f4040000e97afeffffcccccccccccc
timestamp: 2022-10-19 06:17:55

Version Info:

0: [No Data]

Tedy.104681 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Scar.mip4
MicroWorld-eScanGen:Variant.Tedy.104681
FireEyeGeneric.mg.e866be162d5cae88
CAT-QuickHealRansom.Gimemo.6806
ALYacGen:Variant.Tedy.104681
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005848221 )
CrowdStrikewin/malicious_confidence_70% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderGen:Variant.Tedy.104681
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Tedy.104681
EmsisoftGen:Variant.Tedy.104681 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
VIPREGen:Variant.Tedy.104681
McAfee-GW-EditionBehavesLike.Win32.BadFile.tm
SophosGeneric ML PUA (PUA)
GDataWin32.Trojan.PSE.1G80G6X
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitTrojan.Tedy.D198E9
MicrosoftTrojan:Win32/Wacatac.A!ml
AhnLab-V3Trojan/Win.Generic.C5285790
Acronissuspicious
McAfeeArtemis!E866BE162D5C
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H09JO22
RisingTrojan.Generic@AI.85 (RDML:fyWDjqa/NJHBDrOYRtFVuw)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
BitDefenderThetaGen:NN.ZexaF.34726.HvW@a8aOn4cb
AVGWin32:Malware-gen

How to remove Tedy.104681?

Tedy.104681 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment