Malware

About “Tedy.151472” infection

Malware Removal

The Tedy.151472 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.151472 virus can do?

  • Dynamic (imported) function loading detected
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Tedy.151472?


File Info:

name: 4B46C3FC1615A35FF0E5.mlw
path: /opt/CAPEv2/storage/binaries/d7d7ab3fbaed266cdfe5d950a1119259a2c777a63ab969bb3529b2747d261005
crc32: 3CC4557B
md5: 4b46c3fc1615a35ff0e54c892b5bca8a
sha1: 7ee4d7bad250907d3792a59025655e50cd74fd1e
sha256: d7d7ab3fbaed266cdfe5d950a1119259a2c777a63ab969bb3529b2747d261005
sha512: b24bb8f20103f9faea729560f12c4df573325700bcf4482fa3a7e3bce9fe8adf1d74f2962c5490fff463254164484d23f42ec8952bb01ec4f2b5db8cedf18ecf
ssdeep: 49152:6ZYgATtZa7R9rnwu5DB+XzFEum7+dj0K4hJ:KAXO7rwQmFqajY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9752358B290B5DFC972C4329DA50E75EB2034BB9B1F8303945B65ED881DB9ACF190F2
sha3_384: 11011e31a60b739eb795ef9fde9e1b1458433c8d7538cbeda101b5c17fb9e6800df747bbd3ecb6db9c12094633e4c923
ep_bytes: ff250020400000000000000000000000
timestamp: 2072-08-03 03:38:36

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Ghifile
FileVersion: 1.0.0.0
InternalName: Ghifile.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: Ghifile.exe
ProductName: Ghifile
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Tedy.151472 also known as:

BkavW32.AIDetectNet.01
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Tedy.151472
FireEyeGeneric.mg.4b46c3fc1615a35f
ALYacGen:Variant.Tedy.151472
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00594f4c1 )
K7GWTrojan ( 00594f4c1 )
Cybereasonmalicious.ad2509
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FNS
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Tedy.151472
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Tedy.151472
EmsisoftGen:Variant.Tedy.151472 (B)
VIPREGen:Variant.Tedy.151472
TrendMicroTROJ_GEN.R03BC0WG122
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Tedy.151472
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=89)
ArcabitTrojan.Tedy.D24FB0
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win.Generic.C5185551
McAfeeArtemis!4B46C3FC1615
MalwarebytesMachineLearning/Anomalous.100%
RisingTrojan.Generic/MSIL@AI.96 (RDM.MSIL:BYJNJRkm5DBoQV4xTDmJkw)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.FNP!tr
BitDefenderThetaGen:NN.ZemsilF.34742.Ln0@aOKmdHh
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Tedy.151472?

Tedy.151472 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment