Trojan

How to remove “Trojan:MSIL/AgentTesla.ASAA!MTB”?

Malware Removal

The Trojan:MSIL/AgentTesla.ASAA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.ASAA!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/AgentTesla.ASAA!MTB?


File Info:

name: FAF88DB90E61AE5093F7.mlw
path: /opt/CAPEv2/storage/binaries/ecca354c7c340b8bf5d59bc5dbf06cfc05a2ed439ce121e343b59dc7a7e2e371
crc32: C7B7ED36
md5: faf88db90e61ae5093f77f5804e272aa
sha1: 80ab72b848fd103200600be48c1bb37d125bacfa
sha256: ecca354c7c340b8bf5d59bc5dbf06cfc05a2ed439ce121e343b59dc7a7e2e371
sha512: 7132ab9db587e0e9196e11b28eaf8dd367f4bc4bfff6fcd63f7e15f614051981efcd43986e495c85b887b8103615da4880b546af4ab46ff6fcd0e997234288c9
ssdeep: 12288:LoAcuF6mn1DHLZnvJUMiOe42KMu/N3mWhQmwmJCMpUSc466X+DxWsPaejwapiOf3:XiOV/NOa7cSgWsPeKiMOHlqvN8UJBZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11105014873FA491FC66F2FBC2D21717183F8B2523063C79F5E96A9DC8D82B194A91643
sha3_384: e8a59544fcda6f09edce9a36757debc362b5668bae40f5d07c57ddb427ae65499f7cace10d65c5c1d2e628b5d7245deb
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-06-12 01:55:53

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Gas Natural Fenosa
FileDescription: WhamoLauncher.Charts
FileVersion: 1.0.8563.8876
InternalName: cYDG.exe
LegalCopyright: Copyright © DeadHead Software 2016
LegalTrademarks: © DeahHead 2016
OriginalFilename: cYDG.exe
ProductName: WhamoLauncher.Charts
ProductVersion: 1.0.8563.8876
Assembly Version: 1.0.8563.8876

Trojan:MSIL/AgentTesla.ASAA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Noon.4!c
MicroWorld-eScanTrojan.Generic.33935086
FireEyeTrojan.Generic.33935086
ALYacTrojan.Generic.33935086
MalwarebytesTrojan.MalPack.PNG.Generic
SangforTrojan.Win32.Kryptik.V6mf
AlibabaTrojanSpy:MSIL/SnakeLogger.a5121433
VirITTrojan.Win32.MSIL_Heur.A
CyrenW32/MSIL_Troj.CQG.gen!Eldorado
SymantecScr.Malcode!gdn34
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AJAY
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.MSIL.SnakeLogger.gen
BitDefenderTrojan.Generic.33935086
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.13cfed47
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.ckpth
DrWebTrojan.PackedNET.2032
VIPRETrojan.Generic.33935086
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftTrojan.Generic.33935086 (B)
GDataTrojan.Generic.33935086
AviraTR/Redcap.ckpth
MAXmalware (ai score=80)
Antiy-AVLTrojan/MSIL.Kryptik
ArcabitTrojan.Generic.D205CEEE
ZoneAlarmHEUR:Trojan-Spy.MSIL.SnakeLogger.gen
MicrosoftTrojan:MSIL/AgentTesla.ASAA!MTB
GoogleDetected
AhnLab-V3Infostealer/Win.Formbook.C5440475
McAfeeRDN/Generic PWS.y
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0DFC23
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:1CRIDT5cHT+AbnIm6yTaAw)
YandexTrojan.Igent.b0iQsi.17
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.AJAY!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/AgentTesla.ASAA!MTB?

Trojan:MSIL/AgentTesla.ASAA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment