Malware

Win32/Tencent.U potentially unwanted removal instruction

Malware Removal

The Win32/Tencent.U potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Tencent.U potentially unwanted virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Win32/Tencent.U potentially unwanted?


File Info:

name: 863B26DE920F658589C5.mlw
path: /opt/CAPEv2/storage/binaries/457ed848c319b285db43a53bd6ff7acfb33d80350ed12f0ab0b2d9f9e559bd20
crc32: 78E8169C
md5: 863b26de920f658589c5967b2052673a
sha1: c93222d3b6ccef7a281213dd47787bd54d9ac29d
sha256: 457ed848c319b285db43a53bd6ff7acfb33d80350ed12f0ab0b2d9f9e559bd20
sha512: b99c12b4e05f6d408497bcb1dc04fa325aa525fa99529a426fedd7f47e973cdd0aea6c61e2b77576968a19147fa4c576cbd8b4f664ec264ae5dbdb6afbe43a9a
ssdeep: 196608:l49HMexUDVp99ukMh8HY5hams5HOTVbdybjAgC/gzkFPKBl:l4HxMLDukMsI0msmVxgPzR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164B63362B5C93CE3E57D697563A8A2600179FDA02A275E2F137C3D418F780C1A6837E7
sha3_384: 267661481d8c00fb21e7017231b4649af1b731ed062b3df91b88f794e8a98fa3f1f5b772dac48d1bd18472879b618dd7
ep_bytes: e86a460000e97ffeffff558bec568b75
timestamp: 1970-01-03 00:12:48

Version Info:

Comments: 2014-07-16 00:00:00
CompanyName: Tencent Inc.
FileDescription: 腾讯网迷你版安装程序
FileVersion: 1.0.0.0
InternalName: QQAIO
LegalCopyright: Copyright © 2015 Tencent. All Rights Reserved.
ProductName: 腾讯网迷你版
ProductVersion: 1.0.0.0
Translation: 0x0804 0x04b0

Win32/Tencent.U potentially unwanted also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 0055899c1 )
K7GWAdware ( 0055899c1 )
CyrenW32/Trojan.NGKL-5691
ESET-NOD32a variant of Win32/Tencent.U potentially unwanted
SophosGeneric PUA MJ (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SentinelOneStatic AI – Suspicious PE
GridinsoftRansom.Win32.Sabsik.sa
McAfeeArtemis!863B26DE920F
VBA32BScope.Trojan.Zpevdo
APEXMalicious
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Tencent

How to remove Win32/Tencent.U potentially unwanted?

Win32/Tencent.U potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment