Backdoor

Backdoor:Win32/Tenpeq.C removal tips

Malware Removal

The Backdoor:Win32/Tenpeq.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Tenpeq.C virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Tenpeq.C?


File Info:

crc32: 071E2B1C
md5: e3445f0d2a10c1e72c74d6a8a6ad8c10
name: E3445F0D2A10C1E72C74D6A8A6AD8C10.mlw
sha1: d01d2bb937487bba835f43953fc51e61cf60a8a0
sha256: a99d052e9dd9b54b3f549722725785b5d82e44de6a5d4fd73a67966b181a0e45
sha512: d1f89cf5fb0000a7c2abdcdaa37fbcd5384564e04a94cceb9011bc6622eebead92dd33aa8e80dd8b787511b8e5774473debd9edc8d77f463f98d9f27d7af64bb
ssdeep: 12288:o9Ec//////tBU3J1w0yh/vtjoYI/JEF6EQOj7oblsbJCysoplNRwp+MzxkxzSY3v:IEc//////d0yNNw/JEYEQOfk29Csqde3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Tenpeq.C also known as:

Elasticmalicious (high confidence)
ClamAVWin.Trojan.Graftor-1455
FireEyeGeneric.mg.e3445f0d2a10c1e7
CAT-QuickHealTrojan.Delfinject.17617
ALYacGen:Heur.Mint.Zard.35
CylanceUnsafe
VIPRETrojan.Win32.Injector.fut (v)
SangforMalware
K7AntiVirusTrojan ( 005191a81 )
BitDefenderGen:Heur.Mint.Zard.35
K7GWTrojan ( 005191a81 )
Cybereasonmalicious.d2a10c
SymantecSMG.Heur!gen
TotalDefenseWin32/Injector.A!generic
APEXMalicious
AvastWin32:Inject-ZM [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Tenpeq.07a7b8f2
NANO-AntivirusTrojan.Win32.Buzus.bylho
MicroWorld-eScanGen:Heur.Mint.Zard.35
Ad-AwareGen:Heur.Mint.Zard.35
EmsisoftGen:Heur.Mint.Zard.35 (B)
ComodoTrojWare.Win32.Buzus.fbnc@4mgtpb
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.DownLoader5.4842
TrendMicroTROJ_INJECT.SMT
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
MaxSecureTrojan.Malware.300983.susgen
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Buzus.bamx
AviraDR/Delphi.Gen
MAXmalware (ai score=82)
MicrosoftBackdoor:Win32/Tenpeq.C
ArcabitTrojan.Mint.Zard.35
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Mint.Zard.35
AhnLab-V3Trojan/Win32.Buzus.R73383
Acronissuspicious
McAfeeGenericRXBP-HQ!E3445F0D2A10
VBA32Malware-Cryptor.Inject.gen
MalwarebytesMalware.AI.1732970864
ZonerTrojan.Win32.33877
ESET-NOD32a variant of Win32/Injector.FUT
TrendMicro-HouseCallTROJ_INJECT.SMT
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpI0vtMLhnXXR8pBe/0tnCT)
YandexTrojan.GenAsa!ATLc8IOeu5c
IkarusTrojan-PWS.Win32.QQPass
eGambitUnsafe.AI_Score_91%
FortinetW32/Injector.GUD!tr
BitDefenderThetaAI:Packer.0E6A428419
AVGWin32:Inject-ZM [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Generic.HwUB8vcA

How to remove Backdoor:Win32/Tenpeq.C?

Backdoor:Win32/Tenpeq.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment