Spy Trojan

TrojanSpy:MSIL/AgentTesla.PR!MTB removal guide

Malware Removal

The TrojanSpy:MSIL/AgentTesla.PR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/AgentTesla.PR!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:MSIL/AgentTesla.PR!MTB?


File Info:

crc32: 6C0DFE18
md5: b2474f4fff2fe8de9b91642837364f75
name: B2474F4FFF2FE8DE9B91642837364F75.mlw
sha1: 4c502f32d0d29750b4a821944af6861722428b0d
sha256: 0e950de0479f62a50178a15909a1ee421345b0ad6cfda87ef9bb453afad71b54
sha512: 6180fde282e396c9011630cd060272df19cc3b532b8f55389da83dda0df41f1e473c1097844709a8fe1d7f4caa6c4d990dc2555907556b67c8cf96d26fe3a5c4
ssdeep: 6144:UE6FllRdBHMlU8LF1NNYAo41nYbRPVn7RSArAS7xipVLkrhOFg1b0unXh18qkd:J6Jt8LF7NDl1nSP5R37sOIghnzxO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2011 - 2020
Assembly Version: 4.0.2.0
InternalName: x695e.exe
FileVersion: 4.0.2.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Space Invaders
ProductVersion: 4.0.2.0
FileDescription: Space Invaders
OriginalFilename: x695e.exe

TrojanSpy:MSIL/AgentTesla.PR!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71331
CAT-QuickHealBackdoor.MSIL
ALYacTrojan.GenericKDZ.71331
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00572c2d1 )
BitDefenderTrojan.GenericKDZ.71331
K7GWTrojan ( 00572c2d1 )
Cybereasonmalicious.2d0d29
CyrenW32/MSIL_Kryptik.CDG.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Taskun-9791093-0
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaTrojan:Win32/starter.ali1000139
AegisLabTrojan.MSIL.Androm.m!c
TencentWin32.Backdoor.Netwire.Auto
Ad-AwareTrojan.GenericKDZ.71331
EmsisoftTrojan.GenericKDZ.71331 (B)
F-SecureTrojan.TR/Kryptik.qfqug
DrWebTrojan.Inject4.4796
TrendMicroBackdoor.MSIL.REMCOS.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.b2474f4fff2fe8de
SophosMal/Generic-R + Troj/Steal-AVI
IkarusTrojan.MSIL.Inject
AviraTR/Kryptik.qfqug
eGambitUnsafe.AI_Score_97%
MAXmalware (ai score=82)
MicrosoftTrojanSpy:MSIL/AgentTesla.PR!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D116A3
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataTrojan.GenericKDZ.71331
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MSIL.R355405
McAfeePWS-FCSU!B2474F4FFF2F
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.YPD
TrendMicro-HouseCallBackdoor.MSIL.REMCOS.SM
RisingTrojan.Kryptik!8.8 (TFE:C:l3iBU8i7XFS)
YandexTrojan.Igent.bUM5NI.37
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.EWCI!tr
BitDefenderThetaGen:NN.ZemsilF.34634.ym0@ayXF7mf
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/Backdoor.9cf

How to remove TrojanSpy:MSIL/AgentTesla.PR!MTB?

TrojanSpy:MSIL/AgentTesla.PR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment