Spy Trojan

TrojanSpy:MSIL/AgentTesla!bit removal instruction

Malware Removal

The TrojanSpy:MSIL/AgentTesla!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/AgentTesla!bit virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanSpy:MSIL/AgentTesla!bit?


File Info:

crc32: DD7FB530
md5: 420950c1614843f3c0bc07eb6eceb8f1
name: zssasaas.exe
sha1: 65191175015468751ad235784f44942ba585e865
sha256: 9173f2faece11779acf4f2a7e484e7c497ea5173ca88376db256515889cae3ae
sha512: bd676c38e78fa9c5fa7af97577904337b1c9cea033a1515ea6b22e1ed351d03565ab5006a56b5c2e1231e56fa1e91a7eff8d35d2414b41a29128bcc5e9c14588
ssdeep: 12288:/0OqBQg/+0cCSSveMQnsFP6puj/h8rU03DRWzUjmue+Sz0aP4ubnjnGJbHDE1yrV:MOqBQg/+0cCSSveMQnsFP6puj/h8rU0N
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Jan Fiala (2001)
InternalName: PSPad editor
FileVersion: 5.0.0.277
CompanyName: Jan Fiala
LegalTrademarks: Jan Fiala (2001)
Comments: General freeware text editor
ProductName: PSPad editor
ProgramID: com.embarcadero.PSPad
ProductVersion: 5.0
FileDescription: Text editor
OriginalFilename: PSPad.exe
Translation: 0x0405 0x04e2

TrojanSpy:MSIL/AgentTesla!bit also known as:

K7AntiVirusTrojan ( 0053c4a21 )
MicroWorld-eScanTrojan.GenericKD.40765403
CAT-QuickHealTrojan.IGENERIC
McAfeeRDN/Generic.grp
CylanceUnsafe
BitDefenderTrojan.GenericKD.40765403
K7GWTrojan ( 0053c4a21 )
CrowdStrikemalicious_confidence_100% (D)
ArcabitTrojan.Generic.D26E07DB
TrendMicroTROJ_GEN.F0C2C00KI18
NANO-AntivirusTrojan.Win32.Crypt.fkndzs
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.F0C2C00KI18
AvastWin32:Malware-gen
GDataTrojan.GenericKD.40765403
KasperskyHEUR:Trojan.MSIL.Crypt.gen
AlibabaTrojan:Win32/Tiggre.91616be1
RisingTrojan.Crypt!8.2E3 (CLOUD)
Ad-AwareTrojan.GenericKD.40765403
EmsisoftTrojan.GenericKD.40765403 (B)
ComodoTrojWare.MSIL.Androm.PMV@7xhktx
F-SecureHeuristic.HEUR/AGEN.1001615
DrWebTrojan.Inject3.4015
ZillyaTrojan.Crypt.Win32.49359
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.grp
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
CyrenW32/Trojan.FKSH-0990
AviraHEUR/AGEN.1001615
Antiy-AVLTrojan/MSIL.Crypt
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftTrojanSpy:MSIL/AgentTesla!bit
AhnLab-V3Malware/Win32.Generic.C2845641
MalwarebytesTrojan.Crypt.XMP
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.QCU
TencentMsil.Trojan.Crypt.Oyon
SentinelOnestatic engine – malicious
FortinetMSIL/Injector.UDK!tr
AVGWin32:Malware-gen
Cybereasonmalicious.161484
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.21a

How to remove TrojanSpy:MSIL/AgentTesla!bit?

TrojanSpy:MSIL/AgentTesla!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment