Trojan

Trojan:MSIL/AgentTesla.JIL!MTB removal

Malware Removal

The Trojan:MSIL/AgentTesla.JIL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.JIL!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/AgentTesla.JIL!MTB?


File Info:

crc32: 6BDDAFF7
md5: 114e355e1b39cd7a2d5189a2c9443164
name: 114E355E1B39CD7A2D5189A2C9443164.mlw
sha1: 75c4a3e7461118eedec1f095308297209d0c8759
sha256: 15e279f6d2683de62ff9d328c32f0c886f5ee7d20ada26d64c08d5a41af3fe01
sha512: ad8c3f520887bb924fb6961cf367466b9ba70bd481bef5590781a5f5f2bafdfccfe1218a5aeae1f7e349c5af44356b929ed80753bbf796434f0044817578685c
ssdeep: 6144:l3BUASp9GJBmrgymJchGIFnewvsfG5aWDGVgM5o:l37wSYg7YrnOf8a/gM5o
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 10.0.17763.1
InternalName: A-4.exe
FileVersion: 10.0.17763.1
CompanyName: Microsoft Corporation
LegalTrademarks:
Comments: Change Logon Utility
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.17763.1
FileDescription: Change Logon Utility
OriginalFilename: A-4.exe

Trojan:MSIL/AgentTesla.JIL!MTB also known as:

K7AntiVirusTrojan ( 0057f56d1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.558029
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0057f56d1 )
Cybereasonmalicious.746111
CyrenW32/MSIL_Kryptik.FAF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ABXQ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderGen:Variant.Bulz.558029
MicroWorld-eScanGen:Variant.Bulz.558029
TencentMsil.Trojan.Blocker.Duwk
Ad-AwareGen:Variant.Bulz.558029
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34110.Bm0@au0qsFf
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Blocker.R067C0PGG21
McAfee-GW-EditionPWS-FCZF!114E355E1B39
FireEyeGeneric.mg.114e355e1b39cd7a
EmsisoftGen:Variant.Bulz.558029 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Noon.itcpp
MicrosoftTrojan:MSIL/AgentTesla.JIL!MTB
GDataGen:Variant.Bulz.558029
AhnLab-V3Trojan/Win.Generic.C4551454
McAfeePWS-FCZF!114E355E1B39
MAXmalware (ai score=83)
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Blocker.R067C0PGG21
IkarusTrojan.Inject
MaxSecureTrojan.Malware.73689294.susgen
FortinetW32/Noon!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:MSIL/AgentTesla.JIL!MTB?

Trojan:MSIL/AgentTesla.JIL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment