Trojan

Trojan:Win32/Tnega.PKF!MTB removal guide

Malware Removal

The Trojan:Win32/Tnega.PKF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tnega.PKF!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the Raccoon malware family
  • Collects information to fingerprint the system

How to determine Trojan:Win32/Tnega.PKF!MTB?


File Info:

name: EEA0E8C62A6689A9AC4F.mlw
path: /opt/CAPEv2/storage/binaries/10bcbff9daa66600e2c96c046f258631caa7c5b0da5618f001d46d8ed8f36d9c
crc32: DA07C7E0
md5: eea0e8c62a6689a9ac4ff29493395c8b
sha1: 1828d7a7932b48a761490d34b0657eb35c4598ff
sha256: 10bcbff9daa66600e2c96c046f258631caa7c5b0da5618f001d46d8ed8f36d9c
sha512: 758bdefa227b412f688b50f3e1f548ac5d3ed3834d0ae836ab1efc5e19035e890554158ba83d24796be390d27b9ddcb9dae0266a97af0b2cc0d2a3bc6cca24fe
ssdeep: 12288:gSrvuaxlFxf6rH/3e8G1Kf/4dA/KfNa5Ia+U6RlDmsZcvPtlYioYgnfd:zbFxybW8RoASVYIVcXtabYad
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11ED4E140BBA0C03DE0B316F875B993ADA52E7DA16B3450CB62D13AEE16346E0DC7574B
sha3_384: 1d3bebd8bb0b846d0c85bda0331600c28debad3d215954bd6aea311ea6d0b001b27a678044f6067d5fc83e844aeedef6
ep_bytes: 8bff558bece8968f0000e8110000005d
timestamp: 2021-03-25 09:03:47

Version Info:

Translations: 0x0025 0x0243

Trojan:Win32/Tnega.PKF!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.61919
MicroWorld-eScanTrojan.GenericKD.48383685
CAT-QuickHealRansom.Stop.P5
McAfeePacked-GEE!EEA0E8C62A66
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Tnega.759795b6
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
CyrenW32/Kryptik.GAL.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.FICT
Paloaltogeneric.ml
ClamAVWin.Packed.Filerepmalware-9939423-0
KasperskyHEUR:Trojan-PSW.Win32.Racealer.gen
BitDefenderTrojan.GenericKD.48383685
NANO-AntivirusTrojan.Win32.Racealer.jmyvlh
AvastWin32:AceCrypter-D [Cryp]
TencentTrojan-Spy.Win32.Stealer.za
Ad-AwareTrojan.GenericKD.48383685
SophosMal/Generic-S + Troj/Krypt-FV
BaiduWin32.Trojan.Kryptik.jm
ZillyaTrojan.Kryptik.Win32.3703126
TrendMicroRansom.Win32.STOP.SMYXCBP.hp
McAfee-GW-EditionBehavesLike.Win32.Trojan.hc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.eea0e8c62a6689a9
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Crypter
GDataWin32.Trojan.Kryptik.RW
JiangminTrojan.PSW.Racealer.dud
AviraTR/AD.StellarStealer.ihgqm
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Generic.D2E246C5
MicrosoftTrojan:Win32/Tnega.PKF!MTB
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.SmokeLoader.R473494
Acronissuspicious
ALYacTrojan.GenericKD.48383685
MAXmalware (ai score=85)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:tXanqrrYA07qHPflvsalBg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Packed.GEE!tr
AVGWin32:AceCrypter-D [Cryp]
PandaTrj/GdSda.A

How to remove Trojan:Win32/Tnega.PKF!MTB?

Trojan:Win32/Tnega.PKF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment