Trojan

Trojan:MSIL/AgentTesla.CCHS!MTB removal instruction

Malware Removal

The Trojan:MSIL/AgentTesla.CCHS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.CCHS!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary file triggered multiple YARA rules

How to determine Trojan:MSIL/AgentTesla.CCHS!MTB?


File Info:

name: 808128A70A02906736F9.mlw
path: /opt/CAPEv2/storage/binaries/eeaceaf1058769b80a0edc94c77df8752446921bf1a93454328590c9bdc1df66
crc32: AF24E278
md5: 808128a70a02906736f9470ce5659f7f
sha1: 2251316bc1decedc19d38481dbbbd5f837faa408
sha256: eeaceaf1058769b80a0edc94c77df8752446921bf1a93454328590c9bdc1df66
sha512: b50246131caa9e0b8cdb86de13f3467c393f3c223156dee5080b35a21778d6f6da03e34d35743e301b316b80864fe01b1aad21c9ccc0b57a84b350fa1322e6d8
ssdeep: 3072:C2LzzMU0sMtMOr40kZWvbXi/EhOUpQx0P0VZMou5NPe6Yng:LzMU0sMtMOr4ADyOQx0P0VZ56eH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB341F037E88EB15E5A87D3782EF682413F2B4C71633C60F6F49AEA514512426D7E72D
sha3_384: e9a559a48a56b84ebf9aa35463b38578e2f95aa2193ad5ec9bd73dbe223e36c1fecb1d306dcaf65f60ecac5d73c09ab6
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-02-22 17:09:59

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: 2428274c-45d6-4ca2-841e-18b668ffaa16.exe
LegalCopyright:
OriginalFilename: 2428274c-45d6-4ca2-841e-18b668ffaa16.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/AgentTesla.CCHS!MTB also known as:

BkavW32.AIDetectMalware.CS
ElasticWindows.Trojan.AgentTesla
CAT-QuickHealTrojan.Agenttesla
SkyhighBehavesLike.Win32.AgentTesla.dm
McAfeeAgentTesla-FDUP!808128A70A02
MalwarebytesSpyware.AgentTesla.Generic
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 005ac8e01 )
K7GWSpyware ( 005ac8e01 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitGeneric.Dacic.F024A244.A.8FF9AD3A
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.AgentTesla.I
APEXMalicious
ClamAVWin.Packed.Msilperseus-9956591-0
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.a
BitDefenderGeneric.Dacic.F024A244.A.8FF9AD3A
MicroWorld-eScanGeneric.Dacic.F024A244.A.8FF9AD3A
AvastWin32:PWSX-gen [Trj]
EmsisoftGeneric.Dacic.F024A244.A.8FF9AD3A (B)
F-SecureTrojan.TR/Spy.Gen8
DrWebBackDoor.SpyBotNET.62
VIPREGeneric.Dacic.F024A244.A.8FF9AD3A
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.808128a70a029067
SophosMal/Generic-S
IkarusTrojan-Spy.MSIL.Redline
VaristW32/Azorult.D.gen!Eldorado
AviraTR/Spy.Gen8
Kingsoftmalware.kb.c.999
MicrosoftTrojan:MSIL/AgentTesla.CCHS!MTB
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.a
GDataMSIL.Trojan-Stealer.BatStealer.A
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5555608
ALYacGeneric.Dacic.F024A244.A.8FF9AD3A
MAXmalware (ai score=80)
VBA32Trojan.MSIL.InfoStealer.gen.D
Cylanceunsafe
PandaTrj/GdSda.A
RisingTrojan.AntiVM!1.CF63 (CLASSIC)
YandexTrojanSpy.AgentTesla!3IZT14Ot3lU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/RedLine.B!tr
BitDefenderThetaGen:NN.ZemsilF.36802.pm0@a4bRhre
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.70a029
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/AgentTesla.CCHS!MTB?

Trojan:MSIL/AgentTesla.CCHS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment