Trojan

Trojan:MSIL/AgentTesla.MSX!MTB information

Malware Removal

The Trojan:MSIL/AgentTesla.MSX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.MSX!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/AgentTesla.MSX!MTB?


File Info:

crc32: CFBE299F
md5: d49afad32bdc8fe0fe14a6501422665d
name: D49AFAD32BDC8FE0FE14A6501422665D.mlw
sha1: 58a51a4e95e1acb6085d8ba43330f4904305bea4
sha256: 5ac5eee21d5a32eb57d80ff83da21265c7d11c525f6b57ed124a266ce04fee54
sha512: 66c378635c3e1819a55aed6ec7c4c619d7616cdb62aabd159f44904691375b7c5a0b09a685d343758e1d6321740f282e61f595a7879fbef77377727a0c11a5e1
ssdeep: 24576:cmLSVQYyaJjFN3YjwMExoe8ecQ79bA5oqJx:cmL6yaBX3VME6aBBq
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021-2022
Assembly Version: 140.0.0.1
InternalName: DirectoryString.exe
FileVersion: 140.0.0.01
CompanyName: THE LUXURY FLEET Co., Ltd.
LegalTrademarks: Akasaka
Comments: Tokyo Metropolitan Central Library
ProductName: Tokyo Metropolitan Central Library
ProductVersion: 140.0.0.01
FileDescription: Tokyo Metropolitan Central Library
OriginalFilename: DirectoryString.exe

Trojan:MSIL/AgentTesla.MSX!MTB also known as:

Elasticmalicious (high confidence)
ClamAVWin.Packed.Generickdz-9831052-0
CAT-QuickHealTrojan.Agenttesla
McAfeePWS-FCUF!D49AFAD32BDC
MalwarebytesTrojan.MalPack
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Taskun.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005776011 )
BitDefenderTrojan.GenericKD.36352047
K7GWTrojan ( 005776011 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D229D88B
CyrenW32/Trojan.ZFGU-7426
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 90)
KasperskyHEUR:Trojan.MSIL.Taskun.gen
AlibabaTrojan:Win32/starter.ali1000139
MicroWorld-eScanTrojan.GenericKD.36296843
TencentMsil.Trojan.Taskun.Wrgk
Ad-AwareTrojan.GenericKD.36296843
SophosMal/Generic-R + Troj/Kryptik-RX
F-SecureTrojan.TR/AD.AgentTesla.zfjfg
DrWebTrojan.PackedNET.526
TrendMicroTrojanSpy.MSIL.TESLA.THBODBA
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeTrojan.GenericKD.36296843
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.udee
WebrootW32.Trojan.Gen
AviraTR/AD.AgentTesla.zfjfg
MAXmalware (ai score=88)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:MSIL/AgentTesla.MSX!MTB
ZoneAlarmHEUR:Trojan.MSIL.Taskun.gen
GDataMSIL.Trojan-Stealer.AgentTesla.7QCCRR
AhnLab-V3Malware/Win32.RL_Generic.C4329310
ALYacTrojan.GenericKD.36296843
VBA32TScope.Trojan.MSIL
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.ZNV
TrendMicro-HouseCallTrojanSpy.MSIL.TESLA.THBODBA
RisingTrojan.AgentTesla!8.104D5 (CLOUD)
IkarusTrojan.MSIL.Crypt
eGambitUnsafe.AI_Score_84%
FortinetMSIL/GenKryptik.FBCB!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.32bdc8
AvastWin32:Trojan-gen
Qihoo-360Win32/TrojanSpy.AgentTesla.HgIASOoA

How to remove Trojan:MSIL/AgentTesla.MSX!MTB?

Trojan:MSIL/AgentTesla.MSX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment