Malware

How to remove “Tedy.13203”?

Malware Removal

The Tedy.13203 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.13203 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Tedy.13203?


File Info:

name: 5DA43826C108C9CCB8E3.mlw
path: /opt/CAPEv2/storage/binaries/0ce75e004bc317473a90654cf4dd67ef2c5ffc6e19b9e11dc3e81d7d76a350cf
crc32: 82EEB16A
md5: 5da43826c108c9ccb8e38a6e8c04164a
sha1: 3357223eb28adcc0ab8693b6b7ad0b1c7d775304
sha256: 0ce75e004bc317473a90654cf4dd67ef2c5ffc6e19b9e11dc3e81d7d76a350cf
sha512: 723d72a4ed0b03c56c4f29e39def7695c368256f98414e4b4a720a0b0ba88eb7fa2fb4bec67239b6cfd93dd8bcbe4a39599b26b9297bac4ab3827ede53d26320
ssdeep: 768:4qVSIcfS/Kcdqfg4wu4I8cSmmN8mb8mb8m3I/TRgEZOnK/K9KrKGK+K7KfKSnMQb:4qVtcx9wd1KnMQOBa+CRYlCO8rco1en
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0740144661145C0F4273CBBC2ECD57F78A677CE580AC67C6958E8E624B7A8623E1F0B
sha3_384: 4eca4817323dbf6d7e92a89b79a5c2c9c785ad2581d4bf33ad3dd457649f787ed11fdec325f4daea224c3168cd7ee87a
ep_bytes: 68b4114000e8eeffffff000000000000
timestamp: 2010-11-07 06:14:41

Version Info:

Translation: 0x0409 0x04b0
ProductName: VAYWJa
FileVersion: 9.10
ProductVersion: 9.10
InternalName: VAYWJa
OriginalFilename: VAYWJa.exe

Tedy.13203 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Tedy.13203
ClamAVWin.Malware.Vobfus-9806879-0
FireEyeGeneric.mg.5da43826c108c9cc
CAT-QuickHealWorm.WbnaMF.S22387675
McAfeeDownloader-CJX.gen.j
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Tedy.13203
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 001f4fd41 )
K7GWTrojan ( 001f4fd41 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.VB.al
VirITWorm.Win32.Generic.EXM
CyrenW32/A-8f807ac2!Eldorado
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.WL
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Tedy.13203
NANO-AntivirusTrojan.Win32.VBKrypt.covjue
SUPERAntiSpywareTrojan.Agent/Gen-Changeup
AvastWin32:Agent-AZYI [Trj]
TencentTrojan.Win32.VBKrypt.hc
TACHYONWorm/W32.VB-WBNA.344064
EmsisoftGen:Variant.Tedy.13203 (B)
F-SecureWorm:W32/Vobfus.AX
DrWebWin32.HLLW.Autoruner.34955
TrendMicroWORM_VBNA.SMCY
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ft
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1G6QWK0
JiangminTrojan/VBKrypt.hcgq
AviraTR/Dldr.Renos.J
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Renos.~AI@3o38oc
ArcabitTrojan.Tedy.D3393
ViRobotTrojan.Win32.A.VBKrypt.339968.AC
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R19485
Acronissuspicious
BitDefenderThetaAI:Packer.D8964AA320
ALYacGen:Variant.Tedy.13203
MAXmalware (ai score=84)
VBA32Worm.WBNA
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VBNA.SMCY
RisingTrojan.Win32.VBCode.ccn (CLASSIC)
YandexTrojan.GenAsa!3xJnv/kHGt8
IkarusWorm.Win32.VBNA
MaxSecureTrojan.Malware.5496659.susgen
FortinetW32/AutoRun.XM!worm
AVGWin32:Agent-AZYI [Trj]
DeepInstinctMALICIOUS

How to remove Tedy.13203?

Tedy.13203 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment