Tencent94332 and Other 'Tencent' Strings: What They Mean

By · Updated · 7 min read

If you searched a string like tencent94332, tencent64332 or tencent14332, here is the honest answer first: that is not the format of a Tencent antivirus detection name, and I have not been able to find any authoritative source that says what those strings are. What I can tell you is what genuine Tencent detections look like, where a “tencent” plus-digits string tends to turn up on a website, and how to work out whether yours is harmless or a sign of compromise.

I’d rather give you a way to check than a confident guess. The steps below settle it in almost every case.

What a real Tencent detection looks like

Tencent runs an antivirus engine — often referred to as TAV, Tencent Anti-Virus — that appears on VirusTotal simply as Tencent. Its detection names follow the usual vendor pattern of type, platform, family and variant. Examples reported publicly include labels in the form Malware.Win32.Gencirc.<hex> and Trojan.Win32.<family>, where the last part is a short hexadecimal identifier rather than a clean number.

In other words, a real Tencent verdict appears in the Tencent row of a scan report, with a descriptive name next to it. It does not appear as a single word glued to the vendor name. If you are looking at a VirusTotal report and the row literally says Tencent, the detection is whatever text is in the result column beside it — and the fix for a wrong one is covered in my Tencent false positive removal steps.

Where did you see it?

Because the string itself tells you almost nothing, the place you found it is what matters. These are the places a strange username-style string most often turns up on a website, and what each one implies.

Where you saw itWhat it usually meansWorry level
WordPress Users list, as an administratorAn account you didn’t create with full control of the siteHigh
Users list, as a subscriber or customerBot registrations, usually through an open signup formLow to moderate
Comments or form submissionsSpam bots using generated namesLow
Email “From” line or reply-toSpam or phishing, possibly sent through your siteModerate
Server access logs or user-agent stringsAutomated traffic identifying itself oddlyLow unless it hits admin URLs
A VirusTotal or security-product reportA genuine detection — read the full rowDepends on the verdict
Inside a PHP or JS file, or the databaseInjected contentHigh

If it’s a user account

This is the case to take seriously. Attackers who get into a WordPress site almost always leave an administrator account behind so they can return, and they often give it a throwaway name that looks machine-generated. Check from the command line rather than the dashboard, because some malware hides its accounts from the Users screen:

wp user list --role=administrator --fields=ID,user_login,user_email,user_registered

Or directly in the database:

SELECT u.ID, u.user_login, u.user_email, u.user_registered
FROM wp_users u JOIN wp_usermeta m ON m.user_id = u.ID
WHERE m.meta_key = 'wp_capabilities' AND m.meta_value LIKE '%administrator%';

If the dashboard count and the database count disagree, you have a hidden admin and a compromised site — my guide on hidden admin users in WordPress shows how those are concealed and removed. Deleting the account is not enough on its own; whatever created it can create another. Check the registration date against file modification times, and read how the site got hacked before you consider it done.

If the account is only a subscriber and your site allows open registration, it is most likely bot signups. Turn off “Anyone can register” under Settings → General unless you genuinely need it, and delete the junk accounts in bulk.

If it’s in your files or database

A string you don’t recognise inside site code or content is worth tracing to its full context. Search for it everywhere at once:

grep -rn "tencent94332" /path/to/site --include=*.php --include=*.js --include=.htaccess
wp db search "tencent94332" --all-tables

Then look at what surrounds it. A username inside a spam post, a domain inside a <script src>, a value in wp_options that loads on every page — each points somewhere different. If it sits next to a domain name, my guide to checking a strange domain in your site’s code walks through looking it up safely. If it sits inside obfuscated code, base64 and obfuscated code in WordPress covers how to read it without running it.

If it’s in email or logs

Spam that uses your domain in the From line may be spoofed rather than sent through your server — the message headers tell you which. If the Received lines show your own server, the site is sending mail it shouldn’t, which is covered in hacked website sending spam. If they don’t, it’s spoofing, and SPF, DKIM and DMARC are the fix.

In access logs, a strange user-agent on its own is noise. What matters is what it requested: repeated POSTs to wp-login.php or xmlrpc.php, or requests for files that shouldn’t exist. Reading access logs after a hack shows what to filter for.

If Tencent really is flagging you

When the Tencent row on VirusTotal shows a verdict against your file or URL, treat it the way you would any single-engine hit: check whether other engines agree, check the file’s origin, and check the site itself with my free scanner and the blacklist checker. If it is a false positive, Tencent takes reports through a dedicated false-positive mailbox; the address and what to send are on my Tencent removal page. If other vendors are listing you too, the vendor removal directory has every route in one place.

And if the trail leads to an admin account you didn’t create, or code you didn’t write, stop investigating strings and treat it as a compromise. That is exactly what my malware removal service is for.

Common questions

What is tencent94332?

I have not found an authoritative source that explains it. It does not match the format of Tencent antivirus detection names, which appear in the Tencent row of a scan report with a descriptive label. The useful question is where you saw it: as an admin user, in your files or database, in email, or in logs. Each points to a different check.

Is tencent94332 a virus?

Not as far as can be confirmed. It is not a recognised malware or detection name. If it appears as an administrator account on your website, or inside your site's code or database, treat that as a sign of compromise and investigate. If it only appears in comment spam or bot signups, it is usually just noise.

What do real Tencent detections look like?

On VirusTotal the engine is listed as Tencent, and the verdict sits beside it in the results column, typically in a form such as Malware.Win32.Gencirc followed by a short hexadecimal identifier, or Trojan.Win32 followed by a family name.

How do I report a Tencent false positive?

Tencent accepts false-positive reports through a dedicated email mailbox for its antivirus engine. Send the VirusTotal permalink, the exact label, the SHA-256 for files and your evidence that the file or site is clean. Confirm the site really is clean before you send it.

I found a strange admin user with a random name. What should I do?

Assume the site is compromised. List administrators with WP-CLI or a database query rather than the dashboard, since some malware hides accounts. Remove the account, but also find what created it, check for backdoors and modified files, and rotate every password, because a deleted account can simply be recreated.