Trojan

Trojan:MSIL/AgentTesla.PAS!MTB information

Malware Removal

The Trojan:MSIL/AgentTesla.PAS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.PAS!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/AgentTesla.PAS!MTB?


File Info:

crc32: 02E68485
md5: 7ca3c2ad1da3bd5514be7054b2af0a78
name: 7CA3C2AD1DA3BD5514BE7054B2AF0A78.mlw
sha1: bc96a6c3f9f442f2d52a8ec7e48a7d010b6d767b
sha256: 5bad96dda4ae65a4b81d53e3ddd51eaa0181e07c5dea64b1d1bfb561b900dc53
sha512: c4b71df1e2e40c6f9a5489f7b2f5f9935053b524d99a24f0c3869d0a9013a2441ac3b6c6f8f991b8df89fadba9890f946a4e7b5e3fbbd6f476d7fb9f8b2658c6
ssdeep: 12288:PeSLRfmUi2iNml1gYzY/IfefmPOLdjyRMDK+qBOvx:JLBmUi1ktzIc8BRDK+5x
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: Partition.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: ArenaDeBatalha.GameLogic
ProductVersion: 1.0.0.0
FileDescription: ArenaDeBatalha.GameLogic
OriginalFilename: Partition.exe

Trojan:MSIL/AgentTesla.PAS!MTB also known as:

K7AntiVirusTrojan ( 005894191 )
LionicTrojan.MSIL.Bladabindi.m!c
Elasticmalicious (high confidence)
DrWebTrojan.Hosts.48903
CynetMalicious (score: 100)
ALYacTrojan.Agent.FOMF
CylanceUnsafe
SangforBackdoor.MSIL.Bladabindi.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/AgentTesla.222802fe
K7GWTrojan ( 005894191 )
CyrenW32/MSIL_Kryptik.FXO.gen!Eldorado
ESET-NOD32a variant of MSIL/Kryptik.ADJN
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderTrojan.Agent.FOMF
MicroWorld-eScanTrojan.Agent.FOMF
Ad-AwareTrojan.Agent.FOMF
SophosMal/Generic-S
ComodoMalware@#1ocvv7jmmd97o
BitDefenderThetaGen:NN.ZemsilF.34266.Hm0@amrYyVp
VIPREWin32.Malware!Drop
TrendMicroTROJ_GEN.R03FC0DJO21
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.7ca3c2ad1da3bd55
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.GenSteal.ubzhu
Antiy-AVLTrojan/Generic.ASMalwS.34C0075
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.PAS!MTB
ArcabitTrojan.Agent.FOMF
GDataTrojan.Agent.FOMF
AhnLab-V3Trojan/Win.Agent.C4714783
McAfeeRDN/AgentTesla
MAXmalware (ai score=83)
VBA32CIL.HeapOverride.Heur
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03FC0DJO21
YandexTrojan.AvsArher.bUPOkE
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.73686729.susgen
FortinetMSIL/GenKryptik.FMJE!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:MSIL/AgentTesla.PAS!MTB?

Trojan:MSIL/AgentTesla.PAS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment