Malware

How to remove “Tedy.63556”?

Malware Removal

The Tedy.63556 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.63556 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Tedy.63556?


File Info:

name: 20C029EAFBF236C04E36.mlw
path: /opt/CAPEv2/storage/binaries/e42740d7c48667a73b7bd5335279b8eeed833623b1581e1d93cab583f477271a
crc32: 9C92E1A5
md5: 20c029eafbf236c04e367daec829dda3
sha1: 5011a16917d2c41bd9c2d0a2cab004867f491f74
sha256: e42740d7c48667a73b7bd5335279b8eeed833623b1581e1d93cab583f477271a
sha512: 16b3744bed1601ca0aa500f42dcee3e1cb608e497fec8467cc03ba6a1bc38efb50f4df37be2a3bb769e0b912a40deb96cdd7fb9a3a7713d5348c972f6f8e2803
ssdeep: 24576:wYLui2J1D4gSZJA0UPWbsP2y6Yblp7vdVVIDpQnz0wBB:n9Lg2AA+2hkvv2mz1B
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T16D352390349D5F5BF0273B3959E44A127335AA96AB43C71B8A20763B2F03BD51EC325E
sha3_384: 939508878a935823f6b926058a3fdad2cf8f68b2ef9c0ee9f602de34c3f04643b133c44ce0046e0acef20c4bef9a03ba
ep_bytes: 53565755488d35fa34f0ff488dbedbaf
timestamp: 2021-12-11 20:50:18

Version Info:

0: [No Data]

Tedy.63556 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.20c029eafbf236c0
McAfeeArtemis!20C029EAFBF2
CylanceUnsafe
AlibabaTrojan:Win32/Shelma.768b3c42
Cybereasonmalicious.917d2c
APEXMalicious
KasperskyTrojan.Win32.Shelma.brzt
BitDefenderGen:Variant.Tedy.63556
MicroWorld-eScanGen:Variant.Tedy.63556
AvastFileRepMalware
Ad-AwareGen:Variant.Tedy.63556
SophosMal/Generic-S + ATK/FatRat-G
TrendMicroTROJ_GEN.R002C0RLF21
McAfee-GW-EditionBehavesLike.Win64.Trickbot.tc
EmsisoftGen:Variant.Tedy.63556 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Tedy.63556
AviraTR/Shelma.jzijp
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.34ED03C
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacGen:Variant.Tedy.63556
TrendMicro-HouseCallTROJ_GEN.R002C0RLF21
RisingTrojan.Kryptik/x64!1.D574 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGFileRepMalware
PandaTrj/CI.A

How to remove Tedy.63556?

Tedy.63556 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment