Trojan

Trojan:Win32/Tnega.P!MTB removal guide

Malware Removal

The Trojan:Win32/Tnega.P!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tnega.P!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Trojan:Win32/Tnega.P!MTB?


File Info:

name: 2B007052B30B1819F121.mlw
path: /opt/CAPEv2/storage/binaries/016750af3c77c6d6a4efddbfaeb2c76958a28f50f32b0290609a773aa41c19dc
crc32: E34EB642
md5: 2b007052b30b1819f121d89ab9d9b560
sha1: 945d2ab70dc9a8bd069c3dcf9f490dd0dd0d523c
sha256: 016750af3c77c6d6a4efddbfaeb2c76958a28f50f32b0290609a773aa41c19dc
sha512: 8b9243e4a6194107c6bb84946e5d5f21ee0ee01952491a0567067e7917154fbc7cad289f16adb1a1548271c14924ab868bb42cfc014f99e4b487748a1f91dd14
ssdeep: 12288:DSYSMXRFwZEQ5TYy2apWLD2veIy7kdFRcqzit:D48wKOD2aI/2JD5G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11705AF7131A0E473E37BC5BECC67A6D81034BF619B48E84526E4B90D4EF9B50F91B286
sha3_384: 7f55f631a0e080255166ba4cb27f736ce717f379517b3209e43db037cb30536025a9754f921b690536cadcc0b0c8f27f
ep_bytes: 558bec83c4f0b814e44500e8047bfaff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Tnega.P!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.1792
MicroWorld-eScanTrojan.Generic.31253036
FireEyeGeneric.mg.2b007052b30b1819
CAT-QuickHealTrojan.Tnega
McAfeeArtemis!2B007052B30B
CylanceUnsafe
ZillyaDownloader.Delf.Win32.62095
K7AntiVirusTrojan ( 0058b35f1 )
AlibabaBackdoor:Win32/Tnega.f19444ad
K7GWTrojan ( 0058b35f1 )
Cybereasonmalicious.70dc9a
CyrenW32/Injector.BBKM-7396
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Delf.DIB
TrendMicro-HouseCallTROJ_GEN.R011C0DLB21
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Androm.gen
BitDefenderTrojan.Generic.31253036
AvastWin32:Trojan-gen
RisingTrojan.Generic@ML.90 (RDML:NTB/z+L4dAY8e93l43XuTg)
Ad-AwareTrojan.Generic.31253036
EmsisoftTrojan.Generic.31253036 (B)
TrendMicroTROJ_GEN.R011C0DLB21
McAfee-GW-EditionBehavesLike.Win32.Dropper.bh
SophosMal/Generic-S
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1201670
Antiy-AVLTrojan/Generic.ASMalwS.34E8EB4
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Tnega.P!MTB
GDataTrojan.Generic.31253036
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Woreflint.C4830316
ALYacTrojan.Generic.31253036
MAXmalware (ai score=89)
VBA32BScope.Backdoor.Androm
MalwarebytesTrojan.MalPack.DLF
APEXMalicious
TencentMalware.Win32.Gencirc.10cf983b
FortinetW32/Injector.EQQS!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan:Win32/Tnega.P!MTB?

Trojan:Win32/Tnega.P!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment