Malware

How to remove “Tedy.56866 (B)”?

Malware Removal

The Tedy.56866 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.56866 (B) virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine Tedy.56866 (B)?


File Info:

name: B772F7A07D9AB2D0BB44.mlw
path: /opt/CAPEv2/storage/binaries/b40021248aaa7297efb3a23f16c196526703f602b25c41dc4d131997d4d841cc
crc32: A2CD070E
md5: b772f7a07d9ab2d0bb4404519f968227
sha1: 428c429271da0fb984a1ffcfdcf665ec2ad38c5e
sha256: b40021248aaa7297efb3a23f16c196526703f602b25c41dc4d131997d4d841cc
sha512: 8f278d9b9fd80c059470a6180b5f3839fbf6ca71e9d0be2177131b4d79f1a555f175cd4fdd632271e9b0726734fcbe310cba05e8548ad1fc99f056ff79906cd5
ssdeep: 49152:lUZEcoFRZES05hDp9nG0ElPFa78txDu2AOznu9DYkjsVe:lUdofqIxDNZnu9YYsV
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1A7A53371C041EE55FABA7E312CED12D479F0B9870B1F166BEAD17C41CA7B1213B6920A
sha3_384: 3efba3600e941e04fbda40f1f59ac8c7c310509ba6bd319cac02ecb1fea34652924efd9788401b06170353b7c5dd99e9
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-12-05 19:10:36

Version Info:

Translation: 0x0000 0x04b0
Comments: CareUEyes
CompanyName: CareUEyes
FileDescription: CareUEyes
FileVersion: 2.1.2.0
InternalName: XMR-ZOOMX-WITHOUTDEFENDER.exe
LegalCopyright: Copyright (C) 2017-2021
OriginalFilename: XMR-ZOOMX-WITHOUTDEFENDER.exe
ProductName: https://care-eyes.com
ProductVersion: 2.1.2.0
Assembly Version: 0.0.0.0

Tedy.56866 (B) also known as:

LionicTrojan.Win32.Tedy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.56866
FireEyeGeneric.mg.b772f7a07d9ab2d0
CAT-QuickHealTrojan.Phonzy
McAfeeArtemis!B772F7A07D9A
CylanceUnsafe
ZillyaTrojan.CoinMiner.Win32.41245
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058941e1 )
AlibabaTrojan:Win32/CoinMiner.ali1002002
K7GWTrojan ( 0058941e1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW64/MSIL_Troj.BCG.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/CoinMiner.BOR
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Inject.gen
BitDefenderGen:Variant.Tedy.56866
AvastWin64:CoinminerX-gen [Trj]
TencentMsil.Trojan.Inject.Pfss
Ad-AwareGen:Variant.Tedy.56866
SophosMal/Generic-S
DrWebTrojan.InjectNET.14
TrendMicroTROJ_GEN.R03BC0WLB21
McAfee-GW-EditionBehavesLike.Win64.Fareit.vc
EmsisoftGen:Variant.Tedy.56866 (B)
IkarusTrojan.MSIL.CoinMiner
GDataGen:Variant.Tedy.56866
AviraHEUR/AGEN.1203865
MAXmalware (ai score=82)
GridinsoftRansom.Win64.Gen.sa
ArcabitTrojan.Tedy.DDE22
ViRobotTrojan.Win32.Z.Tedy.2188800
MicrosoftTrojan:MSIL/Injectgen.MA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4551388
ALYacGen:Variant.Tedy.56866
VBA32Trojan.InjectNET
TrendMicro-HouseCallTROJ_GEN.R03BC0WLB21
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetAdware/Miner
AVGWin64:CoinminerX-gen [Trj]
Cybereasonmalicious.271da0
MaxSecureTrojan.Malware.300983.susgen

How to remove Tedy.56866 (B)?

Tedy.56866 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment