Trojan

What is “Trojan:Win32/Tnega.KZ!MTB”?

Malware Removal

The Trojan:Win32/Tnega.KZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tnega.KZ!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Tnega.KZ!MTB?


File Info:

crc32: C9A214DF
md5: ac8c78de76cc5d0ee1807babc3b5ab98
name: AC8C78DE76CC5D0EE1807BABC3B5AB98.mlw
sha1: 00d70500a3d176f89d16845005ff40ce3728f2a6
sha256: 3009ff9d8a1675709ccb395bb2c45fb0046a19389e37f4e20bc672efee49f8cd
sha512: 35af0af1737c9a61ba01c128d1af02d0837d0d455d04524977391669cf91908f64da818c79f62d5e1b7ffbaf26695e0d6340a5b071455333a133d49740b41be6
ssdeep: 6144:VPB6YtwEs09ZfVZcYRHOUoSDSQJkiqpcq22Lb+D:JLtwkffzcY4UTlOiN1Q+D
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan:Win32/Tnega.KZ!MTB also known as:

BkavW32.FamVT.GluptebaBTTc.Worm
K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.Siggen13.36816
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.36918631
CylanceUnsafe
SangforSpyware.Win32.Noon.gen
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaBackdoor:Win32/Formbook.ba50ccba
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.0a3d17
CyrenW32/Agent.CXH.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/Formbook.AA
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderTrojan.GenericKD.36918631
MicroWorld-eScanTrojan.GenericKD.36918631
Ad-AwareTrojan.GenericKD.36918631
SophosMal/Generic-S + Troj/Formbo-AFI
TrendMicroTROJ_FRS.0NA103EI21
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGeneric.mg.ac8c78de76cc5d0e
EmsisoftTrojan.GenericKD.36918631 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/AD.Swotter.vzbkp
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tnega.KZ!MTB
ArcabitTrojan.Generic.D2335567
AegisLabTrojan.Win32.Noon.l!c
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataTrojan.GenericKD.36918631
AhnLab-V3Malware/Win.Generic.C4478215
McAfeeArtemis!AC8C78DE76CC
MAXmalware (ai score=86)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA103EI21
IkarusTrojan.Inject
FortinetNSIS/Injector.EPJF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Tnega.KZ!MTB?

Trojan:Win32/Tnega.KZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment