Malware

Tedy.48949 (file analysis)

Malware Removal

The Tedy.48949 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.48949 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Tedy.48949?


File Info:

name: AF0DFA98D07C4800A615.mlw
path: /opt/CAPEv2/storage/binaries/a66c61b07f852f4a94d5fbf3cb09d60b3fb60118882b1839f8b26bb50bd67764
crc32: FB75F9F6
md5: af0dfa98d07c4800a615c573db7214ff
sha1: 13f3817fa180f5c92eb91a8623963263e4c2e129
sha256: a66c61b07f852f4a94d5fbf3cb09d60b3fb60118882b1839f8b26bb50bd67764
sha512: 5ce378707a934521838272f172c4d8a40851269d76d810d237f10e6596a3c4d082cf4f06c2f25be0698b1af42bbaa4e4662e016fbb5d86fb55d5e19137bbada7
ssdeep: 98304:9+RYNAKvkTgXuquveY+W2o8oT3ezMrl9cekcHhXh9HJUiWUXsmqsqzl87aW7tPW3:UmA2e9k
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1BA062929EEEE9E22CC7955705F7E979C81247CA016E0C65B23507ABCD933F58A81F213
sha3_384: a1bbfdf37c76703ff4341dd4bbfd8811d462a194ec5ae5ca27ba04b198556f1b3c7355c8147f1e623ad99935fab1aeae
ep_bytes: ff25de26fdffcccccccccccccccccccc
timestamp: 2010-11-20 11:21:46

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Media Center Store Update Manager
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
InternalName: mcupdate.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: mcupdate.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7601.17514
Translation: 0x0409 0x04b0

Tedy.48949 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.48949
FireEyeGeneric.mg.af0dfa98d07c4800
McAfeeArtemis!AF0DFA98D07C
CylanceUnsafe
Cybereasonmalicious.8d07c4
CyrenW64/Blackie.R.gen!Eldorado
APEXMalicious
ClamAVWin.Malware.Bulz-9871427-0
BitDefenderGen:Variant.Tedy.48949
AvastWin64:Malware-gen
Ad-AwareGen:Variant.Tedy.48949
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionArtemis
EmsisoftGen:Variant.Tedy.48949 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Tedy.48949
JiangminPacked.Krap.gvwv
AviraHEUR/AGEN.1141290
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Tedy.48949
MAXmalware (ai score=86)
IkarusTrojan.Msil
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.BE23!tr
AVGWin64:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Tedy.48949?

Tedy.48949 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment