Trojan

Trojan:MSIL/AgentTesla.FN!MTB removal instruction

Malware Removal

The Trojan:MSIL/AgentTesla.FN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.FN!MTB virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:MSIL/AgentTesla.FN!MTB?


File Info:

crc32: 2C5206F1
md5: 5d41d8b9af733fc35ee61458a1551468
name: 5D41D8B9AF733FC35EE61458A1551468.mlw
sha1: 0aefa96ee8a1b61ac471de4279f38be0b2bb65b8
sha256: 027044b05e7e2394a8cefa312ef324eb62b01f757be6532050b3cc013bf88da7
sha512: 4063298ca822bb8187097b463dff41cfde38d1ff4a0b07cf25a1cacdbd878f5bc0a5fb822bd5c34720099198791230a9b617958fe6e689f6a44c7630657b4cb4
ssdeep: 24576:/aJET5ZEYj/Isqi0fQI6zjSuaW8Cj0hntUEcrsEOzVs29LuotV2:z0YH38CfEzVp9Llc
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019 Windscribe Limited
FileVersion: 2.0.2.10
CompanyName: Windscribe Limited
ProductName: Windscribe
ProductVersion: 2.0.2.10
FileDescription: Windscribe Installer
OriginalFilename: Windscribe.exe
Translation: 0x0409 0x04b0

Trojan:MSIL/AgentTesla.FN!MTB also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.MSILHeracles.15377
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:MSIL/AgentTesla.5bf8babd
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ee8a1b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ABAW
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderGen:Variant.MSILHeracles.15377
MicroWorld-eScanGen:Variant.MSILHeracles.15377
Ad-AwareGen:Variant.MSILHeracles.15377
SophosMal/Generic-S
ComodoMalware@#bbweuuwjkjlr
BitDefenderThetaGen:NN.ZemsilF.34692.kn2@aGm1dYfi
TrendMicroTROJ_GEN.R002C0DEN21
McAfee-GW-EditionPWS-FCWJ!5D41D8B9AF73
FireEyeGen:Variant.MSILHeracles.15377
EmsisoftGen:Variant.MSILHeracles.15377 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Tesla.jwrbn
eGambitPE.Heur.InvalidSig
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.FN!MTB
ArcabitTrojan.MSILHeracles.D3C11
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
GDataGen:Variant.MSILHeracles.15377
AhnLab-V3Trojan/Win.AgentTesla.C4482450
McAfeeArtemis!5D41D8B9AF73
MAXmalware (ai score=86)
MalwarebytesMalware.AI.1133796971
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DEN21
RisingSpyware.Stealer!8.3090 (CLOUD)
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:MSIL/AgentTesla.FN!MTB?

Trojan:MSIL/AgentTesla.FN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment