Trojan

Trojan:MSIL/AgentTesla.CAX!MTB malicious file

Malware Removal

The Trojan:MSIL/AgentTesla.CAX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.CAX!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:MSIL/AgentTesla.CAX!MTB?


File Info:

crc32: 27F451E0
md5: 2b134be5c3d9c940c710adcf5f5e6b84
name: 2B134BE5C3D9C940C710ADCF5F5E6B84.mlw
sha1: 95342605ed928e172f42593093b75d1f5cc652f7
sha256: 64a6309eb963fb0fbc26d0d1d8a370f2e9f554174a58f2e5bd254ecba31771f3
sha512: ab008cf3458337fa11fb244afe17c93ad9314922a6ea86f1e30a52db153adeeabebe5bef4d1ccc1a6b7d4cca9c450e7dc1bfedaecd233ef51b5dbe41ab495917
ssdeep: 12288:EnK8jEyoS03dyvUIZbVIVZrbcemx7Y9JA226xLPNGsa9B3td3MTDS89dyP3fHvX:E3jEyoSUgvDBIjcei7Y9g6R1g3bm
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2013
Assembly Version: 2.6.1.0
InternalName: DispatchWrapperTy.exe
FileVersion: 2.6.1.0
CompanyName:
LegalTrademarks:
Comments: Software to config and start Coj2 Dedicated servers and to make and store mods for CoJ2 Dedicated Servers online. You can modify character's weapons, ammo quantity and set hardcore mode.
ProductName: Coj2 Controller
ProductVersion: 2.6.1.0
FileDescription: Coj2 Controller
OriginalFilename: DispatchWrapperTy.exe

Trojan:MSIL/AgentTesla.CAX!MTB also known as:

K7AntiVirusTrojan ( 0057f9d81 )
LionicTrojan.MSIL.Taskun.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.14546
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37263861
CylanceUnsafe
ZillyaTrojan.Taskun.Win32.3120
SangforTrojan.MSIL.Taskun.gen
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:MSIL/AgentTesla.fee3a8a8
K7GWTrojan ( 0057f9d81 )
CyrenW32/MSIL_Kryptik.CYQ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ACAX
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Taskun.gen
BitDefenderTrojan.GenericKD.37263861
MicroWorld-eScanTrojan.GenericKD.37263861
TencentMsil.Trojan.Taskun.Hqln
Ad-AwareTrojan.GenericKD.37263861
BitDefenderThetaGen:NN.ZemsilF.34058.dn0@aGi43ig
TrendMicroTROJ_GEN.R049C0PGM21
McAfee-GW-EditionPWS-FCXD!2B134BE5C3D9
FireEyeGeneric.mg.2b134be5c3d9c940
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.MSIL.adzfe
AviraTR/AD.AgentTesla.lwxlq
eGambitUnsafe.AI_Score_96%
MicrosoftTrojan:MSIL/AgentTesla.CAX!MTB
GDataTrojan.GenericKD.37263861
AhnLab-V3Trojan/Win.PWSX-gen.C4559224
McAfeePWS-FCXD!2B134BE5C3D9
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R049C0PGM21
YandexTrojan.Taskun!0tJmzVHGwko
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.GIQ!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.AgentTesla.HwMAtpoA

How to remove Trojan:MSIL/AgentTesla.CAX!MTB?

Trojan:MSIL/AgentTesla.CAX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment