Malware

Tedy.1468 (file analysis)

Malware Removal

The Tedy.1468 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.1468 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Tedy.1468?


File Info:

name: 48C11B7199CCB25AA798.mlw
path: /opt/CAPEv2/storage/binaries/db73233807fe61d51c2ac34d27f0b4a5df3aee137a79aff63f4497a2b0ae5bf3
crc32: 455C0816
md5: 48c11b7199ccb25aa798eefcb79f11f9
sha1: 8e800788217bb2ef0135e4d3270d9e90e0465073
sha256: db73233807fe61d51c2ac34d27f0b4a5df3aee137a79aff63f4497a2b0ae5bf3
sha512: ffbd0b6a8485cad07e19b650629971a4c9ac0a5f68a6a212b60b5608b9495f01fc9a86e0b51b6ab6c2036824e38267a77fab36420c3f71f9eb62e5084f281dd0
ssdeep: 3072:ix9Yv+zANQrsrQwg/gngvQjA7AnJCag3JCZJCrwigRgHFTFggHgnQqQlQiwewDQM:igGora8zo0Ysru7gHT/A1ultJMsMP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8D357B672D4389AF05B2974267E03720CFA548D264712923BB79FEBAF55FC0C0645A3
sha3_384: 31bd4b1c8af3dd92a84f49e0d7ef194ef318048d9bb7778cb8a993b3cd6b5da195ac762dc6bfc7ea756af3871dcb9c02
ep_bytes: 68c4124000e8f0ffffff000048000000
timestamp: 2010-07-24 14:15:22

Version Info:

Translation: 0x0409 0x04b0
ProductName: patYABkw
FileVersion: 5.30
ProductVersion: 5.30
InternalName: patYABkw
OriginalFilename: patYABkw.exe

Tedy.1468 also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-BLX [Wrm]
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop1.40423
MicroWorld-eScanGen:Variant.Tedy.1468
FireEyeGeneric.mg.48c11b7199ccb25a
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeDownloader-CJX.gen.g
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWNetWorm ( 700000151 )
K7AntiVirusNetWorm ( 700000151 )
BitDefenderThetaAI:Packer.E3F1AE6A20
VirITTrojan.Win32.Inject.UN
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.RU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1162
KasperskyTrojan.Win32.Vobfus.avvo
BitDefenderGen:Variant.Tedy.1468
NANO-AntivirusTrojan.Win32.VB.cojaqg
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Alg]
AvastWin32:AutoRun-BLX [Wrm]
EmsisoftGen:Variant.Tedy.1468 (B)
F-SecureWorm:W32/Vobfus.BS
BaiduWin32.Trojan.VB.a
TrendMicroWORM_VB.SMRX
Trapminesuspicious.low.ml.score
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
JiangminWorm.WBNA.boim
VaristW32/Vobfus.E.gen!Eldorado
AviraWORM/VBNA.kasww
MAXmalware (ai score=84)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.VB.SWA@527lh3
ArcabitTrojan.Tedy.D5BC
ViRobotWorm.Win32.A.VBNA.141312
ZoneAlarmTrojan.Win32.Vobfus.avvo
GDataGen:Variant.Tedy.1468
GoogleDetected
AhnLab-V3Win32/Vbna4.worm.Gen
VBA32TScope.Trojan.VB
ALYacGen:Variant.Tedy.1468
TACHYONWorm/W32.VB-Agent.141312.B
Cylanceunsafe
PandaW32/VobfusLNK.A
TrendMicro-HouseCallWORM_VB.SMRX
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.1231436.susgen
FortinetW32/VBObfus.BDBD!tr
Cybereasonmalicious.199ccb
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Tedy.1468?

Tedy.1468 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment