Malware

About “Tedy.166869” infection

Malware Removal

The Tedy.166869 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.166869 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Tedy.166869?


File Info:

name: E8A765F37744CE185AF2.mlw
path: /opt/CAPEv2/storage/binaries/170c975fcc5fe2d88efb48c73907908fbcbd157f77e665ddfad95025ada0a7ed
crc32: 52FED247
md5: e8a765f37744ce185af2010805b672ce
sha1: 7325639f39d63f089575f6f162d265cebf946c69
sha256: 170c975fcc5fe2d88efb48c73907908fbcbd157f77e665ddfad95025ada0a7ed
sha512: 1af07dbf56e6fb9a15e2678a8d5904d8a254f9416c505ddc5b47855868e698ecb8d1071e46ba41a8cf65822dddd1a44f0e203b87ea583ca95ca94723ac95ffd2
ssdeep: 24576:ptTaR+7L01plGWE3+wH+o0tZDfGPbaK2uvjG4Hmwpc6zU3qVuD4:CALgpMz0DfGPb6kjG4XAaVg4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1948533213770E061DDA65770ACB9CE3BA713BC7A1CE1064BBCFA7A6EF4725414016C99
sha3_384: b4e36d2c738652d643e60fa651eff55e250d3170a497f3d83c3d8db67e7d2919009a5f880464f6c793c6b259d702e682
ep_bytes: 558bec81ec20020000565733ff680180
timestamp: 2021-09-25 21:56:18

Version Info:

Comments: Postmestrenes183
CompanyName: Medhjlp Nesty
FileDescription: Postansvarlige Foreknown
FileVersion: 3.0.0.5
OriginalFilename: Norske Antagonismers.exe
Translation: 0x0409 0x04b0

Tedy.166869 also known as:

MicroWorld-eScanGen:Variant.Tedy.166869
FireEyeGen:Variant.Tedy.166869
McAfeeArtemis!E8A765F37744
CylanceUnsafe
AlibabaTrojan:Win32/Shelsy.04728e82
CyrenW32/Ninjector.DR.gen!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32NSIS/Injector.BBF
TrendMicro-HouseCallTROJ_GEN.F0D1C00GE22
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Shelsy.gen
BitDefenderGen:Variant.Tedy.166869
AvastNSIS:InjectorX-gen [Trj]
Ad-AwareGen:Variant.Tedy.166869
VIPREGen:Variant.Tedy.166869
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Tedy.166869 (B)
IkarusTrojan.Inject
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Tedy.166869
MAXmalware (ai score=81)
FortinetNSIS/Injector.AOW!tr
AVGNSIS:InjectorX-gen [Trj]

How to remove Tedy.166869?

Tedy.166869 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment