Malware

PWS:MSIL/AgentTesla.ZD!MTB removal

Malware Removal

The PWS:MSIL/AgentTesla.ZD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/AgentTesla.ZD!MTB virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:MSIL/AgentTesla.ZD!MTB?


File Info:

crc32: 621EEA82
md5: 08179aaaf9c3ee86f040025ca3e9509c
name: 08179AAAF9C3EE86F040025CA3E9509C.mlw
sha1: 7d51229d2a893579c85b0d71543505641c6e8868
sha256: d5cbb60f893a7ce656a25f9f449b1150a8b24cc20a4b550b1a5c536d3cf41fc8
sha512: f7dfae9d91f72da70cc3fa2d7a1f38cff16c294a4d13283d719367feac56fa347a3e75e5b823be06d94a3d714b23c1d3470d776d827241e331e60851e1036039
ssdeep: 6144:p4XkTkBCDm8y50jRVCdT3/ceLDcLuZTvznLhm54P64fK+yW+tvlyHY/:/QP50jwcEc6tBm54Pr5+F
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2007 :652HC5<;=DI99D882I5
Assembly Version: 1.0.0.0
InternalName: ttttttttttttttttt.exe
FileVersion: 6.9.12.15
CompanyName: :652HC5<;=DI99D882I5
Comments: ?:4FFA@A3F3BG<;
ProductName: E=3@D@JFC6::3DJ=?
ProductVersion: 6.9.12.15
FileDescription: E=3@D@JFC6::3DJ=?
OriginalFilename: ttttttttttttttttt.exe

PWS:MSIL/AgentTesla.ZD!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.832364
FireEyeGeneric.mg.08179aaaf9c3ee86
ALYacGen:Variant.Razy.832364
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.832364
K7GWTrojan ( 005767561 )
K7AntiVirusTrojan ( 005767561 )
CyrenW32/MSIL_Kryptik.CMB.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Inject.gen
Ad-AwareGen:Variant.Razy.832364
EmsisoftGen:Variant.Razy.832364 (B)
F-SecureTrojan.TR/Kryptik.nfbyr
TrendMicroTROJ_GEN.R06CC0PAN21
McAfee-GW-EditionPWS-FCRY!08179AAAF9C3
SophosMal/Generic-S
IkarusTrojan.MSIL.Inject
AviraTR/Kryptik.nfbyr
MAXmalware (ai score=84)
MicrosoftPWS:MSIL/AgentTesla.ZD!MTB
ArcabitTrojan.Razy.DCB36C
ZoneAlarmHEUR:Trojan.MSIL.Inject.gen
GDataGen:Variant.Razy.832364
CynetMalicious (score: 85)
AhnLab-V3Malware/Gen.RL_Reputation.C4305380
McAfeePWS-FCRY!08179AAAF9C3
MalwarebytesMalware.AI.4243191972
ESET-NOD32a variant of MSIL/Kryptik.ZJE
TrendMicro-HouseCallTROJ_GEN.R06CC0PAN21
YandexTrojan.Igent.bVctJP.10
FortinetW32/Inject!tr
BitDefenderThetaGen:NN.ZemsilF.34804.Um0@aaBDL1
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.d2a893
Paloaltogeneric.ml
Qihoo-360HEUR/QVM03.0.0745.Malware.Gen

How to remove PWS:MSIL/AgentTesla.ZD!MTB?

PWS:MSIL/AgentTesla.ZD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment