Trojan

How to remove “Trojan:MSIL/AgentTesla.BC!MTB”?

Malware Removal

The Trojan:MSIL/AgentTesla.BC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.BC!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/AgentTesla.BC!MTB?


File Info:

name: FEE09EC1100769391CBA.mlw
path: /opt/CAPEv2/storage/binaries/5ce84c540a1a69f9048fc4eb28fda1acdceabcd919c35ec52982cd45e9f50f1d
crc32: 9CB41FBB
md5: fee09ec1100769391cba17ef07882e46
sha1: 35ebc4c361979d89e2eb11978426fbd0d49573f5
sha256: 5ce84c540a1a69f9048fc4eb28fda1acdceabcd919c35ec52982cd45e9f50f1d
sha512: bd7c2c24def7205482357c62835801ccf0d030cb0129b08b2baeb0b56af7f957dbe69840ae4aa02be9f251b2ed7554e5c46ab03e15c7e67ae78bb898d43c7594
ssdeep: 24576:0NNUtQhWhtqDfDXQdy+N+gfQqRsgFlDRluQ70eJiVbWpR:EzhWhCXQFN+0IEuQgyiVK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E65AD067A55CE43D0694733C4EFC12843ECAD462A66D75ABE8A33AD25013E71E8E5CF
sha3_384: 7d1e6ee0c81ffbe20ead54aa1fd00a012080f47972fab3be846df7808fd57938e512a5542ac6a4bbff42b4e53f74dd53
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-26 22:21:24

Version Info:

ProductName: 09oFGmsxTKpwZFqP2er4D7l6
CompanyName: gm8VLPd22sznwkv7
InternalName: qJQ.exe
LegalCopyright: w1ZRq5qAx2RdowAdZI46pu
Comments: jwwxk6AuohbN8oE
OriginalFilename: UM2HleL3QvVgSOTK4Xzm9K.exe
ProductVersion: 313.386.909.920
FileVersion: 863.944.846.523
Translation: 0x0409 0x0514

Trojan:MSIL/AgentTesla.BC!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen17.30000
MicroWorld-eScanTrojan.MSIL.Basic.8.Gen
ClamAVWin.Packed.Basic-9952747-0
FireEyeGeneric.mg.fee09ec110076939
CAT-QuickHealTrojan.Generic.TRFH503
ALYacTrojan.MSIL.Basic.8.Gen
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.MSIL.Basic.8.Gen
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0058ef511 )
K7GWSpyware ( 0058ef511 )
Cybereasonmalicious.110076
VirITTrojan.Win32.GenusT.DGRK
CyrenW32/MSIL_Agent.CZA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.DTX
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderTrojan.MSIL.Basic.8.Gen
AvastWin32:MalwareX-gen [Trj]
TencentTrojan-Spy.Msil.Stealer.fe
SophosMal/DCRat-C
F-SecureHeuristic.HEUR/AGEN.1323944
BitDefenderThetaGen:NN.ZemsilF.36302.Dr0@aCe31qgi
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.MSIL.Basic.8.Gen (B)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan.PSE1.UH00QZ
AviraHEUR/AGEN.1323944
Antiy-AVLTrojan[Spy]/MSIL.Stealer
ArcabitTrojan.MSIL.Basic.8.Gen
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
MicrosoftTrojan:MSIL/AgentTesla.BC!MTB
GoogleDetected
AhnLab-V3Trojan/Win.MSILZilla.C4982822
Acronissuspicious
McAfeeTrojan-FUJL!FEE09EC11007
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
Cylanceunsafe
PandaTrj/GdSda.A
RisingSpyware.Agent!8.C6 (TFE:dGZlOg0gtezMUn+WgQ)
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.73709669.susgen
FortinetMSIL/Agent.DTR!tr.spy
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:MSIL/AgentTesla.BC!MTB?

Trojan:MSIL/AgentTesla.BC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment