Spy Trojan

TrojanSpy:MSIL/Masslogger.AR!MTB removal tips

Malware Removal

The TrojanSpy:MSIL/Masslogger.AR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/Masslogger.AR!MTB virus can do?

  • Network activity detected but not expressed in API logs

How to determine TrojanSpy:MSIL/Masslogger.AR!MTB?


File Info:

crc32: 24794FA7
md5: 53e9b701faed25d5c975e199b0251721
name: upload_file
sha1: a7d6878c26bb48a9ff9409815a17ae36b9aea378
sha256: ab96445acdd91759fbadb7a87dc1efcf56317a2fcec3b5ecb03b887b86796288
sha512: ac6889b57815575c1cf8d89a2848ae41a08db844e0adcde51b3e5483e258c9220a6a3fd8ef965a7a045f89461c700cc0b934f91092374f37d24dd65776d4a507
ssdeep: 12288:n2amdleestD8HOJrTGBuMq1V5p4wJ8hkdTq8IsKVvJ9xF8cQAFAICS+8lvIHXX:2aj78H2GBuJVJZ6/9xP5A7S+8lvIH
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: December 2005 (C)
Assembly Version: 4.7.0.0
InternalName: bGFDOrFiAs.exe
FileVersion: 4.7.0.0
CompanyName: Dana Gas
LegalTrademarks: Dana Gas
Comments: The greatest
ProductName: In the end
ProductVersion: 4.7.0.0
FileDescription: In the end
OriginalFilename: bGFDOrFiAs.exe

TrojanSpy:MSIL/Masslogger.AR!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34289535
FireEyeGeneric.mg.53e9b701faed25d5
CAT-QuickHealTrojanpws.Msil
McAfeeFareit-FXY!53E9B701FAED
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.m7QV
SangforMalware
K7AntiVirusTrojan ( 0056bf251 )
BitDefenderTrojan.GenericKD.34289535
K7GWTrojan ( 0056bf251 )
Cybereasonmalicious.c26bb4
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34152.en0@a87VlZo
F-ProtW32/MSIL_Kryptik.BHP.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanSpy:MSIL/Masslogger.304dfdec
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.34289535
SophosMal/Generic-S
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/AD.AgentTesla.ofgvo
TrendMicroTROJ_GEN.R049C0WH520
FortinetMSIL/Kryptik.XCR!tr
EmsisoftTrojan.GenericKD.34289535 (B)
SentinelOneDFI – Malicious PE
CyrenW32/MSIL_Kryptik.BHP.gen!Eldorado
AviraTR/AD.AgentTesla.ofgvo
MAXmalware (ai score=80)
ArcabitTrojan.Generic.D20B377F
ViRobotTrojan.Win32.S.Agent.1127936.C
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
MicrosoftTrojanSpy:MSIL/Masslogger.AR!MTB
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Kryptik.C4176249
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.34289535
MalwarebytesTrojan.MalPack.PNG.Generic
ESET-NOD32a variant of MSIL/Kryptik.XFO
TrendMicro-HouseCallTROJ_GEN.R049C0WH520
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusBackdoor.MSIL.Bladabindi
GDataTrojan.GenericKD.34289535
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Generic/Trojan.PSW.374

How to remove TrojanSpy:MSIL/Masslogger.AR!MTB?

TrojanSpy:MSIL/Masslogger.AR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment