Trojan

How to remove “Trojan:MSIL/AgentTesla.PAB!MTB”?

Malware Removal

The Trojan:MSIL/AgentTesla.PAB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.PAB!MTB virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan:MSIL/AgentTesla.PAB!MTB?


File Info:

crc32: ABB9CC3F
md5: b36447c6987dda4dce4ed3c821acf9bd
name: B36447C6987DDA4DCE4ED3C821ACF9BD.mlw
sha1: 89331d26ffaf33e207460d890542132e7b941897
sha256: 19ce4f024d418759d4a5f9240e2f636ff66ce6f63964b3685013bde36487615c
sha512: 86e6332cb7a1909ea9c22cf8687aef0ec94a704cda9e3b4df7543d13721c0084a37b5d7c52463b71d2c3e6685314ee3348e20e521482870fe38efae54b7b6ede
ssdeep: 24576:qNHVXfpBhEStCFJpw1ATK2RMwwAyymblSSR0o6y2jXg:y/p4K2yw5glSSR0o6y20
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2021 Open Whisper Systems
FileVersion: 1.39.6
CompanyName: Open Whisper Systems
ProductName: Signal
ProductVersion: 1.39.6
FileDescription: Private messaging from your desktop
Translation: 0x0409 0x04e4

Trojan:MSIL/AgentTesla.PAB!MTB also known as:

K7AntiVirusTrojan ( 00579ec11 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.624
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Sdum
ALYacSpyware.Infostealer.RedLine
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3010977
SangforTrojan.Win32.AgentTesla.ml
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:MSIL/Kryptik.fc74cb9b
K7GWTrojan ( 00579ec11 )
Cybereasonmalicious.6ffaf3
CyrenW32/MSIL_Kryptik.DCT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AAFO
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Sdum.gen
BitDefenderTrojan.GenericKD.46004659
MicroWorld-eScanTrojan.GenericKD.46004659
Ad-AwareTrojan.GenericKD.46004659
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-FCVG!B36447C6987D
FireEyeGeneric.mg.b36447c6987dda4d
EmsisoftTrojan.GenericKD.46004659 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Kryptik.kwhvr
eGambitPE.Heur.InvalidSig
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.PAB!MTB
GDataTrojan.GenericKD.46004659
AhnLab-V3Malware/Win.Generic.C4398976
McAfeePWS-FCVG!B36447C6987D
MalwarebytesSpyware.RedLineStealer
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R023H0CD321
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Agent!qV79hDVq9RI
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.73691310.susgen
FortinetMSIL/Kryptik.AAFO!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Noon.HgIASR0A

How to remove Trojan:MSIL/AgentTesla.PAB!MTB?

Trojan:MSIL/AgentTesla.PAB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment