Trojan

Trojan:MSIL/AgentTesla.FF!MTB malicious file

Malware Removal

The Trojan:MSIL/AgentTesla.FF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.FF!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:MSIL/AgentTesla.FF!MTB?


File Info:

crc32: 5BA1FD93
md5: 48db1efd405907c867358fe6ae8111e4
name: 48DB1EFD405907C867358FE6AE8111E4.mlw
sha1: c8cbf648b8d519ea882208d2e5a9df53638bbd0a
sha256: 285d51cb84e0f6fe2e215a22a14c90aed6f59f4ac2bd819ab9bf364d567c3dfa
sha512: 73d423a157a430f88bc681706d961e4a7ccae39c33b44c64658aba11d142d167c7f125c733b2b09453739a79ca0b530f662e90b5ee834e666ecdd1fbc094ad25
ssdeep: 49152:4lR4u3Hx11zugUZBIpwNPwEmq2zIbDUMaqxk7lv:4lWuBrkKSPwEmbWvOR
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Action Auto xa9 2017
Assembly Version: 3.0.0.0
InternalName: HebrewCalendar.exe
FileVersion: 3.0.0.0
CompanyName: Action Auto LTD
LegalTrademarks:
Comments:
ProductName: ASManager2017
ProductVersion: 3.0.0.0
FileDescription: ASManager2017
OriginalFilename: HebrewCalendar.exe

Trojan:MSIL/AgentTesla.FF!MTB also known as:

K7AntiVirusTrojan ( 0057bf2d1 )
DrWebTrojan.PackedNET.624
CynetMalicious (score: 99)
CAT-QuickHealTrojan.MSIL
ALYacTrojan.GenericKD.36852535
CylanceUnsafe
SangforTrojan.MSIL.Bingoml.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/starter.ali1000139
K7GWTrojan ( 0057bf2d1 )
CyrenW32/MSIL_Kryptik.EEN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AATA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Bingoml.gen
BitDefenderTrojan.GenericKD.36852535
NANO-AntivirusTrojan.Win32.Bingoml.ivbltv
MicroWorld-eScanTrojan.GenericKD.36852535
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.36852535
SophosTroj/MSILIn-AQN
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.VSNW05E21
McAfee-GW-EditionPWS-FCWJ!48DB1EFD4059
FireEyeTrojan.GenericKD.36852535
EmsisoftTrojan.Crypt (A)
AviraTR/AD.Inject.ghjpw
MicrosoftTrojan:MSIL/AgentTesla.FF!MTB
ArcabitTrojan.Generic.D2325337
AegisLabTrojan.MSIL.Bingoml.4!c
ZoneAlarmHEUR:Trojan.MSIL.Bingoml.gen
GDataMSIL.Trojan.PSE.17YXG5
AhnLab-V3Trojan/Win.Generic.C4453000
McAfeeArtemis!48DB1EFD4059
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack.ADC
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.VSNW05E21
RisingTrojan.Kryptik/MSIL!1.D5BE (CLOUD)
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.109085720.susgen
FortinetMSIL/Kryptik.AATA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:MSIL/AgentTesla.FF!MTB?

Trojan:MSIL/AgentTesla.FF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment