Malware

Tedy.59148 removal guide

Malware Removal

The Tedy.59148 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.59148 virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Tedy.59148?


File Info:

name: AC4812E43E2F23FF224C.mlw
path: /opt/CAPEv2/storage/binaries/be56f6af253f8167e17af624b506b13e334aff68723727a13d05a543e0a14444
crc32: 981996C4
md5: ac4812e43e2f23ff224cbcfe9e5f7d62
sha1: 00c1a603935d8a26a69afc2b7c673d15c2341d6b
sha256: be56f6af253f8167e17af624b506b13e334aff68723727a13d05a543e0a14444
sha512: 2cf141e39128f4afafdf004e6acc715933cb7d8575f46a6d242999d1fb29b4d09a7445845c1b0e794e8c0bc009c017d9086f7a3781429b5a8aba3a7a7f5dbab6
ssdeep: 3072:8wlAfZsKaGJyw5adiWU1zfaddxBAvkDO1m3MNr0pjLQd62Ejx8Bykw4UrsDZ:8SAx5aaywEdiWU1zfaUvCO1m3MNrkXXY
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T184046C4263F80166F0F61B3C6DBA37954CBDBC96F974CE6E114864CE2866A90D4AC337
sha3_384: dd4c4ebcfe039e5d51b74aefaab5a4ac801caaab29040b89df45bca0593418a8bf99eb002f11751770a24b82426d9e35
ep_bytes: 48895c2408574883ec20488bda488bf9
timestamp: 2016-03-03 04:42:34

Version Info:

FileVersion: 1.0.1.16
Translation: 0x0804 0x04b0

Tedy.59148 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Tedy.59148
FireEyeGeneric.mg.ac4812e43e2f23ff
McAfeeArtemis!AC4812E43E2F
CylanceUnsafe
K7AntiVirusTrojan ( 7000001d1 )
AlibabaPacked:Win32/VMProtect.1f2ea994
K7GWTrojan ( 7000001d1 )
Cybereasonmalicious.3935d8
ESET-NOD32a variant of Win32/Packed.VMProtect.ABO
TrendMicro-HouseCallTROJ_GEN.R03BH09L321
BitDefenderGen:Variant.Tedy.59148
AvastWin64:Trojan-gen
Ad-AwareGen:Variant.Tedy.59148
EmsisoftGen:Variant.Tedy.59148 (B)
BaiduWin32.Backdoor.Yobdam.b
McAfee-GW-EditionBehavesLike.Win64.Infected.ch
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Tedy.59148
MAXmalware (ai score=88)
ViRobotTrojan.Win32.Z.Vmprotect.185712
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Tedy.59148
MalwarebytesMalware.AI.1487302936
APEXMalicious
IkarusTrojan.Win32.VMProtect
FortinetPossibleThreat.PALLASNET.H
AVGWin64:Trojan-gen

How to remove Tedy.59148?

Tedy.59148 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment