Trojan

Trojan:MSIL/AgentTesla.OXY!MTB information

Malware Removal

The Trojan:MSIL/AgentTesla.OXY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.OXY!MTB virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine Trojan:MSIL/AgentTesla.OXY!MTB?


File Info:

crc32: C7ACC09D
md5: 1a4b3c9d4ac133e364c2f9609b8b1184
name: 1A4B3C9D4AC133E364C2F9609B8B1184.mlw
sha1: debca648d781186b608c751ccde45bcfd0ccda09
sha256: 7331f95a07beb3d748679ad215cb4ec731cafacee756c2a79795b8b91d3ecd17
sha512: 06236a5123909e2ff854bf1c4c0b28acbae774c82ca83777eb5d1bba9afe18a7dfefba059807611f2657ee94015ceb29440f6b24e01b68a56a55f93d1f96a933
ssdeep: 24576:mp+k28mcqWWrWWe4rEVJNawmNuWGLyZVdg/BxhZ5X3t:mp+k3mCWr6VNaKkZn+/hX
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright (c) 2020 Discord Inc. All rights reserved.
Assembly Version: 0.0.3.14
InternalName: DiscordSetup.exe
FileVersion: 0.0.3.14
CompanyName: Discord Inc.
Comments: Discord - https://discord.com/
ProductName: Discord - https://discord.com/
ProductVersion: 0.0.3.14
FileDescription: DiscordSetup
OriginalFilename: DiscordSetup.exe

Trojan:MSIL/AgentTesla.OXY!MTB also known as:

K7AntiVirusTrojan ( 005788ee1 )
DrWebTrojan.PackedNET.568
CynetMalicious (score: 100)
CAT-QuickHealTrojanpws.Msil
ALYacGen:Variant.Bulz.391392
MalwarebytesSpyware.DiscordStealer
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 005788ee1 )
CyrenW32/Trojan.FMYN-1241
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ZUR
ZonerTrojan.Win32.106130
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderGen:Variant.Bulz.391392
ViRobotTrojan.Win32.Z.Kryptik.2871296.A
MicroWorld-eScanGen:Variant.Bulz.391392
TencentMsil.Trojan-qqpass.Qqrob.Dygx
Ad-AwareGen:Variant.Bulz.391392
SophosMal/Generic-S
ComodoMalware@#hhn66v3xfgud
BitDefenderThetaGen:NN.ZemsilF.34628.Vo0@ay!i2ek
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R049C0DCG21
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.1a4b3c9d4ac133e3
EmsisoftGen:Variant.Bulz.391392 (B)
WebrootW32.Malware.Gen
AviraTR/Kryptik.fqjvo
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.OXY!MTB
ArcabitTrojan.Bulz.D5F8E0
GDataGen:Variant.Bulz.391392
AhnLab-V3Trojan/Win.Kryptik.C4371490
McAfeeGenericRXNY-DF!1A4B3C9D4AC1
MAXmalware (ai score=81)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R049C0DCG21
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Kryptik!vkdl1qLnFJg
FortinetMSIL/Kryptik.ZTU!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.AgentTesla.HwMA3oMA

How to remove Trojan:MSIL/AgentTesla.OXY!MTB?

Trojan:MSIL/AgentTesla.OXY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment