Malware

How to remove “Tedy.56870”?

Malware Removal

The Tedy.56870 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.56870 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine Tedy.56870?


File Info:

name: E611C3561348CD809E3D.mlw
path: /opt/CAPEv2/storage/binaries/bc42afd6fa8b1e456316f5b7fc2741e8f5ba012e67bea6011639fbd0e773515f
crc32: 241D0DCE
md5: e611c3561348cd809e3d340f888c01bd
sha1: 43374472a66ea3c8b1b4e05dce88a4651088884f
sha256: bc42afd6fa8b1e456316f5b7fc2741e8f5ba012e67bea6011639fbd0e773515f
sha512: 74ff613f5a48149084f1b58538426e7c400ce1d19a9545392cbb300853b092d44c3fc37a421b5b8a0a49e635a44cdefff47f12ad8aa6d1b2962e6fd32d72e122
ssdeep: 96:I+CA+PAZGjn/phKL97RGdabjW1Lth3wTFZeCNCyXmTIoDSu05PWwOgzNt:I+CAFcxhK1RMAK1LtpU7eLR0RWu
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T181F1E841B7EC8215F4FE4B3158B14B551279FAD7AA12C76E2885800D6C72B84CFA2FB2
sha3_384: ab4f01000d3af60652ab0727f0b0d95ec3329a25dc0e0ed9136cbce9a857bcb57aa0f358ffce9a87d09780765eac28a3
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-11-30 14:28:39

Version Info:

Translation: 0x0000 0x04b0
Comments: Shell Infrastructure Host
FileDescription: Shell Infrastructure Host
FileVersion: 10.0.19041.746
InternalName: Akrien-watchdog.exe
LegalCopyright: © Microsoft Corporation. All Rights Reserved.
OriginalFilename: Akrien-watchdog.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.746
Assembly Version: 0.0.0.0

Tedy.56870 also known as:

LionicTrojan.MSIL.Miner.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.56870
FireEyeGeneric.mg.e611c3561348cd80
CAT-QuickHealTrojan.WacatacFC.S20328146
ALYacGen:Variant.Tedy.56870
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057a08c1 )
AlibabaTrojan:MSIL/CoinMiner.93a1dee4
K7GWTrojan ( 0057a08c1 )
CyrenW64/MSIL_Coinminer.C.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/CoinMiner.BIP
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Bulz-9879448-0
KasperskyHEUR:Trojan.MSIL.Miner.gen
BitDefenderGen:Variant.Tedy.56870
AvastWin64:CoinminerX-gen [Trj]
TencentMsil.Trojan.Miner.Ahxp
Ad-AwareGen:Variant.Tedy.56870
EmsisoftGen:Variant.Tedy.56870 (B)
DrWebTrojan.MinerNET.20
TrendMicroTROJ_GEN.R002C0DL521
McAfee-GW-EditionArtemis!Trojan
SophosTroj/Miner-ABI
SentinelOneStatic AI – Malicious PE
WebrootW32.Coinminer.Gen
AviraHEUR/AGEN.1143071
GridinsoftRansom.Win64.Gen.sa
MicrosoftTrojan:Win64/CoinMiner.GA!MTB
GDataGen:Variant.Tedy.56870
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4404809
McAfeeArtemis!E611C3561348
MAXmalware (ai score=89)
VBA32Trojan.MSIL.Miner
MalwarebytesTrojan.BitCoinMiner.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0DL521
IkarusTrojan.MSIL.CoinMiner
eGambitUnsafe.AI_Score_98%
FortinetMSIL/CoinMiner.BIP!tr
AVGWin64:CoinminerX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Tedy.56870?

Tedy.56870 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment