Categories: Spy

Spyware.AgentTesla.bit malicious file

The Spyware.AgentTesla.bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.AgentTesla.bit virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Spyware.AgentTesla.bit?


File Info:

crc32: 56713FE6md5: 550aca49b41b65a597f11c5845507769name: br.exesha1: 85761f39d1ca755cf49342bd9a33113825fe7b58sha256: 8def1d7fd8d74bcf214e05f26c37fedd4fef5786ceecf4a12d9a041381830401sha512: b7a947b9f56b5e5b240c888020073a6327dba332a55933ea56093405308fdcb424d596125bdd08ae0b18cf4373c3a74b4f058aef2ea10c14ba15b551d26fec5dssdeep: 24576:tqlSqN1W+nhDT5BkGGuxLNuxxqpj/Wcub/r:TUM+fVKqpj/WFTtype: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0LegalCopyright: Copyright xa9 Microsoft 2013Assembly Version: 1.0.0.0InternalName: sUxTgKjalYWGbiPSog.exeFileVersion: 1.0.0.0CompanyName: MicrosoftLegalTrademarks: Comments: ProductName: CataclysmModderProductVersion: 1.0.0.0FileDescription: CataclysmModderOriginalFilename: sUxTgKjalYWGbiPSog.exe

Spyware.AgentTesla.bit also known as:

DrWeb Trojan.PackedNET.284
MicroWorld-eScan Trojan.GenericKD.43024039
FireEye Generic.mg.550aca49b41b65a5
Qihoo-360 Generic/Trojan.PSW.374
McAfee GenericRXKG-HB!550ACA49B41B
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Malware
BitDefender Trojan.GenericKD.43024039
K7GW Trojan ( 005650951 )
BitDefenderTheta Gen:NN.ZemsilF.34106.ln0@aitUnh
F-Prot W32/MSIL_Agent.BGV.gen!Eldorado
APEX Malicious
Avast Win32:PWSX-gen [Trj]
ClamAV Win.Trojan.Agent-7682550-0
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Trojan:Win32/starter.ali1000139
AegisLab Trojan.MSIL.Agensla.i!c
Ad-Aware Trojan.GenericKD.43024039
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.qnurq
McAfee-GW-Edition Artemis!Trojan
Trapmine suspicious.low.ml.score
Emsisoft Trojan.GenericKD.43024039 (B)
Ikarus Trojan.MSIL.Inject
Cyren W32/MSIL_Agent.BGV.gen!Eldorado
Webroot Trojan.Dropper.Gen
Avira TR/Kryptik.qnurq
Fortinet MSIL/GenKryptik.EIVY!tr
Antiy-AVL Trojan[PSW]/MSIL.Agensla
Endgame malicious (high confidence)
Arcabit Trojan.Generic.D2907EA7
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
Microsoft Trojan:Win32/Occamy.C
AhnLab-V3 Trojan/Win32.Kryptik.R333655
ALYac Trojan.GenericKD.43024039
MAX malware (ai score=87)
Malwarebytes Spyware.AgentTesla.bit
Panda Trj/GdSda.A
ESET-NOD32 a variant of MSIL/Kryptik.VOK
TrendMicro-HouseCall TROJ_GEN.R03FH0CDM20
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
eGambit Unsafe.AI_Score_97%
GData Trojan.GenericKD.43024039
AVG Win32:PWSX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_60% (W)

How to remove Spyware.AgentTesla.bit?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Lazy.280688 removal guide

The Lazy.280688 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.3454153382 information

The Malware.AI.3454153382 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Midie.100502 removal tips

The Midie.100502 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Malware.AI.3915743673 (file analysis)

The Malware.AI.3915743673 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Malware.AI.2034266737 removal

The Malware.AI.2034266737 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Trojan.Win32.Agent.xbmkmt removal tips

The Trojan.Win32.Agent.xbmkmt is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago