Trojan

Trojan:MSIL/AgentTesla.LAN!MTB removal instruction

Malware Removal

The Trojan:MSIL/AgentTesla.LAN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.LAN!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/AgentTesla.LAN!MTB?


File Info:

name: 7FF5674B81790E6EE26E.mlw
path: /opt/CAPEv2/storage/binaries/4bccc2a17e1311c4bf6972c7bce13ce690cf21e34682803fc2496be5ab37684d
crc32: 08573253
md5: 7ff5674b81790e6ee26edf2b0d03cbec
sha1: 5f4f8cef9955d5f0591fe6240ee6243414622e38
sha256: 4bccc2a17e1311c4bf6972c7bce13ce690cf21e34682803fc2496be5ab37684d
sha512: 3a1c9310ba686e6285897f345c83dddd2ceaf1f5034fa2223a4b1039881d39e61eb20eb8551236d3662d85ec2071043aee1d18d335e74f850b5e514c586d523b
ssdeep: 12288:o2TPkUSBVYwuVd7OvL6P2ekAMJ491cn0U5/7HFQ1LZJW:jTPOBCwuVd3+tJ491cn0clQtZY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13ED40252EFB099A6C1190EF65172E070C374DE90BC62F75A8DD9BDA337733E404852A6
sha3_384: dadb2ed6508802836108296fcbde4add693f4c0e04ac866e8cd4bf05be455d2412e6301d133f2e0e792cbdbc7eb96437
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-10-13 01:45:28

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: reblGreen Software Ltd
FileDescription: DimWin Brightness
FileVersion: 2.0.1.0
InternalName: IDeferredDisposab.exe
LegalCopyright: Copyright © 2015
LegalTrademarks:
OriginalFilename: IDeferredDisposab.exe
ProductName: DimWin Brightness
ProductVersion: 2.0.1.0
Assembly Version: 2.0.1.0

Trojan:MSIL/AgentTesla.LAN!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Agensla.i!c
tehtrisGeneric.Malware
DrWebBackDoor.SpyBotNET.25
MicroWorld-eScanTrojan.Ransom.Loki.GXF
ClamAVWin.Packed.Msilheracles-10009903-0
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
SkyhighBehavesLike.Win32.Generic.jc
McAfeePWS-FCZF!7FF5674B8179
Cylanceunsafe
SangforInfostealer.MSIL.Agensla.gen
K7AntiVirusTrojan ( 00588e3a1 )
AlibabaTrojanPSW:MSIL/AgentTesla.37df5e78
K7GWTrojan ( 00588e3a1 )
Cybereasonmalicious.f9955d
ArcabitTrojan.Ransom.Loki.GXF
VirITTrojan.Win32.MSIL_Heur.A
SymantecScr.Malcode!gdn34
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.ADDJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.Ransom.Loki.GXF
AvastWin32:CrypterX-gen [Trj]
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:P6h0p+lkRC2G0zqTxMZbfA)
SophosTroj/Krypt-DO
F-SecureHeuristic.HEUR/AGEN.1309270
VIPRETrojan.Ransom.Loki.GXF
EmsisoftTrojan.Ransom.Loki.GXF (B)
IkarusTrojan.Inject
GoogleDetected
AviraHEUR/AGEN.1309270
Antiy-AVLTrojan/MSIL.Kryptik
Kingsoftmalware.kb.c.987
MicrosoftTrojan:MSIL/AgentTesla.LAN!MTB
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.Ransom.Loki.GXF
VaristW32/MSIL_Kryptik.FVQ.gen!Eldorado
AhnLab-V3Trojan/Win.PWSX-gen.C4699184
VBA32TrojanLoader.MSIL.DaVinci.Heur
ALYacTrojan.Ransom.Loki.GXF
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
YandexTrojan.Kryptik!TQPAad41iq0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ADIA!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/AgentTesla.LAN!MTB?

Trojan:MSIL/AgentTesla.LAN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment