Trojan

TrojanDropper:Win32/Tenpeq!A information

Malware Removal

The TrojanDropper:Win32/Tenpeq!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Tenpeq!A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDropper:Win32/Tenpeq!A?


File Info:

name: EAF4C5EC65EAF001A6FA.mlw
path: /opt/CAPEv2/storage/binaries/a9af837bb9d8f78c85ec92672eb0ebca99e6fdc1cad5c1db31fd22e650030541
crc32: 46D24D11
md5: eaf4c5ec65eaf001a6fa47b5ca3c8b9f
sha1: 94e3bd6fd2acdba02715116f6cd2947d25f8258f
sha256: a9af837bb9d8f78c85ec92672eb0ebca99e6fdc1cad5c1db31fd22e650030541
sha512: 01b6abedea5451374efbe26443bdcd1ad47203600b002bd49e1e31dd2509ce07a7e8a1fe45161192b1b23df29f0880af51504a8cabfc954227a7d33fcc8a5f2e
ssdeep: 3072:DKihb29ToVwwACCEupUq0m8wRpcX48MOnHVetLPEVMu1yMh:DK4bnww6rMMcoQVM4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123147D23F2C088B1D06489BC5D19C795EA3EFF302E35949F72DA5F0D8EBD490A55E292
sha3_384: 73a74ec21b9bca695f7b2e6254b465a368bbe3b53b07383bbf3858b4c1f5e15a837470ccd135aca094721424cf72c001
ep_bytes: 833d0400400000755505e901000000c3
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

TrojanDropper:Win32/Tenpeq!A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Generic.4072210
FireEyeGeneric.mg.eaf4c5ec65eaf001
McAfeeGenericRXBT-EQ!EAF4C5EC65EA
MalwarebytesMalware.AI.1769623640
ZillyaTrojan.Agent.Win32.547407
SangforTrojan.Win32.Save.a
Cybereasonmalicious.c65eaf
BitDefenderThetaAI:Packer.B7CBE87F1F
CyrenW32/Troj_Obfusc.N.gen!Eldorado
SymantecBackdoor.Trojan
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Delf.NKN
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Yaryar.i
BitDefenderTrojan.Generic.4072210
NANO-AntivirusTrojan.Win32.Sdbot.dstiep
AvastWin32:Trojan-gen
TencentWin32.Trojan.Killav.Lflw
EmsisoftTrojan.Generic.4072210 (B)
BaiduWin32.Trojan-Dropper.Agent.e
F-SecureTrojan.TR/Killav.PO
DrWebBackDoor.IRC.Sdbot.4282
VIPRETrojan.Generic.4072210
McAfee-GW-EditionBehavesLike.Win32.Picsys.dm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.4072210
JiangminBackdoor/Agent.bzma
AviraTR/Killav.PO
XcitiumPacked.Win32.Klone.~KF@1jnkve
ArcabitTrojan.Generic.D3E2312
ZoneAlarmTrojan.Win32.Yaryar.i
MicrosoftTrojanDropper:Win32/Tenpeq.gen!A
GoogleDetected
Acronissuspicious
VBA32BScope.Trojan.Agent
ALYacTrojan.Generic.4072210
MAXmalware (ai score=87)
Cylanceunsafe
PandaGeneric Suspicious
RisingBackdoor.Win32.XiaoNiu.h (CLASSIC)
IkarusTrojan-Dropper.Agent
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:Win32/Tenpeq!A?

TrojanDropper:Win32/Tenpeq!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment