Trojan

Trojan:MSIL/AgentTesla.APJ!MTB (file analysis)

Malware Removal

The Trojan:MSIL/AgentTesla.APJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.APJ!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:MSIL/AgentTesla.APJ!MTB?


File Info:

crc32: 96B289C6
md5: cafbf5023a47e424802e8311ee0076e2
name: CAFBF5023A47E424802E8311EE0076E2.mlw
sha1: 19f5be7abef02bcddd39ad7cf9c03e1654259f9b
sha256: 3a90f3602e9695f2a8879a1f28f8a0eefbd57e8644d42a4afe47abf0c0094494
sha512: 1cd197bd107182a38e01dfe0add493426de6cf89451f673bf03b1b149f0c6046df4c09b9c894e712f65660553ec6526e11a29254b5f8ef1fc2bc90ea639fcdd2
ssdeep: 12288:W+wEzkKOArk/gzJ1zsmMRrTYU4PLHhUBESfeqG:qNKLrmgfzsmM5EU4/SmqG
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014
Assembly Version: 1.0.2.4
InternalName: TextInfo.exe
FileVersion: 1.0.2.4
CompanyName: NimitzDEV
LegalTrademarks: NimitzDEV
Comments: x4ee3x7406x8fdex63a5x7ba1x7406
ProductName: x4ee3x7406x8fdex63a5x7ba1x7406
ProductVersion: 1.0.2.4
FileDescription: x4ee3x7406x8fdex63a5x7ba1x7406
OriginalFilename: TextInfo.exe

Trojan:MSIL/AgentTesla.APJ!MTB also known as:

K7AntiVirusTrojan ( 0057b4c81 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.679
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.36792154
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/starter.ali1000139
K7GWTrojan ( 0057b4c81 )
Cybereasonmalicious.abef02
CyrenW32/MSIL_Kryptik.EAH.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.AAPA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Androm.gen
BitDefenderTrojan.GenericKD.36792154
MicroWorld-eScanTrojan.GenericKD.36792154
Ad-AwareTrojan.GenericKD.36792154
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34686.Xm0@aC0hjSm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-FCXD!CAFBF5023A47
FireEyeGeneric.mg.cafbf5023a47e424
EmsisoftTrojan.GenericKD.36792154 (B)
WebrootW32.Trojan.Gen
AviraTR/Kryptik.vpnus
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.APJ!MTB
AegisLabTrojan.MSIL.Androm.m!c
GDataMSIL.Backdoor.ASyncRAT.F40M42
AhnLab-V3Trojan/Win.Crypt.C4442172
McAfeePWS-FCXD!CAFBF5023A47
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.MSIL.ANDROM.USMANDS21
RisingBackdoor.Androm!8.113 (CLOUD)
YandexTrojan.AvsArher.bTJEKx
IkarusTrojan.MSIL.Agent
FortinetMSIL/Kryptik.AAPA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:MSIL/AgentTesla.APJ!MTB?

Trojan:MSIL/AgentTesla.APJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment