Categories: Malware

Tedy.56860 information

The Tedy.56860 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.56860 virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine Tedy.56860?


File Info:

name: 684D3021920DCC2B6872.mlwpath: /opt/CAPEv2/storage/binaries/5f9a098e60ed9a0e691cec3cb856a8761577d3a1ceb7b483543cebf62117d214crc32: 49F04C70md5: 684d3021920dcc2b6872dcf753a3b3f6sha1: 4d7511040b46dcbf36a1374ca12f5df05eb830b1sha256: 5f9a098e60ed9a0e691cec3cb856a8761577d3a1ceb7b483543cebf62117d214sha512: bf3fd852e16953ba27e9489949c450934a0dea230f2f1a9a1c7528ca60ad8f9cb646863f26559804136dbdc52393e78ee4047571db74a7b8b74898d7c4778407ssdeep: 96:c3HfdonTuHjv5GTZSYw792+ab3CVCXTFytjlEshpGRvRxNXYPRTIoDeNViPWwOgv:cPdqs50E792+A3fjFajxhcrNXYlogWutype: PE32+ executable (GUI) x86-64, for MS Windowstlsh: T1E412C51077F98618F5FF4F752CB176205136F7875A52D2AF1C85409A2C32A50CB92BBBsha3_384: ce97ecccfee52ba3be433ebd138c217cd175e8ba4324ad11179671be750371d97ced6d67488fc70ad5cde30d6ba7cc20ep_bytes: 4d5a90000300000004000000ffff0000timestamp: 2021-12-06 11:36:56

Version Info:

Translation: 0x0000 0x04b0Comments: Shell Infrastructure HostFileDescription: Shell Infrastructure HostFileVersion: 10.0.19041.746InternalName: un-watchdog.exeLegalCopyright: © Microsoft Corporation. All Rights Reserved.OriginalFilename: un-watchdog.exeProductName: Microsoft® Windows® Operating SystemProductVersion: 10.0.19041.746Assembly Version: 0.0.0.0

Tedy.56860 also known as:

Lionic Trojan.MSIL.Bladabindi.m!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Tedy.56860
ALYac Gen:Variant.Tedy.56860
Cylance Unsafe
K7AntiVirus Trojan ( 0057f9af1 )
Alibaba Backdoor:Win32/Bladabindi.2f99389d
K7GW Trojan ( 0057f9af1 )
Cyren W64/MSIL_Coinminer.C.gen!Eldorado
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win32/CoinMiner.CGV
APEX Malicious
Paloalto generic.ml
Kaspersky HEUR:Backdoor.MSIL.Bladabindi.gen
BitDefender Gen:Variant.Tedy.56860
Avast Win64:CoinminerX-gen [Trj]
Tencent Trojan.Win64.BitCoinMiner.16000099
Ad-Aware Gen:Variant.Tedy.56860
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1143071
TrendMicro TROJ_GEN.R002C0WL621
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.684d3021920dcc2b
Emsisoft Gen:Variant.Tedy.56860 (B)
Ikarus Trojan.Win32.CoinMiner
GData Gen:Variant.Tedy.56860
Webroot W32.Trojan.Dropper
Avira HEUR/AGEN.1143071
Arcabit Trojan.Tedy.DDE1C
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 99)
AhnLab-V3 Trojan/Win.Generic.C4785167
McAfee Artemis!684D3021920D
MAX malware (ai score=84)
TrendMicro-HouseCall TROJ_GEN.R002C0WL621
SentinelOne Static AI – Malicious PE
Fortinet MSIL/CoinMiner.CGV!tr
AVG Win64:CoinminerX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen

How to remove Tedy.56860?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Adware.Hotbar.1 information

The Adware.Hotbar.1 is considered dangerous by lots of security experts. When this infection is active,…

50 seconds ago

Barys.456554 information

The Barys.456554 is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

Midie.66060 (file analysis)

The Midie.66060 is considered dangerous by lots of security experts. When this infection is active,…

26 mins ago

Should I remove “Symmi.6017 (B)”?

The Symmi.6017 (B) is considered dangerous by lots of security experts. When this infection is…

41 mins ago

Zusy.540971 removal tips

The Zusy.540971 is considered dangerous by lots of security experts. When this infection is active,…

42 mins ago

Should I remove “Win32:VB-VBS [Wrm]”?

The Win32:VB-VBS [Wrm] is considered dangerous by lots of security experts. When this infection is…

46 mins ago