Trojan

TrojanDownloader:MSIL/AgentTesla.QN!MTB malicious file

Malware Removal

The TrojanDownloader:MSIL/AgentTesla.QN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:MSIL/AgentTesla.QN!MTB virus can do?

  • Network activity detected but not expressed in API logs

How to determine TrojanDownloader:MSIL/AgentTesla.QN!MTB?


File Info:

crc32: 821A040F
md5: 29fd4e6e6034b24fcbde11ecadc7c375
name: 29FD4E6E6034B24FCBDE11ECADC7C375.mlw
sha1: c0a2d95df7e0163b2b19950b35008d308f34e575
sha256: 7cdf04a12db1a317e5f039f407ca0aafd16e5bdea27890ab3d058d958d414ba9
sha512: b00325397f577151d89b666c549881568813b6337601d9c17cf8f687a13c89ac5337a4e25c85dc4f13c0188a476c5745732c4d2bb6e34dbc9404c54468cb65db
ssdeep: 24576:HgMhlt0J8ITIIIIIIIII/KIIIIIIIIIIIIIRIIIIIIIIIIII8o1IIIIIIIaIIII:i8ITIIIIIIIII/KIIIIIIIIIIIIIRII
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 2.0.0.0
InternalName: RemotingTimeoutException.exe
FileVersion: 2.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: McGrath
ProductVersion: 2.0.0.0
FileDescription: McGrath
OriginalFilename: RemotingTimeoutException.exe

TrojanDownloader:MSIL/AgentTesla.QN!MTB also known as:

K7AntiVirusTrojan ( 00579d291 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.612
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacTrojan.GenericKD.36603307
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3013834
SangforInfostealer.MSIL.Agensla.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:MSIL/AgentTesla.8ee63089
K7GWTrojan ( 00579d291 )
Cybereasonmalicious.e6034b
CyrenW32/MSIL_Kryptik.CYQ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32MSIL/Spy.Agent.AES
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.36603307
NANO-AntivirusTrojan.Win32.GCS.dkpiay
MicroWorld-eScanTrojan.GenericKD.36603307
TencentMsil.Trojan-qqpass.Qqrob.Hvab
Ad-AwareTrojan.GenericKD.36603307
SophosMal/Generic-R + Troj/TeslaA-AIN
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.MSIL.BLADABINDI.AC
McAfee-GW-EditionPWS-FCUF!29FD4E6E6034
FireEyeTrojan.GenericKD.36603307
EmsisoftTrojan.GenericKD.36603307 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.MSIL.ccdl
AviraTR/AD.AgentTesla.javqf
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.323F1D4
MicrosoftTrojanDownloader:MSIL/AgentTesla.QN!MTB
ArcabitTrojan.Generic.D22E85AB
GDataMSIL.Trojan-Stealer.AgentTesla.WL1ONZ
AhnLab-V3Trojan/Win.Generic.C4398307
McAfeePWS-FCUF!29FD4E6E6034
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.AgentTesla
PandaTrj/WLT.F
TrendMicro-HouseCallTrojanSpy.MSIL.BLADABINDI.AC
IkarusBackdoor.MSIL.Bladabindi
MaxSecureTrojan.Malware.74499699.susgen
FortinetMSIL/Kryptik.AAEM!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove TrojanDownloader:MSIL/AgentTesla.QN!MTB?

TrojanDownloader:MSIL/AgentTesla.QN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment