Trojan

Trojan:MSIL/AgentTesla.MBKR!MTB removal instruction

Malware Removal

The Trojan:MSIL/AgentTesla.MBKR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.MBKR!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/AgentTesla.MBKR!MTB?


File Info:

name: 35CE62FE711D3925ADC4.mlw
path: /opt/CAPEv2/storage/binaries/217a262a39180a91c826d58610cfbc2c1b5434c47d88213b3fc7e57ab4c2f53e
crc32: 9DDE584D
md5: 35ce62fe711d3925adc473c2d79edc86
sha1: af75a38e91620938cbe05977204e5f6180cdf584
sha256: 217a262a39180a91c826d58610cfbc2c1b5434c47d88213b3fc7e57ab4c2f53e
sha512: c3c123f1e135811dd97793d9d509722ae1b6c738597e00d3e271c76da32ed64a64219ac6ce3eb310860daaf8ff22d98624a3e1b67dba454918c69ec3daffa58b
ssdeep: 12288:MG+iDkb6W5Y/SRESYnuvP6HJPHEWFwph4C9aZvEkoHiea663x:MGbWeSeu36HKqshTgEkoCZ6i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BD4232747D085ABDC2E4A3A48C3B787C336F411AAF6DA5CBC85250C9B57D0FAE10D69
sha3_384: 37658c0618fbdfce711418f070d46141e1916eca2a3800699014662e49b62f0ec31423dc0d35dc779fa247f5b1e077bd
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-11-02 01:47:39

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Hewlett-Packard
FileDescription: File-Auto-Sync
FileVersion: 1.3.0.0
InternalName: bmln.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: bmln.exe
ProductName: File-Auto-Sync
ProductVersion: 1.3.0.0
Assembly Version: 4.0.0.0

Trojan:MSIL/AgentTesla.MBKR!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Agensla.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Lazy.5527
FireEyeGen:Variant.Ser.Lazy.5527
SkyhighBehavesLike.Win32.Generic.hc
McAfeeArtemis!35CE62FE711D
Cylanceunsafe
SangforTrojan.Msil.AgentTesla.Vmt9
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanPSW:MSIL/AgentTesla.9cd51c26
K7GWTrojan ( 005ad7381 )
K7AntiVirusTrojan ( 005ad7381 )
ArcabitTrojan.Ser.Lazy.D1597
BitDefenderThetaGen:NN.ZemsilF.36744.Lm0@aWAWTdo
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AKAA
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderGen:Variant.Ser.Lazy.5527
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.11bb10ca
EmsisoftGen:Variant.Ser.Lazy.5527 (B)
F-SecureTrojan.TR/AD.GenSteal.kgoge
DrWebTrojan.Packed2.45876
VIPREGen:Variant.Ser.Lazy.5527
SophosTroj/Krypt-ABH
IkarusTrojan.MSIL.Crypt
GoogleDetected
AviraTR/AD.GenSteal.kgoge
VaristW32/MSIL_Kryptik.KCD.gen!Eldorado
MicrosoftTrojan:MSIL/AgentTesla.MBKR!MTB
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataGen:Variant.Ser.Lazy.5527
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.TrojanX-gen.C5536193
ALYacGen:Variant.Ser.Lazy.5527
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:8rrHXxaOu46qrC442lzHzw)
YandexTrojan.Kryptik!8A3BLP0d2ZA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.GLXZ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/AgentTesla.MBKR!MTB?

Trojan:MSIL/AgentTesla.MBKR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment