Trojan

Should I remove “Trojan-PSW.Win32.Tepfer.uvsx”?

Malware Removal

The Trojan-PSW.Win32.Tepfer.uvsx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Tepfer.uvsx virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

How to determine Trojan-PSW.Win32.Tepfer.uvsx?


File Info:

name: 40A59F55199E4578267D.mlw
path: /opt/CAPEv2/storage/binaries/1fa614e5ae8e7b2307851227e5f7324ea38b57416e14518a730d3071dd0ba956
crc32: AAACA8B0
md5: 40a59f55199e4578267dfb883747be9f
sha1: 9db1f09b293f65b376ae16431c6b1ed0376be2a4
sha256: 1fa614e5ae8e7b2307851227e5f7324ea38b57416e14518a730d3071dd0ba956
sha512: 428daea4d239b50a6f5a8f0e902945ae60775fda46e1f87e1b5134307c08c71595028c7f3619aa6eecd0a81591b46964c46e85561b8e23fe86970f28ec673e2a
ssdeep: 1536:bQ9RWjaqE7C34rTjNGUvQt9Z4vqAHUJ/XfjerYEgqxlzB3TdhKu434TlnSjTmgsJ:OWgt54/T8CMvLTfW3Jy08+q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10AB3E847B7BD18EDE2C3427D18908598C20771F723A1E6E66E89C4352473A7B7DA8F24
sha3_384: bcbd2ad8ef8d8c307c5729400977c7628d528ba0275219657595c32b554ec5bea42fdea208929d5e2b7651537f223bcd
ep_bytes: 558bec6aff68c85b4100683427410064
timestamp: 2015-01-27 14:32:41

Version Info:

FileDescription: ManyBytes program
FileVersion: 1.0.0.4
LegalCopyright: Copyright 2001-2014 all authors(GPLv3)
OriginalFilename: ManyBytes.exe
ProductName: ManyBytes program
ProductVersion: 1.0.0.4
CompanyName: ManyBytes
Translation: 0x0419 0x04e1

Trojan-PSW.Win32.Tepfer.uvsx also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lZ5Q
DrWebTrojan.PWS.Stealer.13052
MicroWorld-eScanTrojan.GenericKD.2120295
FireEyeGeneric.mg.40a59f55199e4578
McAfeeGeneric.wd
MalwarebytesBackdoor.Bot
ZillyaTrojan.Tepfer.Win32.78932
SangforInfostealer.Win32.Tepfer.uvsx
K7AntiVirusPassword-Stealer ( 004afe551 )
AlibabaTrojanPSW:Win32/Tepfer.743568e9
K7GWPassword-Stealer ( 004afe551 )
Cybereasonmalicious.5199e4
BitDefenderThetaGen:NN.ZexaF.34212.hq0@a0N7wrpG
VirITTrojan.Win32.Zbot.XGD
CyrenW32/PWS.IJTA-5865
SymantecDownloader.Ponik
ESET-NOD32Win32/PSW.Fareit.G
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Tepfer.uvsx
BitDefenderTrojan.GenericKD.2120295
NANO-AntivirusTrojan.Win32.Tepfer.efhfnp
TencentWin32.Trojan-qqpass.Qqrob.Pbpd
Ad-AwareTrojan.GenericKD.2120295
SophosMal/Generic-S + Mal/Generic-L
ComodoMalware@#1hzydnh25ztht
BaiduWin32.Trojan-Downloader.Waski.a
VIPREWin32.Malware!Drop
TrendMicroTROJ_MOSERAN.BME
McAfee-GW-EditionGeneric.wd
EmsisoftTrojan.GenericKD.2120295 (B)
IkarusTrojan.Win32.PSW
GDataWin32.Trojan.Agent.BJ368N
JiangminTrojan/PSW.Tepfer.cbwl
WebrootW32.Malware.Gen
AviraTR/Spy.Fareit.114688
Antiy-AVLTrojan[PSW]/Win32.Tepfer
KingsoftWin32.PSWTroj.Tepfer.uv.(kcloud)
ArcabitTrojan.Generic.D205A67
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
ZoneAlarmTrojan-PSW.Win32.Tepfer.uvsx
MicrosoftPWS:Win32/Fareit
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.ZBot.R127901
VBA32TrojanPSW.Tepfer
ALYacTrojan.GenericKD.2120295
MAXmalware (ai score=100)
PandaTrj/Chgt.O
TrendMicro-HouseCallTROJ_MOSERAN.BME
RisingTrojan.Win32.Fareit.hb (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_90%
FortinetW32/Kryptik.CWAI!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-PSW.Win32.Tepfer.uvsx?

Trojan-PSW.Win32.Tepfer.uvsx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment