Trojan

What is “Trojan:MSIL/AgentTesla.CED!MTB”?

Malware Removal

The Trojan:MSIL/AgentTesla.CED!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Agent Tesla virus can do?

    How to determine Trojan:MSIL/AgentTesla.CED!MTB?

    
    

    File Info:

    crc32: A7CA992A
    md5: 6d074a76a94dcc62dfa66bc5a062b882
    name: 6D074A76A94DCC62DFA66BC5A062B882.mlw
    sha1: 413e6dc1c96ef5656c9e4d62c5cca61060a07332
    sha256: 77fdb42cb917a1d6c672f274dcd7884f6cc7c94503c5375d80569ffb0ad206ae
    sha512: 7e4528a58dea4c0e9ee20811be05828bb4df16ae802570c9f20c294b404595e016590251e57e395b44e666db77a410f735d44cdac216cf2d7282194ad7427eb8
    ssdeep: 12288:FlAjXxP/hP+5WyKVXY9KjcNPDY2AxRFHzf+KN8YH4+ejOjdUcPbCdkU7YgAp:XADxP/85WyKe9gcNPDsxRFHzfTKYY+e
    type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

    Version Info:

    Translation: 0x0000 0x04b0
    LegalCopyright: Copyright xa9 1996 InstallShield Software Corporation
    Assembly Version: 1.2.1.0
    InternalName: BRoooh.exe
    FileVersion: 1.2.1.0
    CompanyName: InstallShield Software Corporation
    LegalTrademarks:
    Comments: PackageForTheWeb Stub
    ProductName: PackageForTheWeb Stub
    ProductVersion: 1.2.1.0
    FileDescription: PackageForTheWeb Stub
    OriginalFilename: BRoooh.exe

    Trojan:MSIL/AgentTesla.CED!MTB also known as:

    K7AntiVirusTrojan ( 005800831 )
    Elasticmalicious (high confidence)
    CynetMalicious (score: 100)
    ALYacGen:Variant.Bulz.579206
    CylanceUnsafe
    CrowdStrikewin/malicious_confidence_100% (D)
    K7GWTrojan ( 005800831 )
    Cybereasonmalicious.1c96ef
    CyrenW32/MSIL_Kryptik.EZS.gen!Eldorado
    SymantecML.Attribute.HighConfidence
    ESET-NOD32a variant of MSIL/Kryptik.ACED
    ZonerTrojan.Win32.115961
    APEXMalicious
    AvastWin32:MalwareX-gen [Trj]
    BitDefenderGen:Variant.Bulz.579206
    MicroWorld-eScanGen:Variant.Bulz.579206
    Ad-AwareGen:Variant.Bulz.579206
    SophosML/PE-A
    BitDefenderThetaGen:NN.ZemsilF.34058.Qm0@a8VwNCh
    McAfee-GW-EditionAgentTesla-FDAW!6D074A76A94D
    FireEyeGeneric.mg.6d074a76a94dcc62
    EmsisoftGen:Variant.Bulz.579206 (B)
    SentinelOneStatic AI – Malicious PE
    MicrosoftTrojan:MSIL/AgentTesla.CED!MTB
    GridinsoftTrojan.Win32.Agent.oa!s1
    ArcabitTrojan.Bulz.D8D686
    GDataGen:Variant.Bulz.579206
    AhnLab-V3Trojan/Win.Generic.C4570837
    McAfeeAgentTesla-FDAW!6D074A76A94D
    MAXmalware (ai score=80)
    VBA32TScope.Trojan.MSIL
    MalwarebytesMalware.AI.4196131598
    PandaTrj/GdSda.A
    IkarusTrojan-Spy.FormBook
    MaxSecureTrojan.Malware.300983.susgen
    FortinetMSIL/GenKryptik.FIAU!tr
    AVGWin32:MalwareX-gen [Trj]
    Qihoo-360HEUR/QVM03.0.09C0.Malware.Gen

    How to remove Trojan:MSIL/AgentTesla.CED!MTB?

    Trojan:MSIL/AgentTesla.CED!MTB removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment