Skip to main content

TPE

Classification

Summary

TridenT Polymorphic Engine

TPE was written in 1992 by Masud Khafir, a Dutch member of the TridenT virus group. Before and after TPE, Masud Khafir has created several advanced viruses. Among them are the first Windows virus, Win_Vir, the Cruncher virus series, and one of the most widespread viruses using MtE, the MtE.Pogue virus. TPE itself is based on the encryption routine of Masud Kafir's Coffeeshop 3 virus, currently known as TPE.1_0.Girafe.A.

Removal

Technical Details

To date, four versions of TPE have come out. The author has implied that he considers the product finished, and will not write further versions. The later versions of TPE are highly complex, making it one the most advanced polymorphic generators in the world.

TPE version 1.1 was technically advanced, but it contained bugs which made it incompatible with some processor types. Versions 1.2 and 1.3 corrected this problem. The last version, 1.4, introduced an improved, highly complex encryption method, which makes TPE-hidden viruses difficult to identify by using decryption-based detection methods.

Variant:DGME

A separate, modified version of TPE has also appeared. It is known as the Darwinian Genetic Mutation Engine (DGME). DGME was published in Mark Ludwig's latest disputed book 'Computer Viruses, Artificial Life and Evolution'.

TPE takes up about 1.6 KB. Presently, it is known to be linked to 10 different viruses.

Variant:Girafe (Coffeeshop)

Other:Resident, COM/EXE-files

Girafe was the first virus to use TPE-encryption in its code. It infects COM and EXE files. On thursdays it shows a picture from Cannabis magazine and a text "Legalize Cannabis". Infected files are 2000-4000 bytes longer than original files.

The next text can be found inside Girafe in a crypted form:

COSCCLVSNEHTTBVIFIGIRAFEMTBRIM [ MK / Trident ] Amsterdam = COFFEESHOP!

See also: Cruncher

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.