Malware

What is “Tedy.547”?

Malware Removal

The Tedy.547 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.547 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Tedy.547?


File Info:

name: 9B50FEC83A55E8040B6A.mlw
path: /opt/CAPEv2/storage/binaries/0098f9def2dc82a62356d2ee6d92f70eac8705c291527ecfa1ce80e4f7cdebf5
crc32: B9DE95B5
md5: 9b50fec83a55e8040b6aebe0c6ba85c9
sha1: 6843260939937dcc79861855c076a59ec7a3a519
sha256: 0098f9def2dc82a62356d2ee6d92f70eac8705c291527ecfa1ce80e4f7cdebf5
sha512: fd8213f3a5d3cebebeeb16a1efe45a5e4434d8eb893528f92f792ffe57bfddcdc0503d2d136ba304b287339215bb645b970f2db51ec87fe4f89aa9f56ef13db4
ssdeep: 1536:BJxR1r2qDANtz2WHtHRHzH6tLj5YpQqNldFeLDNlN1yHzDR2LYpyTU7g0:Hhr2yItGtLj5YpQqNldFeLDNlN18
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B73D63EB1481416C54D353A37F7C3F204A7E4490ACB568B9271A6EC9E24F80F9A6F27
sha3_384: e5291a4b7f0915673c3154f64ec3cdb19166bf145c5f5d28a372a4faac3365f336bbad4804b15cd09925ce1024b06fc6
ep_bytes: 68a0124000e8f0ffffff000040000000
timestamp: 2010-07-15 06:59:26

Version Info:

Translation: 0x0409 0x04b0
ProductName: a2
FileVersion: 7.13
ProductVersion: 7.13
InternalName: TWWcuDae
OriginalFilename: TWWcuDae.exe

Tedy.547 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.547
ClamAVHtml.Trojan.VBSpy-3
FireEyeGeneric.mg.9b50fec83a55e804
CAT-QuickHealWorm.VBNA.gen
SkyhighBehavesLike.Win32.VBObfus.lm
ALYacGen:Variant.Tedy.547
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( f1000d011 )
AlibabaWorm:Win32/vobfus.1030
K7GWTrojan ( f1000d011 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Tedy.547
BitDefenderThetaGen:NN.ZevbaF.36744.em0@aSyugVoi
VirITWorm.Win32.VB.AB
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.RI
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Tedy.547
NANO-AntivirusTrojan.Win32.WBNA.dwxvyu
AvastWin32:AutoRun-BLX [Wrm]
EmsisoftGen:Variant.Tedy.547 (B)
BaiduWin32.Trojan.AutoRun.az
F-SecureWorm:W32/Vobfus.gen!K
DrWebTrojan.MulDrop1.39622
VIPREGen:Variant.Tedy.547
TrendMicroWORM_VBNA.SMN
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Dewrt.74240
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.VBNA.~BA@2qkiro
MicrosoftWorm:Win32/Vobfus!pz
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.Tedy.547
VaristW32/Vobfus.I.gen!Eldorado
AhnLab-V3Win32/Vbna4.worm.Gen
McAfeeDownloader-CJX.gen.af
MAXmalware (ai score=89)
VBA32Worm.VBNA
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallWORM_VBNA.SMN
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!O8pjWlOmcyA
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.1890494.susgen
FortinetW32/Injector.ADYA!tr
AVGWin32:AutoRun-BLX [Wrm]
Cybereasonmalicious.939937
DeepInstinctMALICIOUS

How to remove Tedy.547?

Tedy.547 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment