Trojan

What is “Trojan:MSIL/AgentTesla.PK!MTB”?

Malware Removal

The Trojan:MSIL/AgentTesla.PK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.PK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/AgentTesla.PK!MTB?


File Info:

crc32: 6A1A2F3C
md5: 3ade5b9b508051cc39c1c610f4af5a12
name: 3ADE5B9B508051CC39C1C610F4AF5A12.mlw
sha1: 662056878a2b1fb1e99d1f74bb0e8694904fdccd
sha256: 207dff33f6f91f114deae60a6cb3a404a5f40bc607fb6015f680c8980af7ac16
sha512: a99f9f23663bc09fca19a96968a15014679e8bbe2bb4a6f64897a34b86faf72848af138b4dbdcda1ef19d4e2488e81dc447c50af5e05f2c67cf7521b070c3d0f
ssdeep: 12288:1WHCM2K4CUtghbx16Fw1m8hS9k6nea987mt:f3CUtKT5tQ9hmE
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019
Assembly Version: 1.0.0.0
InternalName: Reco.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Disciples
ProductVersion: 1.0.0.0
FileDescription: Disciples
OriginalFilename: Reco.exe

Trojan:MSIL/AgentTesla.PK!MTB also known as:

K7AntiVirusTrojan ( 0052eef11 )
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.SpyBotNET.25
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37585529
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0052eef11 )
Cybereasonmalicious.78a2b1
CyrenW32/MSIL_Kryptik.FNP.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Formbook.AA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Pwsx-9893039-0
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.37585529
MicroWorld-eScanTrojan.GenericKD.37585529
Ad-AwareTrojan.GenericKD.37585529
SophosMal/Generic-S + Troj/MSIL-RRC
BitDefenderThetaGen:NN.ZemsilF.34142.Im0@aeOqCbh
TrendMicroTROJ_FRS.0NA103IG21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.3ade5b9b508051cc
EmsisoftTrojan.GenericKD.37585529 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.PK!MTB
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataWin32.Trojan-Stealer.FormBook.VG3HB8
AhnLab-V3Trojan/Win.PWSX-gen.C4633164
McAfeeRDN/Generic.dx
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.PNG.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00IF21
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ZXG!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:MSIL/AgentTesla.PK!MTB?

Trojan:MSIL/AgentTesla.PK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment