Categories: SpyTrojan

TrojanSpy:MSIL/AgentTesla.AN!MTB removal guide

The TrojanSpy:MSIL/AgentTesla.AN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/AgentTesla.AN!MTB virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients

How to determine TrojanSpy:MSIL/AgentTesla.AN!MTB?


File Info:

crc32: F0C24C99md5: af3ec1b5d7ffa44c070ee0fae1060ceename: upload_filesha1: 7f3b8d47042b4f8be46e90168da9457121c0360bsha256: bf578c98708023b142b79f6928aa9b4260c8df607c30cda4e005e8eb1348daa6sha512: ae2b5e5beb2426f9401df61b4b29074eebfebe5d1ff2cf2e3b499d394ae95cb3ef40ad8424a9c9b9216cbb581cd58dff1ad861fb69074e12a5e376649c18b85bssdeep: 12288:i6A+2WE2K3Ny3NkktwwvNtkjf1inbl1E3HT1zZN9weq:FA+zE20ydSwvNCjqbXE3HVmtype: ACE archive data version 20, from Win/32, version 20 to extract, contains AV-String (unregistered), solid

Version Info:

0: [No Data]

TrojanSpy:MSIL/AgentTesla.AN!MTB also known as:

MicroWorld-eScan Trojan.GenericKD.34248112
FireEye Trojan.GenericKD.34248112
McAfee Fareit.gen.e
Symantec Trojan.Gen.NPE
Avast Win32:MalwareX-gen [Trj]
GData Trojan.GenericKD.34248112
Kaspersky HEUR:Trojan.MSIL.Crypt.gen
BitDefender Trojan.GenericKD.34248112
Tencent Msil.Trojan.Crypt.Lohy
Ad-Aware Trojan.GenericKD.34248112
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.ucbhj
DrWeb Trojan.PWS.Siggen2.52666
TrendMicro TROJ_GEN.R06BC0WGS20
Emsisoft Trojan.GenericKD.34248112 (B)
Ikarus Trojan.MSIL.Inject
Cyren W32/MSIL_Kryptik.BFV.gen!Eldorado
Avira PO_NX-LI-15-0001.exe
Microsoft TrojanSpy:MSIL/AgentTesla.AN!MTB
Arcabit Trojan.Generic.D20A95B0
ZoneAlarm HEUR:Trojan.MSIL.Crypt.gen
ALYac Trojan.GenericKD.34248112
ESET-NOD32 a variant of MSIL/Kryptik.XBZ
Rising Trojan.Kryptik!8.8 (CLOUD)
MAX malware (ai score=86)
Fortinet MSIL/Wacatac.C!tr
AVG Win32:MalwareX-gen [Trj]
Panda Trj/GdSda.A

How to remove TrojanSpy:MSIL/AgentTesla.AN!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

About “Tedy.563972” infection

The Tedy.563972 is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Jaik.225774 (B) (file analysis)

The Jaik.225774 (B) is considered dangerous by lots of security experts. When this infection is…

17 mins ago

Zusy.494313 (file analysis)

The Zusy.494313 is considered dangerous by lots of security experts. When this infection is active,…

39 mins ago

Fragtor.158799 (file analysis)

The Fragtor.158799 is considered dangerous by lots of security experts. When this infection is active,…

42 mins ago

Win32/Adware.Agent.NPP removal tips

The Win32/Adware.Agent.NPP is considered dangerous by lots of security experts. When this infection is active,…

43 mins ago

How to remove “Trojan.Agent.VB.BNU (B)”?

The Trojan.Agent.VB.BNU (B) is considered dangerous by lots of security experts. When this infection is…

53 mins ago