Malware

Tedy.20702 removal instruction

Malware Removal

The Tedy.20702 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.20702 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Tedy.20702?


File Info:

name: 93792096D5A30C87DA24.mlw
path: /opt/CAPEv2/storage/binaries/cb5c358c36799aff906bf42de7d289d66599a9d4e5fc5bbd94d9e912ab4ea7be
crc32: 7B852B05
md5: 93792096d5a30c87da245dc54b8ee41d
sha1: d2b716a7aac10d41b38a70fa9f94fff4212a0c20
sha256: cb5c358c36799aff906bf42de7d289d66599a9d4e5fc5bbd94d9e912ab4ea7be
sha512: dfbf53b28eb50be754881cdaafd105b813afe5200e1e1798fd9d81bf4df4ef88f1e18c1c469d6883d6ce386f4db4805f0d3d5c2295d6f1f78f2c9ca87faecb2c
ssdeep: 196608:rPEbGXVFICteEroXxoczlxZV3Gu5D4S26/CS3kV3XMCZCHC5r:7EeInEroXF14S26y3cCZh
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1FA763310B6E81CFEE9BB843AC428C826D1B274214394D55F27ACD62B4F676E17E36F44
sha3_384: cd5df5afdca15254b21a6db5ce721c6e8e426282a9a070e66c1c963017e4bef7cf7eb4f150378edab51df45bcac67e2a
ep_bytes: 4883ec28e8f70400004883c428e972fe
timestamp: 2021-11-09 18:03:59

Version Info:

0: [No Data]

Tedy.20702 also known as:

MicroWorld-eScanGen:Variant.Tedy.20702
FireEyeGen:Variant.Tedy.20702
McAfeeArtemis!93792096D5A3
ZillyaTrojan.Agent.Script.1642598
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002H09L421
BitDefenderGen:Variant.Tedy.20702
AvastFileRepMalware
McAfee-GW-EditionBehavesLike.Win64.HToolLazagne.wc
EmsisoftGen:Variant.Tedy.20702 (B)
JiangminTrojan.Agentb.kqi
Antiy-AVLTrojan/Generic.ASMalwS.34CE845
MicrosoftProgram:Win32/Uwamson.A!ml
GridinsoftRansom.Win64.Sabsik.sa
ViRobotTrojan.Win32.Z.Tedy.7340519
GDataGen:Variant.Tedy.20702
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.PySpy.C4768358
MAXmalware (ai score=85)
AVGFileRepMalware

How to remove Tedy.20702?

Tedy.20702 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment