Malware

Tedy.37704 removal instruction

Malware Removal

The Tedy.37704 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.37704 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Tedy.37704?


File Info:

name: 2A35FD90F20FA17E73F4.mlw
path: /opt/CAPEv2/storage/binaries/c3ab373e53b3cf80d45a96a55567bdaba49a32668134cfd8b26ff4b24949eb13
crc32: C24088A7
md5: 2a35fd90f20fa17e73f4776e6e18e93e
sha1: 0d96cf48d562c0a924250662c8cdb311bd562245
sha256: c3ab373e53b3cf80d45a96a55567bdaba49a32668134cfd8b26ff4b24949eb13
sha512: 25d2e0b68b983e44c6f13da52e30f44aa88e9e2801ae99a6e7b751e3caa675d2047e629c6a958981561e70e740d48008b86f325f46424781a8517d0f1c8c3ef0
ssdeep: 768:gyd7ERIHwxedxzmrh3dYZt485xic1DrzYcHeWDZ7:t5eJ+KBdYn5x1B6cN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135135F1B62DE7EE1C5B91B35373343C1C3ACDE058603DA6E7DD861589ABA2037A523C9
sha3_384: 0f27548caa64d9b1c3a79714f0ce26c91256681a04d0a31ee7a8c317561e4543763a7311f760dec19de7efbaf5c79270
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-04-13 19:04:02

Version Info:

Translation: 0x0000 0x04b0
FileDescription: A _ X Downloader Beta
FileVersion: 1.0.0.0
InternalName: A _ X Downloader Beta.exe
LegalCopyright: Copyright © 2015
OriginalFilename: A _ X Downloader Beta.exe
ProductName: A _ X Downloader Beta
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Tedy.37704 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.37704
FireEyeGeneric.mg.2a35fd90f20fa17e
McAfeeRDN/Generic Downloader.x
SangforTrojan.Win32.Agent.abcbb
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Tedy.37704
K7GWTrojan ( 700000121 )
Cybereasonmalicious.8d562c
BitDefenderThetaGen:NN.ZemsilF.34062.cq1@aqxs4vi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R02DC0PKR21
KasperskyTrojan-Downloader.Win32.Agent.abcbb
NANO-AntivirusTrojan.Win32.Agent.dztmtw
Ad-AwareGen:Variant.Tedy.37704
EmsisoftGen:Variant.Tedy.37704 (B)
DrWebTrojan.DownLoader13.3942
TrendMicroTROJ_GEN.R02DC0PKR21
McAfee-GW-EditionRDN/Generic Downloader.x
SentinelOneStatic AI – Malicious PE
SophosML/PE-A
APEXMalicious
JiangminTrojanDownloader.Agent.epwr
AviraHEUR/AGEN.1112009
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.1056763
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Tedy.D9348
GDataGen:Variant.Tedy.37704
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R453251
PandaTrj/CI.A
TencentMalware.Win32.Gencirc.114ccf44
FortinetW32/Agent.ABCBB!tr.dldr
AVGWin32:GenMaliciousA-SPX [Trj]
AvastWin32:GenMaliciousA-SPX [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Tedy.37704?

Tedy.37704 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment