Malware

Should I remove “Tedy.164012”?

Malware Removal

The Tedy.164012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.164012 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper

How to determine Tedy.164012?


File Info:

name: C6C9D20EB29B8B120948.mlw
path: /opt/CAPEv2/storage/binaries/3c6407c4858480a4117a625b820b7c3394ef6dc6ae2871c843d571c44b894111
crc32: E0214EB4
md5: c6c9d20eb29b8b1209487342739afead
sha1: 1bba6631eb577a346de6e9f6e78bf6101e7a0f1e
sha256: 3c6407c4858480a4117a625b820b7c3394ef6dc6ae2871c843d571c44b894111
sha512: 8efa7db41d02d1e7c9e3a1fc4ba3712c3058311a411f71e054a092bb2d9c1f0da85f2fcbd459546d48cd7af534abde8ed11ba2cdb872fa6568e32b8188b6790b
ssdeep: 12288:lq7z1tUdWcYIaBju/9HK9FkJYlgzaRs5+DEOn6rqGRGKz2nyF:E7TKWcb8m9q9vsh+AO6rcq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5D412523BA4DC67C9100A72CDA8CAFA4775FD52DE40530773D43F6EBDB2641AE1A281
sha3_384: 501b28310e58c63aa68d05d6e14eb6112e401127dde675b57382d8cc8b2a6065b7aa0b5a3c934cecf3bd7f39fa05c356
ep_bytes: 558bec81ec20020000565733ff680180
timestamp: 2021-09-25 21:53:11

Version Info:

Comments: Lapponian Lagerforbrugets
CompanyName: Galvanometre Ahong60 Forhandlerprovisionen Trrestens
FileDescription: PROPOUNDS Driverts Toluyl189
FileVersion: 8.32.24
LegalCopyright: Halset TVESKG
LegalTrademarks: Goosemouth Kovendendes Brsspekulanternes
ProductName: Vredesudbruddets Trochidae Chaldaic Forkastninger
Translation: 0x0409 0x04e4

Tedy.164012 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Shelsy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.164012
FireEyeGen:Variant.Tedy.164012
McAfeeRDN/Generic.dx
CylanceUnsafe
AlibabaTrojan:Win32/Shelsy.58ec7a08
K7GWTrojan ( 005957ef1 )
K7AntiVirusTrojan ( 005957ef1 )
CyrenW32/Trojan.XNAR-4988
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/Injector.AZY
TrendMicro-HouseCallTROJ_GEN.F0D1C00GD22
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Shelsy.gen
BitDefenderGen:Variant.Tedy.164012
APEXMalicious
Ad-AwareGen:Variant.Tedy.164012
EmsisoftGen:Variant.Tedy.164012 (B)
F-SecureTrojan.TR/AD.Nekark.wkgdc
VIPREGen:Variant.Tedy.164012
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.NSIS.Agent
GDataGen:Variant.Tedy.164012
MAXmalware (ai score=82)
ArcabitTrojan.Tedy.D280AC
ZoneAlarmHEUR:Trojan.Win32.Shelsy.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ALYacGen:Variant.Tedy.164012
MalwarebytesTrojan.Dropper.NSIS
AvastNSIS:DropperX-gen [Drp]
TencentWin32.Trojan.Falsesign.Taez
FortinetNSIS/Injector.AOW!tr
AVGNSIS:DropperX-gen [Drp]

How to remove Tedy.164012?

Tedy.164012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment