Trojan

Trojan:MSIL/AgentTesla.BVW!MTB removal instruction

Malware Removal

The Trojan:MSIL/AgentTesla.BVW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.BVW!MTB virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/AgentTesla.BVW!MTB?


File Info:

crc32: C6A5F34B
md5: 99fc947e5e122f99660aec5f0f0855f2
name: 99FC947E5E122F99660AEC5F0F0855F2.mlw
sha1: d6a007c9074eec5e045ecfbedd833e1a5e8d5607
sha256: 12769dfad3c04708ff571307f8591db3acd2469ffdf25813f0eb6ea3ecc3af73
sha512: 2ddfe9af0f688bc14215d875b383a1df23d7a63e7e8c28457173dabe23e9bab37e70483aef7a8991ef1dd36ae7143261995e3ea67815d12a6dd8f53baec84967
ssdeep: 24576:18vjJyU5X7RkIFauHskmTFAXg5T1w/tlhZ:1gFZ5XV51m5AXkT1wVp
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2015 - 2021
Assembly Version: 1.0.0.0
InternalName: v44xk.exe
FileVersion: 1.0.0.0
CompanyName: Micro Ltd.
LegalTrademarks:
Comments:
ProductName: KUI Sole
ProductVersion: 1.0.0.0
FileDescription: KUI Sole
OriginalFilename: v44xk.exe

Trojan:MSIL/AgentTesla.BVW!MTB also known as:

K7AntiVirusTrojan ( 0057f1771 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.13845
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacTrojan.GenericKD.37207762
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:MSIL/Kryptik.e23ac771
K7GWTrojan ( 0057f1771 )
Cybereasonmalicious.9074ee
CyrenW32/Trojan.MPVT-0146
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ABVW
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Taskun.gen
BitDefenderTrojan.GenericKD.37207762
MicroWorld-eScanTrojan.GenericKD.37207762
Ad-AwareTrojan.GenericKD.37207762
SophosMal/Generic-S
ComodoMalware@#1supgmh4yu32r
BitDefenderThetaGen:NN.ZemsilF.34790.Zm0@ay68d4p
McAfee-GW-EditionBehavesLike.Win32.Fareit.cc
FireEyeGeneric.mg.99fc947e5e122f99
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Remcos.onxka
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.BVW!MTB
GDataTrojan.GenericKD.37207762
AhnLab-V3Trojan/Win.Generic.C4545672
McAfeeRDN/Generic.rp
MAXmalware (ai score=85)
VBA32CIL.StupidPInvoker-1.Heur
MalwarebytesTrojan.Tasker
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00G821
YandexTrojan.AvsArher.bSIdr7
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Taskun.ABVW!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Remcos.HwMAebcA

How to remove Trojan:MSIL/AgentTesla.BVW!MTB?

Trojan:MSIL/AgentTesla.BVW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment