Spy Trojan

About “TrojanSpy:MSIL/AgentTesla.KI!MTB” infection

Malware Removal

The TrojanSpy:MSIL/AgentTesla.KI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/AgentTesla.KI!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:MSIL/AgentTesla.KI!MTB?


File Info:

crc32: B6DC5EEF
md5: d0155f91b9525fac44a1e44ed814c973
name: D0155F91B9525FAC44A1E44ED814C973.mlw
sha1: d0ab300a7c3557c46b9d5bd87bff7c6037bc2a85
sha256: c869a6986133c4eda2abe6a0117c35ad8411b44602ec60fe9ca436019f9e4726
sha512: 4f232b1a884e0e145771b05f1b21718e02e354eccc5df11c6baad08ec3426741498515fc192144de2434f2e972a7c74095bf4fc7c6c97006115856a53228d77f
ssdeep: 12288:y2nTmxXz9NK3BmVFSQEHCmE5ZkcVplGydbI8fdc/QaTJH:6D23ukimqkcVpDmhFH
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017 - 2020
Assembly Version: 1.0.0.0
InternalName: 5ocV.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: CashMe Out
ProductVersion: 1.0.0.0
FileDescription: CashMe Out
OriginalFilename: 5ocV.exe

TrojanSpy:MSIL/AgentTesla.KI!MTB also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.SpyBotNET.25
MicroWorld-eScanTrojan.GenericKD.44543368
FireEyeGeneric.mg.d0155f91b9525fac
ALYacTrojan.GenericKD.44543368
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Taskun.4!c
SangforMalware
K7AntiVirusTrojan ( 005735501 )
BitDefenderTrojan.GenericKD.44543368
K7GWTrojan ( 005735501 )
Cybereasonmalicious.a7c355
TrendMicroTROJ_GEN.R057C0DKK20
BitDefenderThetaGen:NN.ZemsilF.34634.Pm0@aqYoVJe
CyrenW32/MSIL_Kryptik.CES.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Taskun.gen
AlibabaTrojan:MSIL/Kryptik.fb9c8476
ViRobotTrojan.Win32.Z.Kryptik.680960.N
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.44543368
SophosTroj/MSILIn-AHT
ComodoMalware@#2u5753oofnjvi
F-SecureTrojan.TR/Kryptik.cadqh
InvinceaMal/Generic-R + Troj/MSILIn-AHT
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
EmsisoftTrojan.GenericKD.44543368 (B)
IkarusTrojan.MSIL.Inject
WebrootW32.Trojan.Gen
AviraTR/Kryptik.cadqh
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojanSpy:MSIL/AgentTesla.KI!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2A7AD88
ZoneAlarmHEUR:Trojan.MSIL.Taskun.gen
GDataTrojan.GenericKD.44543368
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R355847
McAfeePWS-FCSU!D0155F91B952
MAXmalware (ai score=86)
VBA32CIL.HeapOverride.Heur
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.YRQ
TrendMicro-HouseCallTROJ_GEN.R057C0DKK20
YandexTrojan.Igent.bUPCSM.29
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.YQQ!tr
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Generic/Trojan.477

How to remove TrojanSpy:MSIL/AgentTesla.KI!MTB?

TrojanSpy:MSIL/AgentTesla.KI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment