Malware

Tedy.60161 information

Malware Removal

The Tedy.60161 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.60161 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Tedy.60161?


File Info:

name: CFFB14CAA2D891195985.mlw
path: /opt/CAPEv2/storage/binaries/fa8af6bc12fa8b40874d0f1f87db6b06d69ce783c8bc673e23d17ff46823ef96
crc32: 62DE3C68
md5: cffb14caa2d89119598564b6f4a1374b
sha1: ba7f6112ae5b309a60e768cd70ccb3b4cb73adc6
sha256: fa8af6bc12fa8b40874d0f1f87db6b06d69ce783c8bc673e23d17ff46823ef96
sha512: eb3a65713ad734b7251c60f14af68dab2a9055ffdceb4c9ff95610d16d255e330e633e071eb56281484758f3c891a8f9ae8b72ef48b5c56945de27c544bfeb6d
ssdeep: 49152:mGtlqBKIU6i9M5kQoFyA7M5a3vNqdpmq/RZdnwr4idFO5nBqMnx6iXpkBvBsbWiV:E+9Z7M5a/N1pRoVd6iXSf4Wb6WDrun
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1E706AE56B3A800E8D5B7C17CC9564623E7F2B81513B09BDF06A4867A0F237E26E3E751
sha3_384: 54d7ad14f4297d3e7b5556022a20857d410802dddc1abf6d96ba023dc645a0197b9acd3d1f999da754c6215cc4d050f0
ep_bytes: 4883ec28e8cf0700004883c428e972fe
timestamp: 2021-12-05 15:38:27

Version Info:

0: [No Data]

Tedy.60161 also known as:

LionicHacktool.Win64.KernelDrUtil.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.60161
FireEyeGen:Variant.Tedy.60161
McAfeeArtemis!CFFB14CAA2D8
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00578aba1 )
AlibabaTrojan:Win64/Kryptik.4a5a6369
K7GWTrojan ( 00578aba1 )
CyrenW64/Kryptik.FDO.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Kryptik.CHJ
TrendMicro-HouseCallTROJ_GEN.R03BC0WLB21
KasperskyUDS:HackTool.Win64.KernelDrUtil.gen
BitDefenderGen:Variant.Tedy.60161
AvastWin64:HacktoolX-gen [Trj]
Ad-AwareGen:Variant.Tedy.60161
SophosMal/Generic-S
TrendMicroTROJ_GEN.R03BC0WLB21
McAfee-GW-EditionBehavesLike.Win64.Generic.wh
EmsisoftGen:Variant.Tedy.60161 (B)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1144427
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.34E9A5D
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Tedy.60161
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R457070
APEXMalicious
IkarusTrojan.Win64.Crypt
FortinetW64/Kryptik.CHJ!tr
AVGWin64:HacktoolX-gen [Trj]

How to remove Tedy.60161?

Tedy.60161 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment