Malware

What is “Tedy.444188”?

Malware Removal

The Tedy.444188 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.444188 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Tedy.444188?


File Info:

name: E4B28C02F7CD787FEF1C.mlw
path: /opt/CAPEv2/storage/binaries/6fb011cce576f6eb308a9ca2500da52156d1c5af9e3b97e1f01c01e78cce7dbb
crc32: D8F76E95
md5: e4b28c02f7cd787fef1c4e38c0fe88cb
sha1: 1dfeb30f2c2fbb0fc93f92ebd73a95027128fbe6
sha256: 6fb011cce576f6eb308a9ca2500da52156d1c5af9e3b97e1f01c01e78cce7dbb
sha512: cf6aaa723d82f85fe3a89772cc0e5a3ddd58fcbd2d7160cc58b1d0bddd7f0a932835d5d330c544c5f9580e75d810fe01419cb4232efbd5123868d3e4238caa4d
ssdeep: 12288:/QHEoS9P1Txt5PFm3hXKSMSrj1wiXtcxnjYTDR/:/QHCP1Txt5PFm3hXKSMSnlTDR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AFC4D005B9A0C4ADD4FF01BC48B64B994DB8DA1245117907B2362E973EED136AC4FEEC
sha3_384: 1cffc965d27420ef9b6862ff82ace8ab852d3c6d5e5aa37afccbe1fd8f6b25160ad5583a4b3a7648a2c20dfebc8d7dea
ep_bytes: e80600000050e8bb010000558bec81c4
timestamp: 1972-12-25 05:33:23

Version Info:

FileVersion: 3.0.0.0
FileDescription: 乐活论坛荣誉出品 QQ群:207060706
ProductName: 乐活论坛专用解除防沉迷软件第三版
ProductVersion: 3.0.0.0
CompanyName: 乐活论坛荣誉出品
LegalCopyright: 乐活论坛荣誉出品 版权所有
Comments: 乐活论坛荣誉出品 QQ群:207060706
Translation: 0x0804 0x04b0

Tedy.444188 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FlyStudio.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.e4b28c02f7cd787f
SkyhighBehavesLike.Win32.Generic.hc
ALYacGen:Variant.Tedy.444188
MalwarebytesTrojan.FlyStudio
VIPREGen:Variant.Tedy.444188
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005194cc1 )
K7GWTrojan ( 005194cc1 )
Cybereasonmalicious.f2c2fb
VirITTrojan.Win32.Click2.DFZZ
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Tool.Flystudio-9873746-0
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
Webroot
VaristW32/Trojan.GMK.gen!Eldorado
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Wacatac.A!ml
XcitiumTrojWare.Win32.FlyStudio.~UJ@1sa9s6
GDataWin32.Riskware.FlyStudio.C
GoogleDetected
VBA32Trojan.Bingoml
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CJC23
IkarusTrojan.Win32.FlyAgent
FortinetW32/FlyStudio.C!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/grayware_confidence_60% (W)

How to remove Tedy.444188?

Tedy.444188 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment