Malware

How to remove “Tedy.388714”?

Malware Removal

The Tedy.388714 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.388714 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • A HTTP/S link was seen in a script or command line
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Appears to use command line obfuscation
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Tedy.388714?


File Info:

name: 4DC21502903B9C961660.mlw
path: /opt/CAPEv2/storage/binaries/677a56f6a8614d664f688d194528c869bb549c755397b607a8cb9f5943a625bc
crc32: 4B21EA85
md5: 4dc21502903b9c961660b30336bb6eac
sha1: 996a3289f9f1e50340abe4c070b16acb9228a89d
sha256: 677a56f6a8614d664f688d194528c869bb549c755397b607a8cb9f5943a625bc
sha512: d5567d9b5c719dc3e50efe6b6bdae71895aa510ee5d06e4ffa5813a93fc031e1171c3e51a161f6d85ca872bd19e6342d671c20123e30b2248bca528eb3fa36ca
ssdeep: 98304:ib3wjA7ai2CorCRebFsyewVWLs4wHMCwpdK5qYUImFhfe:ib3wjA7ai2BrbseVWgVMCwp1tm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174F5120C5243B79DCC60773B8E6AAF16DAF41D54E06980EE7AC0BA37E6B5E42053D352
sha3_384: 78dd437a0df0c0bd1bcc66d096f384ca7e549d0b7f6189fb1806e2900d20c3c92b2f425d80ce53da4e2d182fb3e7dc59
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2019-12-16 00:50:56

Version Info:

Comments: Left Hook Deliv
FileDescription: Make Descision Soft
FileVersion: 4.5.23.2
InternalName: Incirim Nolweas
LegalCopyright: (C) Software Inc.
LegalTrademarks: Software
Translation: 0x0409 0x04e4

Tedy.388714 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
DrWebTrojan.PWS.Stealer.35843
MicroWorld-eScanGen:Variant.Tedy.388714
ClamAVWin.Packed.Razy-9894224-0
FireEyeGeneric.mg.4dc21502903b9c96
McAfeeArtemis!4DC21502903B
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Coins.Win32.7948
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005a57ac1 )
AlibabaTrojanSpy:Win32/Stealer.58247722
K7GWTrojan ( 005a57ac1 )
Cybereasonmalicious.9f9f1e
CyrenW32/ABRisk.XDEX-7158
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.dkei
BitDefenderGen:Variant.Tedy.388714
AvastWin32:Malware-gen
TencentWin32.Trojan-QQPass.QQRob.Tgil
EmsisoftTrojan.Packed (A)
F-SecureTrojan.TR/PSW.Coins.rfupq
VIPREGen:Variant.Tedy.388714
TrendMicroTROJ_GEN.R002C0XEQ23
McAfee-GW-EditionBehavesLike.Win32.DStudio.wc
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
GDataGen:Variant.Tedy.388714
AviraHEUR/AGEN.1338066
MAXmalware (ai score=89)
ArcabitTrojan.Tedy.D5EE6A
ZoneAlarmHEUR:Trojan-PSW.Win32.Coins.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R441806
Acronissuspicious
ALYacGen:Variant.Tedy.388714
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0XEQ23
RisingTrojan.IPLogger/NSIS!1.C696 (CLASSIC)
FortinetPossibleThreat.PALLAS.H
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Tedy.388714?

Tedy.388714 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment