Spy Trojan

TrojanSpy:MSIL/Stelega.AV!MTB malicious file

Malware Removal

The TrojanSpy:MSIL/Stelega.AV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/Stelega.AV!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine TrojanSpy:MSIL/Stelega.AV!MTB?


File Info:

crc32: D18ED994
md5: a6d0bfb43331260ddd40edf9e56c3ea7
name: A6D0BFB43331260DDD40EDF9E56C3EA7.mlw
sha1: 433fb43d945c7d9165f7fdc021ed183758a2e409
sha256: 72c0ad709b6103880afe20c11163d0c27180c8188a492dd424bc613d6bd78c34
sha512: 3c6f0cfc38dad995c35b2e2f41bd5b74e869f18218bc294e854f44f35ced16c42cff1950c43004a5e0f2b78669db40049a602903035b98d4e9cfbf8452f1e2f7
ssdeep: 12288:/fBHnyCWslmy/jT+D9jW1LU7vFLnuBDUZhvrXnOVvJgwdgl1zvQtG3+fVFn5yga:/fBHypyav0OhDkvJgwWl1Ua+H5JaO0a
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019
Assembly Version: 1.0.0.0
InternalName: CLRIReferenceArrayImpl.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: ManageCustomers
ProductVersion: 1.0.0.0
FileDescription: ManageCustomers
OriginalFilename: CLRIReferenceArrayImpl.exe

TrojanSpy:MSIL/Stelega.AV!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.474
MicroWorld-eScanTrojan.GenericKD.35796384
FireEyeTrojan.GenericKD.35796384
ALYacSpyware.AgentTesla
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35796384
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.433312
BitDefenderThetaGen:NN.ZemsilCO.34700.dn0@aqZET@l
CyrenW32/Trojan.XMDW-5070
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/Agensla.6c3840c1
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.35796384
SophosMal/Generic-R + Troj/Kryptik-PJ
ComodoMalware@#1mj1f06di21gg
F-SecureTrojan.TR/AD.Bladabindi.oagqg
McAfee-GW-EditionPWS-FCTY!A6D0BFB43331
EmsisoftTrojan.GenericKD.35796384 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Bladabindi.oagqg
MAXmalware (ai score=85)
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojanSpy:MSIL/Stelega.AV!MTB
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.Generic.D22235A0
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.35796384
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4267296
McAfeePWS-FCTY!A6D0BFB43331
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.AgentTesla
PandaTrj/GdSda.A
ESET-NOD32MSIL/Spy.Agent.AES
TrendMicro-HouseCallTROJ_GEN.F0D1C00LK20
IkarusTrojan.MSIL.Inject
FortinetMSIL/AgentTesla.3EA7!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Generic/Trojan.PSW.374

How to remove TrojanSpy:MSIL/Stelega.AV!MTB?

TrojanSpy:MSIL/Stelega.AV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment