Trojan

How to remove “Trojan:MSIL/AgentTesla.MBP!MTB”?

Malware Removal

The Trojan:MSIL/AgentTesla.MBP!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.MBP!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:MSIL/AgentTesla.MBP!MTB?


File Info:

name: 9E8DF4914B33B4946723.mlw
path: /opt/CAPEv2/storage/binaries/2f1d7c62cf88d148070d4c70d9f595160eb0b3cff2c182a04997acf835235629
crc32: 5362CA78
md5: 9e8df4914b33b4946723d01d22c5e891
sha1: d5eabdffb152ada5bbe4daac87a6b604a1d79b5c
sha256: 2f1d7c62cf88d148070d4c70d9f595160eb0b3cff2c182a04997acf835235629
sha512: 536a8d4bd2b45fde45a4c0b98d9719ba2a05bd600657117d8f44120e8e7e00d3ebb91d077736c4828ef1657f4def833c58130c23f0baf1ae05ea3a74b45cc58e
ssdeep: 49152:S1oQBOHQ5BTrDK6GjjHzAY2wlHzD1x0+eKivIyF/sn4uu:uDNgj92yTHrejPgXu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C485F1E1317D8393D1A19EB20FCA4A707AF576ACA8E0160D70F5AB2D93D2351148D9FE
sha3_384: 954416fe4f928d0277dc89ba510a1d6c7ffc6b451103f2303dadc046f6eb48b521a8d403984c8e22cf1ebd24eb756998
ep_bytes: ff250020400000000000000000000000
timestamp: 2082-12-01 17:35:22

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: MKkIi8877
FileVersion: 1.0.0.0
InternalName: MKkIi8877.exe
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: MKkIi8877.exe
ProductName: MKkIi8877
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/AgentTesla.MBP!MTB also known as:

DrWebTrojan.DownloaderNET.345
MicroWorld-eScanGen:Variant.Ser.MSILHeracles.3043
FireEyeGeneric.mg.9e8df4914b33b494
MalwarebytesTrojan.Crypt.MSIL
VIPREGen:Variant.Ser.MSILHeracles.3043
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Ser.MSILHeracles.3043
Cybereasonmalicious.fb152a
BitDefenderThetaGen:NN.ZemsilF.36792.Xr0@aiE!Wfp
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Rescoms.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
RisingMalware.Obfus/MSIL@AI.97 (RDM.MSIL2:7qjAWRSr8hELhrw1KfL3/w)
SophosML/PE-A
F-SecureTrojan.TR/Dropper.MSIL.Gen
TrendMicroTROJ_GEN.R014C0DJQ23
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Ser.MSILHeracles.3043 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ser.MSILHeracles.3043
VaristW32/ClipBanker.X.gen!Eldorado
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/MSIL.Kryptik
Kingsoftmalware.kb.c.983
ArcabitTrojan.Ser.MSILHeracles.DBE3
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
MicrosoftTrojan:MSIL/AgentTesla.MBP!MTB
GoogleDetected
AhnLab-V3Infostealer/Win.Browser.C5532303
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Ser.MSILHeracles.3043
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R014C0DJQ23
IkarusTrojan.Inject
FortinetMSIL/Agent.LEY!tr.dldr
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/AgentTesla.MBP!MTB?

Trojan:MSIL/AgentTesla.MBP!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment