Spy Trojan

TrojanSpy:MSIL/AgentTesla.PCF!MTB removal guide

Malware Removal

The TrojanSpy:MSIL/AgentTesla.PCF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/AgentTesla.PCF!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine TrojanSpy:MSIL/AgentTesla.PCF!MTB?


File Info:

crc32: BAA64F70
md5: 45f814f560cf45ab1b6207096e13fb58
name: Proforma Invoice.exe
sha1: 6a2dfa8145e3dfd7c7c66734b7aa4cc994a492b8
sha256: 3081a88581628513f3aeeb4a8a1749302968130017accaef9494458553d19091
sha512: badcc7052929ef71ed0e2836354fd41bbb13f39857141ba30fc968e9d861060dd209b1d372bc8f9b619711455b5cd36ffb0e36690afabc5717e4cc9f12eb9b83
ssdeep: 12288:+3/9++rrv3dfF4BWOlQoWO7khcRF7NgaB0lDz+d2R+dRg:+31RrrFfF4BWON7kDZUdK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: 2Ln.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: DoAn1
ProductVersion: 1.0.0.0
FileDescription: DoAn1
OriginalFilename: 2Ln.exe

TrojanSpy:MSIL/AgentTesla.PCF!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34588564
ALYacTrojan.GenericKD.34588564
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056f82f1 )
K7GWTrojan ( 0056f82f1 )
SymantecPacked.Generic.570
APEXMalicious
Paloaltogeneric.ml
AlibabaTrojanPSW:MSIL/GenKryptik.fc638f8c
AegisLabTrojan.MSIL.Stelega.i!c
Ad-AwareTrojan.GenericKD.34588564
SophosTroj/Tesla-DI
ComodoMalware@#27fr5tm679jy0
F-SecureTrojan.TR/Kryptik.vttic
DrWebTrojan.Packed2.42595
InvinceaMal/Generic-R + Troj/Tesla-DI
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftTrojan.GenericKD.34588564 (B)
IkarusWin32.SuspectCrc
AviraTR/Kryptik.vttic
MAXmalware (ai score=82)
ArcabitTrojan.Generic.D20FC794
ViRobotTrojan.Win32.Z.Genkryptik.737280
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stelega.gen
MicrosoftTrojanSpy:MSIL/AgentTesla.PCF!MTB
AhnLab-V3Trojan/Win32.Stealer.R352146
McAfeeFareit-FXO!45F814F560CF
MalwarebytesTrojan.Crypt.MSIL
TrendMicro-HouseCallTROJ_GEN.F0D1C00IP20
TencentMsil.Trojan-qqpass.Qqrob.Pfjs
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_94%
FortinetMSIL/GenKryptik.ESTS!tr
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove TrojanSpy:MSIL/AgentTesla.PCF!MTB?

TrojanSpy:MSIL/AgentTesla.PCF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment