Malware

Should I remove “Tedy.6638 (B)”?

Malware Removal

The Tedy.6638 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tedy.6638 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Network activity detected but not expressed in API logs
  • CAPE detected the PyInstaller malware family

Related domains:

wpad.local-net

How to determine Tedy.6638 (B)?


File Info:

name: 1E35F22CA59D35FA9A51.mlw
path: /opt/CAPEv2/storage/binaries/f6f2f5dfbd6a4cb28673a0aa0d1582567f8bb2118328dd09c33d5edf2bc449af
crc32: CBF9876F
md5: 1e35f22ca59d35fa9a51b28975f0e53e
sha1: 18832339fe6ea4c7398175fe79b33036a3ae7996
sha256: f6f2f5dfbd6a4cb28673a0aa0d1582567f8bb2118328dd09c33d5edf2bc449af
sha512: 35ff78af929a9cc8b94f50a4991baf57ef3f824aa6698778d8cb8c61a391b96952666592726308412d3b8fb30808260611f17a9e45232ec23feead5d972fddab
ssdeep: 196608:PqAVzKhQW4CsXDjDyfGZkJMD+LjL2dRZbd:IhQVCEDrZkPLjL+
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1B3863308925909B8FDF7113EC8508429CAB538B717A4E64B0E6EA5973FD7A713C3EE50
sha3_384: 2c3081bf5db91a588389d913377ebadad7325b16e900935bb2a85b7755b22ee1b11eef99d67e33cb5b031a909e478da6
ep_bytes: 4883ec28e8f70400004883c428e972fe
timestamp: 2021-11-09 18:03:59

Version Info:

0: [No Data]

Tedy.6638 (B) also known as:

LionicTrojan.Win32.Tedy.4!c
MicroWorld-eScanGen:Variant.Tedy.6638
FireEyeGen:Variant.Tedy.6638
CylanceUnsafe
ZillyaTrojan.Agent.Script.1642598
SangforTrojan.Win32.Sabsik.FL
SymantecTrojan.Gen.2
BitDefenderGen:Variant.Tedy.6638
AvastFileRepMalware
Ad-AwareGen:Variant.Tedy.6638
ComodoTrojWare.Win32.Agent.egcdf@0
McAfee-GW-EditionBehavesLike.Win64.Ransom.wc
EmsisoftGen:Variant.Tedy.6638 (B)
JiangminTrojan.Agentb.kqi
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.34CE845
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Tedy.8072154
GDataGen:Variant.Tedy.6638
CynetMalicious (score: 100)
McAfeeArtemis!1E35F22CA59D
AVGFileRepMalware

How to remove Tedy.6638 (B)?

Tedy.6638 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment