Trojan

Trojan:MSIL/AgentTesla.ARR!MTB removal

Malware Removal

The Trojan:MSIL/AgentTesla.ARR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.ARR!MTB virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:MSIL/AgentTesla.ARR!MTB?


File Info:

crc32: 4EDD9184
md5: 30e97352af5c2d4dc09a085d7f8e210f
name: 30E97352AF5C2D4DC09A085D7F8E210F.mlw
sha1: b5cc7bdf0632240ab74326b668cbd701c59cf277
sha256: 12758eea50a5f2637e5588c99cfe1ad7408b5214d952ef41cf186e0dfcb56dd0
sha512: b78e223cf10050b606cef59c7d7b0b823d86c2d5ef6aaeb7671ec8d190410f0bf7b56ecdd4c1feeaf4718a2bbd27562e44f353843762983bb5fda9093c0f1f24
ssdeep: 24576:+mlJCQ79J3ZE1Xc5SwWOqG9Ay+McUHPBDmIw:+mlJCm7au45gv5ced
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Gilbert Adjin Frimpong
Assembly Version: 1.0.0.0
InternalName: GacIdentityPermission.exe
FileVersion: 1.0.0.0
CompanyName: Gilbert Adjin
LegalTrademarks:
Comments:
ProductName: Shop Manager
ProductVersion: 1.0.0.0
FileDescription: Shop Manager
OriginalFilename: GacIdentityPermission.exe

Trojan:MSIL/AgentTesla.ARR!MTB also known as:

K7AntiVirusTrojan ( 0057be281 )
DrWebTrojan.PackedNET.624
ALYacSpyware.LokiBot
CylanceUnsafe
AlibabaTrojan:Application/Generic.b9f66d72
K7GWTrojan ( 0057be281 )
CyrenW32/MSIL_Kryptik.EEC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AASO
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Injuke.gen
BitDefenderTrojan.GenericKD.36846721
MicroWorld-eScanTrojan.GenericKD.36846721
TencentMsil.Trojan.Injuke.Lkeb
Ad-AwareTrojan.GenericKD.36846721
SophosMal/Generic-S
ComodoMalware@#3skdtnz8i30f8
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.36846721
EmsisoftTrojan.Crypt (A)
WebrootW32.Malware.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.ARR!MTB
AegisLabTrojan.MSIL.Androm.m!c
ZoneAlarmHEUR:Trojan.MSIL.Injuke.gen
GDataMSIL.Trojan.PSE.GXPSRD
AhnLab-V3Infostealer/Win.Lokibot.R418937
McAfeeArtemis!30E97352AF5C
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.ADC
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CE421
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.AARD!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:MSIL/AgentTesla.ARR!MTB?

Trojan:MSIL/AgentTesla.ARR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment