Trojan

What is “TrojanDownloader:MSIL/AgentTesla.QZ!MTB”?

Malware Removal

The TrojanDownloader:MSIL/AgentTesla.QZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:MSIL/AgentTesla.QZ!MTB virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine TrojanDownloader:MSIL/AgentTesla.QZ!MTB?


File Info:

crc32: 7237D70C
md5: 003847b258308e9f6eb05039a6e5de21
name: 003847B258308E9F6EB05039A6E5DE21.mlw
sha1: 3093af80d725fbc8cbac621c938a512464a698da
sha256: fbe04315f08ff50022d31fb59aeb9462d9930ea7fb84ebe4cdfd5d9fedc4b0df
sha512: f535d9a2e1653141bc9043570e6593760918c2a66b9a583b95a281db8e9b495c07682b426e222fd5658edf62e6cb44017bd5a4372b028de9a391f2fc59d4e02d
ssdeep: 12288:o6avUpIJX5t2Ty6gI/el9PQxQiIXAG7L3D0AzQg:o6pIJX5s/FyP+iPr5zQg
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: aRx6ccgcJqx631x62dU.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: WindowsFormsApp1
ProductVersion: 1.0.0.0
FileDescription: WindowsFormsApp1
OriginalFilename: aRx6ccgcJqx631x62dU.exe

TrojanDownloader:MSIL/AgentTesla.QZ!MTB also known as:

K7AntiVirusTrojan ( 0057a1051 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.10156
CynetMalicious (score: 100)
ALYacTrojan.PSW.AveMaria
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/starter.ali1000139
K7GWTrojan ( 0057a1051 )
CyrenW32/MSIL_Kryptik.DOX.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/GenKryptik.FDQE
ZonerTrojan.Win32.107451
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Taskun.gen
BitDefenderTrojan.GenericKD.46012276
MicroWorld-eScanTrojan.GenericKD.46012276
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.46012276
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34670.Nm0@aWJMvHj
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-FCXD!003847B25830
FireEyeGeneric.mg.003847b258308e9f
EmsisoftTrojan.GenericKD.46012276 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.xqyp
WebrootW32.Trojan.Gen
AviraTR/AD.MortyStealer.efikk
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanDownloader:MSIL/AgentTesla.QZ!MTB
ArcabitTrojan.Generic.D2BE1774
GDataWin32.Backdoor.AMRat.V5FZV8
AhnLab-V3Trojan/Win.AgentTesla.R414417
McAfeePWS-FCXD!003847B25830
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.AveMaria
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00D121
YandexTrojan.Igent.bVCcJV.55
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.FDQE!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Generic.HgIASR4A

How to remove TrojanDownloader:MSIL/AgentTesla.QZ!MTB?

TrojanDownloader:MSIL/AgentTesla.QZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment