Trojan

Trojan:MSIL/AgentTesla.DLQ!MTB removal guide

Malware Removal

The Trojan:MSIL/AgentTesla.DLQ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.DLQ!MTB virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/AgentTesla.DLQ!MTB?


File Info:

name: 5BAF357B6DFD6C9D4EBB.mlw
path: /opt/CAPEv2/storage/binaries/ca99de0e83b8226e73b9d1984934c6815d7ff97236747ca04a1fd2ffc7b9f8ba
crc32: 85831A87
md5: 5baf357b6dfd6c9d4ebb6d8ad604be94
sha1: 940843390937a49b05090c5c7f0999b9dd320bc3
sha256: ca99de0e83b8226e73b9d1984934c6815d7ff97236747ca04a1fd2ffc7b9f8ba
sha512: ccdefb13a31f7c765cdee2e5e466a1236a44ff46ac8c8c2f4ed6a0c7c29cd1f474eea0ba8b916945a6b800e0778e8c5e8a080e197d812aafda030b2f55c6ed37
ssdeep: 6144:Nq5BbR9deV7wG+w1xHE9WXy8uX8Oi5geqUAK1/T++GcMC:UHbfde+WfgWTuu5ZL++GE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C884CF5976EC5B07D0AE67F8ABB681544B72F1B4423BE31E5E8070C728E6B424E017B7
sha3_384: b9360eb067306d76408997c2be9197cdc7692ba031792631986ec61e9ffbb199f1cf5208013d526af24f3ef5126f35a5
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-16 12:17:18

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Microsoft
FileDescription: MedicalStore
FileVersion: 1.0.0.0
InternalName: ThreadPoolWorkQueueThreadLoca.exe
LegalCopyright: Copyright © Microsoft 2018
LegalTrademarks:
OriginalFilename: ThreadPoolWorkQueueThreadLoca.exe
ProductName: MedicalStore
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/AgentTesla.DLQ!MTB also known as:

LionicTrojan.MSIL.Agensla.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38041237
FireEyeGeneric.mg.5baf357b6dfd6c9d
CAT-QuickHealTrojanpws.Msil
ALYacTrojan.GenericKD.38041237
CylanceUnsafe
SangforTrojan.MSIL.Kryptik.ADLW
K7AntiVirusTrojan ( 0058a7d71 )
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 0058a7d71 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Trojan.GVR.gen!Eldorado
SymantecTrojan.Gen.9
ESET-NOD32a variant of MSIL/Kryptik.ADLW
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.38041237
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKD.38041237
SophosMal/Generic-R + Troj/MSIL-RZN
ComodoTrojWare.Win32.UMal.gvnsd@0
DrWebTrojan.PackedNET.1102
TrendMicroTROJ_FRS.0NA103KH21
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan.PSE.M6ZDP
JiangminTrojan.PSW.MSIL.cvlg
WebrootW32.Trojan.Gen
AviraTR/AD.Swotter.cxjfe
Antiy-AVLTrojan/Generic.ASSuf.415D1
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2447695
MicrosoftTrojan:MSIL/AgentTesla.DLQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MSILZilla.C4773857
McAfeeRDN/Sabsik
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt.MSIL
TrendMicro-HouseCallTROJ_FRS.0NA103KH21
YandexTrojan.Kryptik!yWg7EKKQVNA
IkarusTrojan.MSIL.Agent
FortinetMSIL/GenKryptik.FNQM!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:MSIL/AgentTesla.DLQ!MTB?

Trojan:MSIL/AgentTesla.DLQ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment