Malware

About “Tedy.1184” infection

Malware Removal

The Tedy.1184 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.1184 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Tedy.1184?


File Info:

name: F59F6BBB9DFE3273BB3E.mlw
path: /opt/CAPEv2/storage/binaries/cbb027bab0623938f3852e4552a6aed4f7f77f4e289baeb728dc205c8eada49e
crc32: 05903225
md5: f59f6bbb9dfe3273bb3e2f372e86a4fe
sha1: a467650509174d8d1126f7c4f3f8e33b73fceb0f
sha256: cbb027bab0623938f3852e4552a6aed4f7f77f4e289baeb728dc205c8eada49e
sha512: 0b976e7cafb78de6d2193e5d1ae4d11fe9c3456ca8c372c45092decdc326cf047b8775ab9ef1b907cb2facca018682e559355ee4af2b2e4c9b09688be9bbfece
ssdeep: 3072:YcVaQvJvKi6MzIIVlz9Pq4wOBS+lFEYZ:ZVaQvJvv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18854052082D66657D8EA4DF85B5BE0FA252DF1BD256B3840384F5E381708EC4E712BBD
sha3_384: f1c83c8ee2236ab218adecf1d174c08c380a447ddf17c9a6c5e4471bb1a80f0d8f27234f89ca4cdfcef3f80ebabd9f1b
ep_bytes: 68ac114000e8f0ffffff000000000000
timestamp: 2010-10-12 12:33:19

Version Info:

Translation: 0x0409 0x04b0
ProductName:
FileVersion: 6.70
ProductVersion: 6.70
InternalName: uWAAI
OriginalFilename: uWAAI.exe

Tedy.1184 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.tpoP
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Tedy.1184
FireEyeGeneric.mg.f59f6bbb9dfe3273
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.dt
ALYacGen:Variant.Tedy.1184
Cylanceunsafe
ZillyaWorm.WBNA.Win32.1393235
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 001f4fd41 )
AlibabaWorm:Win32/vobfus.1030
K7GWTrojan ( 001f4fd41 )
Cybereasonmalicious.509174
ArcabitTrojan.Tedy.D4A0
BitDefenderThetaGen:NN.ZevbaF.36744.sm0@a0Hkl2pi
VirITWorm.Win32.VB.DK
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.VT
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1313
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Tedy.1184
NANO-AntivirusTrojan.Win32.VBKrypt.cnwqnm
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert
AvastWin32:AutoRun-BPR [Wrm]
TencentWorm.Win32.Wbna.za
EmsisoftGen:Variant.Tedy.1184 (B)
BaiduWin32.Worm.VB.al
F-SecureTrojan.TR/Dldr.Sasfis.D.1
DrWebWin32.HLLW.Autoruner.32973
VIPREGen:Variant.Tedy.1184
TrendMicroWORM_VB.SMRZ
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-D
IkarusWorm.Win32.Vobfus
JiangminTrojan/VBKrypt.hcpq
WebrootW32.Trojan.Gen
VaristW32/Vobfus.K.gen!Eldorado
AviraTR/Dldr.Sasfis.D.1
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Trojan.Vbkrypt.~nto@28u0gd
MicrosoftWorm:Win32/Vobfus!pz
ViRobotTrojan.Win32.Downloader.294912.AC
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.Tedy.1184
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R19328
McAfeeDownloader-CJX.gen.an
MAXmalware (ai score=86)
VBA32Trojan.VBKrypt
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallWORM_VB.SMRZ
RisingWorm.Vobfus!8.10E (TFE:3:4FjkerkWMPT)
YandexTrojan.GenAsa!76963Rv6XAg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.5496659.susgen
FortinetW32/AutoRun.VBB!tr
AVGWin32:AutoRun-BPR [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Tedy.1184?

Tedy.1184 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment