Malware

About “Tedy.47305 (B)” infection

Malware Removal

The Tedy.47305 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.47305 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family

How to determine Tedy.47305 (B)?


File Info:

name: A0A696E85F16541ED5DF.mlw
path: /opt/CAPEv2/storage/binaries/971455cd96ce9abee3b3b4424e60d8f3abfff58ea8ef83a191c07087fdb04a28
crc32: 6001B9F9
md5: a0a696e85f16541ed5df781ebaf9b69c
sha1: 988907889bed44b347622528324e91fe041c8c2b
sha256: 971455cd96ce9abee3b3b4424e60d8f3abfff58ea8ef83a191c07087fdb04a28
sha512: 30f53df1706cbf6715901e967d4715cdc3f8a30407936a597296fd9bdd5c9d2a99f5731811761c2153b26b1f3ad9e6326bb71be0fbcc23f3df0b671718f5be8e
ssdeep: 49152:r+Tm8YlrB0+HyrLYUhJPK/8MYebAQ8ZdV/L2l:rZ8YHjynYUZ4A5vV/L2
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1F485221477511CF9FA67923AC842D539E973BC610760CAAF07E84A2B2F23B517E3A711
sha3_384: 808da7736498ff5c73509f60d2d29e45706d35d0fdff3186e4526d8c647221daad171914aaced507cc124a058a36e620
ep_bytes: 4883ec28e8f70400004883c428e972fe
timestamp: 2021-11-09 18:03:59

Version Info:

0: [No Data]

Tedy.47305 (B) also known as:

LionicTrojan.Win32.Tedy.4!c
MicroWorld-eScanGen:Variant.Tedy.47305
FireEyeGen:Variant.Tedy.47305
McAfeeArtemis!A0A696E85F16
ZillyaTrojan.Agent.Script.1642598
TrendMicro-HouseCallTROJ_GEN.R002H09L621
Paloaltogeneric.ml
BitDefenderGen:Variant.Tedy.47305
Ad-AwareGen:Variant.Tedy.47305
McAfee-GW-EditionBehavesLike.Win64.Ransom.tc
EmsisoftGen:Variant.Tedy.47305 (B)
JiangminTrojan.Agentb.kqi
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.34CE845
GridinsoftRansom.Win64.Sabsik.sa
GDataGen:Variant.Tedy.47305
CynetMalicious (score: 100)
ALYacGen:Variant.Tedy.47305

How to remove Tedy.47305 (B)?

Tedy.47305 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment