Malware

Tedy.151414 (B) removal

Malware Removal

The Tedy.151414 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.151414 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Tedy.151414 (B)?


File Info:

name: 3CE6C99187D20D8812FC.mlw
path: /opt/CAPEv2/storage/binaries/aaff33ebdc6e5d4ede5adf7d7d5c2ead19929cf0653d308bddf835675eb691a6
crc32: 7C9A5D98
md5: 3ce6c99187d20d8812fc2f8e328f3e11
sha1: 50c845b15488311f25db6df97699df3d3c445b00
sha256: aaff33ebdc6e5d4ede5adf7d7d5c2ead19929cf0653d308bddf835675eb691a6
sha512: cfa54d3a46d188f22f175d659aec9de711eda1571bae49c01ea29c3ee9175ba35cf7841d2b496d3d458335d6cc8571298b1e268af39f67142a3ea1484fa5592e
ssdeep: 49152:IPKILQ4PlT4NZ3v02aIqEM8ZBA6wEtqF09/88AVvDF2dAFvNnfCFmjeErBkI26:IPKIEwlsov8ZBAZa908ApD80NjN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17DF5330201E9EDE4E194AB3C0C3A8E26EF25DC1341534A7A51F86DDDB6D2CDC1369DB6
sha3_384: 04cf8256e1908630cfdb160efecb62b6438297b4bb4c929dd59c359df6d5c4d709b7ed715853121d64d9b03014908ce6
ep_bytes: 68a54f2e95e8232b3200e10874da48cc
timestamp: 2022-06-14 17:52:30

Version Info:

CompanyName:
FileDescription: BugReport
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: BugReport
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Tedy.151414 (B) also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Tedy.151414
FireEyeGeneric.mg.3ce6c99187d20d88
ALYacGen:Variant.Tedy.151414
CylanceUnsafe
VIPREGen:Variant.Tedy.151414
K7GWTrojan ( 0059380b1 )
Cybereasonmalicious.154883
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/QQWare.DM
APEXMalicious
BitDefenderGen:Variant.Tedy.151414
NANO-AntivirusTrojan.Win32.Banker1.jqcyyp
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Tedy.151414
EmsisoftGen:Variant.Tedy.151414 (B)
DrWebTrojan.PWS.Banker1.37040
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.wc
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Tedy.151414
AviraTR/QQTen.rguvd
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R499802
McAfeeArtemis!3CE6C99187D2
MalwarebytesTrojan.MalPack.DLF
RisingTrojan.Generic@AI.88 (RDML:c+QZkT2qzhbxT0sroe9PKg)
IkarusTrojan.Win32.QQWare
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/QQWare.DM!tr
BitDefenderThetaGen:NN.ZexaF.34786.m30@ayhVhDlb
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Tedy.151414 (B)?

Tedy.151414 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment