Trojan

What is “Trojan:MSIL/AgentTesla.KK!MTB”?

Malware Removal

The Trojan:MSIL/AgentTesla.KK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.KK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/AgentTesla.KK!MTB?


File Info:

crc32: EFB780FB
md5: efed0f9fe0d138e7efe50e663e7f3a98
name: EFED0F9FE0D138E7EFE50E663E7F3A98.mlw
sha1: b8c692e78ca0939d06d18f6d59afa01b5909440a
sha256: fdd29486217d3f13351e6245fee6a892fc4f9c2a9d51e19dca7c8c54c05da3d1
sha512: bf1873a56855396b8de157f8fc1defc32cc532f77962d13210ef20c5a7ddf34128a9ea5a8c71e235fffba549f113def46e968085d455cb96795662b762544ecc
ssdeep: 24576:0iI0Uw8HkKW1RV/VPDIzGyigQfr/kmtkhNJZzTckhs:0X0UwR3VNBHkZK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 6.1.14.0
InternalName: Volatile.exe
FileVersion: 6.01.14.0
CompanyName: 1 Up Nutrition
LegalTrademarks:
Comments: Workout Tracking & Benchmarks
ProductName: Athletic Club Management
ProductVersion: 6.01.14.0
FileDescription: Athletic Club Management
OriginalFilename: Volatile.exe

Trojan:MSIL/AgentTesla.KK!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.524
MicroWorld-eScanTrojan.Agent.FCUR
CAT-QuickHealTrojan.Multi
Qihoo-360Win32/Backdoor.Androm.HgIASOYA
ALYacSpyware.LokiBot
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforTrojan.MSIL.AgentTesla.KK
K7AntiVirusTrojan ( 005773c61 )
BitDefenderTrojan.Agent.FCUR
K7GWTrojan ( 005773c61 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Agent.FCUR
CyrenW32/MSIL_Kryptik.CZL.gen!Eldorado
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_FRS.0NA103B421
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
NANO-AntivirusTrojan.Win32.Androm.ijajsd
RisingBackdoor.Androm!8.113 (CLOUD)
Ad-AwareTrojan.Agent.FCUR
SophosMal/Generic-S + Troj/Kryptik-SA
ComodoMalware@#122h7a3tbuuzi
F-SecureTrojan.TR/Agent.giv
VIPREWin32.Malware!Drop
TrendMicroTROJ_FRS.0NA103B421
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeTrojan.Agent.FCUR
EmsisoftTrojan.Agent (A)
IkarusTrojan.MSIL.Inject
WebrootW32.Trojan.Gen
AviraTR/Agent.giv
Antiy-AVLTrojan[Backdoor]/MSIL.Androm
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:MSIL/AgentTesla.KK!MTB
ViRobotTrojan.Win32.S.Agent.1032704.A
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataTrojan.Agent.FCUR
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Lokibot.C4320613
McAfeePWS-FCUF!EFED0F9FE0D1
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of MSIL/Kryptik.ZNK
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Kryptik.ZNC!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
MaxSecureTrojan.Malware.73691364.susgen

How to remove Trojan:MSIL/AgentTesla.KK!MTB?

Trojan:MSIL/AgentTesla.KK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment