Trojan

Trojan-PSW.Win32.Tepfer.sbav information

Malware Removal

The Trojan-PSW.Win32.Tepfer.sbav is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Tepfer.sbav virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics

How to determine Trojan-PSW.Win32.Tepfer.sbav?


File Info:

name: 5228DEE3074C7BEC91AF.mlw
path: /opt/CAPEv2/storage/binaries/001c5ad0f122d4145e9ff47c24e51adcf66c28c587c38c9290895adc36ba8b06
crc32: AFAE1EC2
md5: 5228dee3074c7bec91afdd63a41a85f7
sha1: 0bb7fc53277da6ac6e7afbc25ac4c890eae3b047
sha256: 001c5ad0f122d4145e9ff47c24e51adcf66c28c587c38c9290895adc36ba8b06
sha512: ff1664a58b6bb2bf06530e91d10d8dc9f00bd3d2d8deb54c37052c48de1398c9cc9091e671bf831174e48e088d6e72505dc1944140277d87ff1e1df0a075aca5
ssdeep: 12288:HpHlsHR7dPcIR6p1KzNdZOfiPNrDr7J3xB5olR0ZF7eVY9SiMRJzTnYR:3sHR5Pcl1odVMleF7eVYMiYxb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1600523434BF79B0DC5A23D77A682129C5697011BC9C6988537FC9F4A737FA3A8B81807
sha3_384: caf5438b206cb70f31e50ee94334aa860b80b14cd85dbf94c7fe84c7619a0402a52699e2aa9f672bdeb55640e316140f
ep_bytes: 54fc58661d00ff724f51baa3bfbfff58
timestamp: 2012-12-03 11:09:11

Version Info:

0: [No Data]

Trojan-PSW.Win32.Tepfer.sbav also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.VIZ.Gen.1
ClamAVWin.Packed.Hlux-9759703-0
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeeGeneric-FANP!5228DEE3074C
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f72a1 )
K7GWTrojan ( 0040f72a1 )
Cybereasonmalicious.3074c7
BaiduWin32.Trojan.Kryptik.ao
CyrenW32/Tepfer.T.gen!Eldorado
SymantecPacked.Generic.461
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BONO
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Tepfer.sbav
BitDefenderTrojan.VIZ.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-Gepys
AvastWin32:Downloader-UWY [Trj]
Ad-AwareTrojan.VIZ.Gen.1
EmsisoftTrojan.VIZ.Gen.1 (B)
ComodoTrojWare.Win32.Kryptik.BLUK@54x5jt
DrWebTrojan.PWS.Siggen1.13108
VIPRETrojan.VIZ.Gen.1
TrendMicroBKDR_KELIHOS.SMF
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5228dee3074c7bec
SophosML/PE-A + Mal/FakeAV-UF
SentinelOneStatic AI – Malicious PE
GDataTrojan.VIZ.Gen.1
JiangminTrojan.PSW.Tepfer.arj
AviraTR/Urausy.69136824
Antiy-AVLTrojan/Generic.ASBOL.191F
ArcabitTrojan.VIZ.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Kelihos.F
GoogleDetected
AhnLab-V3Spyware/Win32.Zbot.R90150
BitDefenderThetaGen:NN.ZexaF.34682.ZmX@a4aMRDb
ALYacTrojan.VIZ.Gen.1
MAXmalware (ai score=86)
VBA32Heur.Trojan.Hlux
MalwarebytesTrojan.MalPack.FFS
TrendMicro-HouseCallBKDR_KELIHOS.SMF
RisingSpyware.Zbot!8.16B (TFE:2:sCJ89UWXW0P)
YandexTrojan.GenAsa!jkojYFBBiEY
IkarusTrojan.ScreenLocker_s
FortinetW32/Kelihos.BQGD!tr
AVGWin32:Downloader-UWY [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-PSW.Win32.Tepfer.sbav?

Trojan-PSW.Win32.Tepfer.sbav removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment