Trojan

Trojan:MSIL/AgentTesla.MOC!MTB malicious file

Malware Removal

The Trojan:MSIL/AgentTesla.MOC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.MOC!MTB virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Trojan:MSIL/AgentTesla.MOC!MTB?


File Info:

crc32: E0952F7A
md5: be32fd64b0000d935183356f7516e04e
name: okoyecryp.exe
sha1: 6d9a5c87a4fa1eb3dd7433dc6076bdbfccbc2961
sha256: b4edc5be2ae28fa9a6ff55d51c35871b81e59f988765087ca404421d2cd7670d
sha512: e7334b0db3b352122eee02ea41fb73bbab58b8a2c858a78cb17817e880d678dc6229c017d12e5d4955e15cc2a434f323eb7e0c3125e0656bafad28d9d28a93ee
ssdeep: 12288:alAGUbgZcz0V34++eSu+nmp5DQdSLYkt1TML1dm07gRhSgzBOVV/p0:aRU8y0hhSgE
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2013
InternalName: EMailSpliter
FileVersion: 1, 0, 0, 1
CompanyName: by suruiqiang (Y!M: suruiqiang)
ProductName: EMailSpliter
ProductVersion: 1, 0, 0, 1
FileDescription: EMailSpliter
OriginalFilename: EMailSpliter.EXE
Translation: 0x0804 0x04b0

Trojan:MSIL/AgentTesla.MOC!MTB also known as:

DrWebTrojan.KillProc2.8825
MicroWorld-eScanTrojan.GenericKD.33298053
McAfeePacked-FWY!BE32FD64B000
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056081c1 )
BitDefenderTrojan.GenericKD.33298053
K7GWTrojan ( 0056081c1 )
ArcabitTrojan.Generic.D1FC1685
BitDefenderThetaGen:NN.ZemsilF.34090.Ym0@a0dVI6sj
CyrenW32/Trojan.OBRB-0256
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.UQP
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaTrojan:Win32/csharp.ali2000008
NANO-AntivirusTrojan.Win32.Androm.hbeypj
ViRobotTrojan.Win32.S.Agent.829440.BA
Ad-AwareTrojan.GenericKD.33298053
EmsisoftTrojan.Crypt (A)
ComodoMalware@#1dv3yv7b6fpxz
F-SecureTrojan.TR/Kryptik.mjfco
TrendMicroTrojan.Win32.DETPLOCK.USXVPBJ20
McAfee-GW-EditionPacked-FWY!BE32FD64B000
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.be32fd64b0000d93
SophosMal/Generic-S
JiangminBackdoor.MSIL.cohh
AviraTR/Kryptik.mjfco
FortinetMSIL/Kryptik.UQP!tr
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
MicrosoftTrojan:MSIL/AgentTesla.MOC!MTB
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
AhnLab-V3Trojan/Win32.Agent.R284273
Acronissuspicious
ALYacTrojan.Agent.Wacatac
MAXmalware (ai score=80)
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.DETPLOCK.USXVPBJ20
RisingBackdoor.Androm!8.113 (TFE:C:FsvtluOCNW)
IkarusTrojan.MSIL.Inject
GDataWin32.Trojan-Stealer.LokiBot.CSMFHR
WebrootW32.Trojan.Gen
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Backdoor.9cf

How to remove Trojan:MSIL/AgentTesla.MOC!MTB?

Trojan:MSIL/AgentTesla.MOC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment