Trojan

TrojanDownloader:Win32/Tinrepo.A removal tips

Malware Removal

The TrojanDownloader:Win32/Tinrepo.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Tinrepo.A virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Tinrepo.A?


File Info:

name: F02FD9D298BC88EB7CB7.mlw
path: /opt/CAPEv2/storage/binaries/17509302f0a6162e815eb0da1fcbec00064089966ffea6f7e036b7421dc52233
crc32: 5AEAA1CA
md5: f02fd9d298bc88eb7cb77aed799bc45b
sha1: f67ed16b4ed1cdceb835ce5bc4a35f297ba60f6e
sha256: 17509302f0a6162e815eb0da1fcbec00064089966ffea6f7e036b7421dc52233
sha512: 050c23ac99d1ac29848050081cac30c99b4f3b5655ad6c4d3218453887d4a5f24e2379bb908134bd7d2ca6f180328fc1bb13fbf7543ac0a45deabceadcdbc6b4
ssdeep: 12288:NjL35Ps1gnRq0TldOqWNp3s3K0U+DQ50sbOVoT:NjD5ZnRq07xmp83FUw8X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EBF46D32B2B18437D5635E39CC2BD259582ABF502E28B94A3BFD3D4C8F3978129152D7
sha3_384: 171df8b3b774bbaf2154caaf16ab4d4e992dc27dfb23dbb48675db6cf9a105bfd5e032a32cb4717c1858e5e0f1091cb6
ep_bytes: 558becb90e0000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: repoint.co.kr
FileDescription: point save
FileVersion: 1.0.0.1
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0412 0x03b5

TrojanDownloader:Win32/Tinrepo.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.8!c
AVGWin32:Agent-AAFO [Trj]
FireEyeGeneric.mg.f02fd9d298bc88eb
SkyhighBehavesLike.Win32.Generic.bh
McAfeeGenericRXSQ-IS!F02FD9D298BC
MalwarebytesWebAlta.Adware.ToolBar.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanDownloader:Win32/Tinrepo.52562fc4
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.36802.VG1@auq8NJoG
SymantecDownloader
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Clicker-3936
KasperskyHEUR:Trojan-Dropper.Win32.Sysn.gen
NANO-AntivirusTrojan.Win32.Agent.paoa
AvastWin32:Agent-AAFO [Trj]
F-SecureTrojan.TR/Agent.800769
DrWebBackDoor.RFM.17
ZillyaTrojan.Agent.Win32.71762
TrendMicroTROJ_CLICKER.AFN
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminAdware/Clicker.grg
VaristW32/Trojan.MQQP-7700
AviraTR/Agent.800769
MAXmalware (ai score=100)
Antiy-AVLTrojan[Clicker]/Win32.Agent
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojanDownloader:Win32/Tinrepo.A
XcitiumMalware@#140ocpip2gbim
ViRobotTrojan.Win32.Clicker.744448.B
ZoneAlarmHEUR:Trojan-Dropper.Win32.Sysn.gen
GoogleDetected
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_CLICKER.AFN
RisingDownloader.Tinrepo!8.A98E (TFE:4:1yPo77Fwov)
YandexTrojan.CL.Agent!PN+1X/9A1aI
IkarusTrojan.Win32.Ozopige
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.XZ!tr
DeepInstinctMALICIOUS
alibabacloudSuspicious

How to remove TrojanDownloader:Win32/Tinrepo.A?

TrojanDownloader:Win32/Tinrepo.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment