Malware

What is “Tedy.16260”?

Malware Removal

The Tedy.16260 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.16260 virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Tedy.16260?


File Info:

name: 2D75ABCF9DD6CA27C17D.mlw
path: /opt/CAPEv2/storage/binaries/0ea8b2c2fc42baf4943e1e838e3ba8caf88b800d1d3a0c0da343ee385e8648af
crc32: 3627C4C9
md5: 2d75abcf9dd6ca27c17d2397aacdfddb
sha1: 3bb8f55d446821db3de0db7478cc4aacfa3c2329
sha256: 0ea8b2c2fc42baf4943e1e838e3ba8caf88b800d1d3a0c0da343ee385e8648af
sha512: f566f0a2df7c439d69b2a45e058ee43c2a580eab393bbfe1de6920b9fbe03e25daf0abafeca7bea737000f4886de1ee29565608e84db1da894f4d8fccc22dfd5
ssdeep: 98304:xd2AiLVxYIts5YnmIhjlLjkkoVcLaRVlAusEuWdnJFLdR9jtAXpx9e4MK/OLBglb:xd21ZHmSI/qaduWtVtAXdeK8gMwAVMN
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1419623ED22547358C42E84380433BD09B1B65B3F4AE994B97ACF7BC07B5E815EA85F06
sha3_384: 246f47caae9b63529beb28133d86366e7c979c78020dc72cb6a4cebdbf64c7717fe9b9b3cb53fb4a1e8968aff290c56a
ep_bytes: 68e08c2c17e8d1f381003b45cd7d72d0
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Google Inc.
FileTitle: chrome.exe
FileDescription: Google Chrome
FileVersion: 70,0,3538,110
LegalCopyright: Copyright 2017 Google Inc. All rights reserved.
LegalTrademark:
ProductName: Google Chrome
ProductVersion: 70,0,3538,110
Translation: 0x0409 0x04b0

Tedy.16260 also known as:

LionicTrojan.Win64.Donut.4!c
DrWebTrojan.Siggen15.49509
MicroWorld-eScanGen:Variant.Tedy.16260
FireEyeGeneric.mg.2d75abcf9dd6ca27
McAfeeArtemis!2D75ABCF9DD6
ZillyaTrojan.VMProtect.Win64.8037
SangforTrojan.Win64.Donut.fnh
K7AntiVirusTrojan ( 0058a7761 )
AlibabaTrojan:Win64/Donut.1a1f6515
K7GWTrojan ( 0058a7761 )
Cybereasonmalicious.d44682
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Packed.VMProtect.NP
Paloaltogeneric.ml
KasperskyTrojan.Win64.Donut.fnh
BitDefenderGen:Variant.Tedy.16260
AvastWin64:Evo-gen [Susp]
TencentWin64.Trojan.Donut.Htmj
Ad-AwareGen:Variant.Tedy.16260
EmsisoftGen:Variant.Tedy.16260 (B)
TrendMicroTROJ_GEN.R002C0RKN21
McAfee-GW-EditionBehavesLike.Win64.Drixed.rc
SophosMal/VMProtBad-A
IkarusTrojan.Win64.Vmprotect
GDataGen:Variant.Tedy.16260
AviraHEUR/AGEN.1120077
MAXmalware (ai score=86)
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Tedy.D3F84
ViRobotTrojan.Win32.Z.Vmprotect.9286656
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Trojan-gen.R452980
VBA32Trojan.Win64.Donut
ALYacGen:Variant.Tedy.16260
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R002C0RKN21
eGambitUnsafe.AI_Score_92%
FortinetW32/PossibleThreat
AVGWin64:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.130700304.susgen

How to remove Tedy.16260?

Tedy.16260 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment