Malware

Tedy.461072 removal instruction

Malware Removal

The Tedy.461072 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.461072 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Tedy.461072?


File Info:

name: 9B198FFC65A4366728D4.mlw
path: /opt/CAPEv2/storage/binaries/150374ede6559b5f74e2151735416189d9cdb7f0ee171347bcb9845c05609d92
crc32: 6D376696
md5: 9b198ffc65a4366728d40d12fb3ec8e0
sha1: ad0e801fddc2e26fd307ead01c694983410319ed
sha256: 150374ede6559b5f74e2151735416189d9cdb7f0ee171347bcb9845c05609d92
sha512: ea526d6f3f1d826b79f57c097d1a963251530948b1b7784fc40db4faf1b04d140c45b52d58c0960d2ae80273cadb11d35546163d7349fc161ac17ed182f40cbf
ssdeep: 24576:dtHNoMGBbNC7KlVMEkBFSxt8GhTlp4w6mO5zL7sdZMf/Nhxdfc+Rt/k9Tn1GM7Nz:k4nS9hTH4fLIuf/NhxzQTn1xNz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0759D53B284443BC1221B35582F9374983F7A912AA5681B3FFC1DEE0F39A416D3A65F
sha3_384: ea26a024d9824d92ced1d1631d88c13a91f993cfad6116bea083cfc04062bf744044c203af30f05c95526bb6a309cedb
ep_bytes: 558bec83c4f053b83ca25400e8f789eb
timestamp: 2016-08-18 07:20:49

Version Info:

CompanyName: 系统总裁装机联盟
FileDescription: 总裁装机必备
FileVersion: 3.8.0.0
InternalName:
LegalCopyright: Copyright © sysceo.cn All Rights Reserved.
LegalTrademarks:
OriginalFilename:
ProductName: 总裁装机必备
ProductVersion: 3.8.0.0
Comments: 总裁装机必备
Translation: 0x0804 0x03a8

Tedy.461072 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Tedy.461072
SkyhighArtemis
ALYacGen:Variant.Tedy.461072
ArcabitTrojan.Tedy.D70910
BitDefenderGen:Variant.Tedy.461072
EmsisoftGen:Variant.Tedy.461072 (B)
VIPREGen:Variant.Tedy.461072
FireEyeGen:Variant.Tedy.461072
MAXmalware (ai score=82)
MicrosoftPUA:Win32/SCAir
GDataGen:Variant.Tedy.461072
McAfeeArtemis!9B198FFC65A4
Cylanceunsafe
MaxSecureTrojan.Malware.220673390.susgen
DeepInstinctMALICIOUS

How to remove Tedy.461072?

Tedy.461072 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment