Tencent94332 and Other 'Tencent' Strings: What They Mean
By Glenn Lyvers · Updated · 7 min read
If you searched a string like tencent94332, tencent64332 or tencent14332, here is the honest answer first: that is not the format of a Tencent antivirus detection name, and I have not been able to find any authoritative source that says what those strings are. What I can tell you is what genuine Tencent detections look like, where a “tencent” plus-digits string tends to turn up on a website, and how to work out whether yours is harmless or a sign of compromise.
I’d rather give you a way to check than a confident guess. The steps below settle it in almost every case.
What a real Tencent detection looks like
Tencent runs an antivirus engine — often referred to as TAV, Tencent Anti-Virus — that appears on VirusTotal simply as Tencent. Its detection names follow the usual vendor pattern of type, platform, family and variant. Examples reported publicly include labels in the form Malware.Win32.Gencirc.<hex> and Trojan.Win32.<family>, where the last part is a short hexadecimal identifier rather than a clean number.
In other words, a real Tencent verdict appears in the Tencent row of a scan report, with a descriptive name next to it. It does not appear as a single word glued to the vendor name. If you are looking at a VirusTotal report and the row literally says Tencent, the detection is whatever text is in the result column beside it — and the fix for a wrong one is covered in my Tencent false positive removal steps.
Where did you see it?
Because the string itself tells you almost nothing, the place you found it is what matters. These are the places a strange username-style string most often turns up on a website, and what each one implies.
| Where you saw it | What it usually means | Worry level |
|---|---|---|
| WordPress Users list, as an administrator | An account you didn’t create with full control of the site | High |
| Users list, as a subscriber or customer | Bot registrations, usually through an open signup form | Low to moderate |
| Comments or form submissions | Spam bots using generated names | Low |
| Email “From” line or reply-to | Spam or phishing, possibly sent through your site | Moderate |
| Server access logs or user-agent strings | Automated traffic identifying itself oddly | Low unless it hits admin URLs |
| A VirusTotal or security-product report | A genuine detection — read the full row | Depends on the verdict |
| Inside a PHP or JS file, or the database | Injected content | High |
If it’s a user account
This is the case to take seriously. Attackers who get into a WordPress site almost always leave an administrator account behind so they can return, and they often give it a throwaway name that looks machine-generated. Check from the command line rather than the dashboard, because some malware hides its accounts from the Users screen:
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
Or directly in the database:
SELECT u.ID, u.user_login, u.user_email, u.user_registered
FROM wp_users u JOIN wp_usermeta m ON m.user_id = u.ID
WHERE m.meta_key = 'wp_capabilities' AND m.meta_value LIKE '%administrator%';
If the dashboard count and the database count disagree, you have a hidden admin and a compromised site — my guide on hidden admin users in WordPress shows how those are concealed and removed. Deleting the account is not enough on its own; whatever created it can create another. Check the registration date against file modification times, and read how the site got hacked before you consider it done.
If the account is only a subscriber and your site allows open registration, it is most likely bot signups. Turn off “Anyone can register” under Settings → General unless you genuinely need it, and delete the junk accounts in bulk.
If it’s in your files or database
A string you don’t recognise inside site code or content is worth tracing to its full context. Search for it everywhere at once:
grep -rn "tencent94332" /path/to/site --include=*.php --include=*.js --include=.htaccess
wp db search "tencent94332" --all-tables
Then look at what surrounds it. A username inside a spam post, a domain inside a <script src>, a value in wp_options that loads on every page — each points somewhere different. If it sits next to a domain name, my guide to checking a strange domain in your site’s code walks through looking it up safely. If it sits inside obfuscated code, base64 and obfuscated code in WordPress covers how to read it without running it.
If it’s in email or logs
Spam that uses your domain in the From line may be spoofed rather than sent through your server — the message headers tell you which. If the Received lines show your own server, the site is sending mail it shouldn’t, which is covered in hacked website sending spam. If they don’t, it’s spoofing, and SPF, DKIM and DMARC are the fix.
In access logs, a strange user-agent on its own is noise. What matters is what it requested: repeated POSTs to wp-login.php or xmlrpc.php, or requests for files that shouldn’t exist. Reading access logs after a hack shows what to filter for.
Want the warnings gone without the paperwork?
Clearing a flag means cleaning the cause and then working each vendor's own queue. I do both.
Not sure which? Ask me first — I’ll tell you honestly if you can handle it yourself.
If Tencent really is flagging you
When the Tencent row on VirusTotal shows a verdict against your file or URL, treat it the way you would any single-engine hit: check whether other engines agree, check the file’s origin, and check the site itself with my free scanner and the blacklist checker. If it is a false positive, Tencent takes reports through a dedicated false-positive mailbox; the address and what to send are on my Tencent removal page. If other vendors are listing you too, the vendor removal directory has every route in one place.
And if the trail leads to an admin account you didn’t create, or code you didn’t write, stop investigating strings and treat it as a compromise. That is exactly what my malware removal service is for.
Common questions
What is tencent94332?
I have not found an authoritative source that explains it. It does not match the format of Tencent antivirus detection names, which appear in the Tencent row of a scan report with a descriptive label. The useful question is where you saw it: as an admin user, in your files or database, in email, or in logs. Each points to a different check.
Is tencent94332 a virus?
Not as far as can be confirmed. It is not a recognised malware or detection name. If it appears as an administrator account on your website, or inside your site's code or database, treat that as a sign of compromise and investigate. If it only appears in comment spam or bot signups, it is usually just noise.
What do real Tencent detections look like?
On VirusTotal the engine is listed as Tencent, and the verdict sits beside it in the results column, typically in a form such as Malware.Win32.Gencirc followed by a short hexadecimal identifier, or Trojan.Win32 followed by a family name.
How do I report a Tencent false positive?
Tencent accepts false-positive reports through a dedicated email mailbox for its antivirus engine. Send the VirusTotal permalink, the exact label, the SHA-256 for files and your evidence that the file or site is clean. Confirm the site really is clean before you send it.
I found a strange admin user with a random name. What should I do?
Assume the site is compromised. List administrators with WP-CLI or a database query rather than the dashboard, since some malware hides accounts. Remove the account, but also find what created it, check for backdoors and modified files, and rotate every password, because a deleted account can simply be recreated.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.