Trojan

Trojan:MSIL/AgentTesla.STA removal guide

Malware Removal

The Trojan:MSIL/AgentTesla.STA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.STA virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/AgentTesla.STA?


File Info:

crc32: ABB57EB2
md5: 34d50da5169cf75afd21f10027ba80e1
name: 34D50DA5169CF75AFD21F10027BA80E1.mlw
sha1: cb56a89c513f8e5f0c1c2f4deff1c601ce30f269
sha256: bae19f194f0d4d760e6dd07ce9e806d052d7dfcaa11c7dd15523b6967e2c9d22
sha512: e2222730fe4a1c1b393e32d133e25fd8908f8fbb1a23d9a8813cebbba88188914157f5ad05d9294aabc1d86f9667497891b98bb86143fa9d1c0e0c8458e831da
ssdeep: 1536:pcdIy9h9BzOdB1oyiWEt7OgGb4pQ3+HbPyFXdU8a3OKx/SE6G6alefwJ:pcWshHWky3zx+HTyRdYFpeo
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Knarring.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Knarring.exe

Trojan:MSIL/AgentTesla.STA also known as:

K7AntiVirusSpyware ( 0057cb401 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.30497
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.513953
SangforTrojan.Win32.Save.a
K7GWSpyware ( 0057cb401 )
CyrenW32/MSIL_Agent.BJO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.DFY
APEXMalicious
AvastWin32:DangerousSig [Trj]
ClamAVWin.Packed.Bulz-9867398-0
KasperskyHEUR:Trojan-PSW.MSIL.Reline.gen
BitDefenderGen:Variant.Bulz.513953
MicroWorld-eScanGen:Variant.Bulz.513953
Ad-AwareGen:Variant.Bulz.513953
BitDefenderThetaGen:NN.ZemsilF.34758.gm1@aqnbreg
McAfee-GW-EditionGenericRXOY-GA!34D50DA5169C
FireEyeGen:Variant.Bulz.513953
EmsisoftMalCert.A (A)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1142322
MicrosoftTrojan:MSIL/AgentTesla.STA
ArcabitTrojan.Bulz.D7D7A1
GDataGen:Variant.Bulz.513953
McAfeeGenericRXOY-GA!34D50DA5169C
MAXmalware (ai score=85)
MalwarebytesTrojan.Crypt
RisingStealer.Agent!1.D483 (CLASSIC)
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:DangerousSig [Trj]

How to remove Trojan:MSIL/AgentTesla.STA?

Trojan:MSIL/AgentTesla.STA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment