Spy Trojan

TrojanSpy:MSIL/AgentTesla.PRB!MTB information

Malware Removal

The TrojanSpy:MSIL/AgentTesla.PRB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/AgentTesla.PRB!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine TrojanSpy:MSIL/AgentTesla.PRB!MTB?


File Info:

crc32: D1B4EBAF
md5: 9cfef1a0ae6a72adf9e284b4114f7e8e
name: tasksmgr.exe
sha1: c42cab6c2602223c9da4b65f23d6081b349d76a7
sha256: b2ce61b582e2d83e2bbad6dfea5c5696b14d36f9b6fd97b0c6c92a5ad2904ce4
sha512: 500587515dd92bedd0e280c17f39c5fa781fee133bf05c95b0e910451207a426973c3fd5d63194a11395f73fb8a61d2e6e2739fb0c31581e8dd37be11fbcf6b4
ssdeep: 6144:/2E/BHsge/ksZooONtEckO8Ipz0cHdr/2ui4gl/QIjKSKM+:3JHTWsEckLI5KueJQs
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: uQStqNL
Assembly Version: 1.0.0.0
InternalName: uQStqNL.exe
FileVersion: 1.0.0.0
LegalTrademarks: EGAGaxw
Comments: EGAGaxw
ProductName: uQStqNL
ProductVersion: 1.0.0.0
FileDescription: EGAGaxw
OriginalFilename: uQStqNL.exe

TrojanSpy:MSIL/AgentTesla.PRB!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.33911911
FireEyeGeneric.mg.9cfef1a0ae6a72ad
McAfeeGenericRXKT-HI!9CFEF1A0AE6A
SangforMalware
BitDefenderTrojan.GenericKD.33911911
CrowdStrikewin/malicious_confidence_90% (W)
Invinceaheuristic
CyrenW32/MSIL_Troj.VE.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataMSIL.Backdoor.Nancat.OA7X2R
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
AegisLabTrojan.Win32.Malicious.4!c
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Nanocore.bpkxw
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
MaxSecureTrojan.Malware.121218.susgen
EmsisoftTrojan.GenericKD.33911911 (B)
IkarusTrojan.Inject
F-ProtW32/MSIL_Troj.VE.gen!Eldorado
AviraTR/AD.Nanocore.bpkxw
ZoneAlarmHEUR:Backdoor.MSIL.NanoBot.gen
MicrosoftTrojanSpy:MSIL/AgentTesla.PRB!MTB
BitDefenderThetaGen:NN.ZemsilF.34122.tm0@aelSSdo
ALYacTrojan.GenericKD.33911911
MAXmalware (ai score=81)
ESET-NOD32a variant of MSIL/Kryptik.WBN
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.WBN!tr
Ad-AwareTrojan.GenericKD.33911911
AVGFileRepMetagen [Malware]
Cybereasonmalicious.c26022
Paloaltogeneric.ml

How to remove TrojanSpy:MSIL/AgentTesla.PRB!MTB?

TrojanSpy:MSIL/AgentTesla.PRB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment