Trojan eM Client MSIL/AgentTesla.RDSK!MTB

Hi,
while using eM Client this message from Windows Defender appeared.

Trojan: MSIL/AgentTesla.RDSK!MTB
File: C:\Program Files (x86)\eM Client\MailClient.dll
file: C:\Program Files (x86)\eM Client\MailClient.Filters.dll
file: C:\Program Files (x86)\M Client\MailClient.Protocols.Imap.dll
file: C:\Program Files (x86)\eM Client\MailClient.Protocols.CloudStorage.dll
file: C:\Program Files (x86)\eM Client\MailClient.Protocols.OnlineMeeting.dll
file: C:\Program Files (x86)\eM Client\MailClient.Security.dll
file: C:\Program Files (x86)\eM Client\MailClient.Settings.Client.dll
file: C:\Program Files (x86)\M Client\MailClient.Storage.Attachment.dll
file: C:\Program Files (x86)\eM Client\MailClient.Storage.Mail.dll

What’s going on? What should I do?

It is either a false positive, which you will need to report to Microsoft, or you have a virus that has infected your device.

You can uninstall eM Client, which will remove those files, run a full scan of your device, then download eM Client from our website and install it again. The install file is 100% virus free.

I did a scan with Defender and now almost all eM Client files are infected!

@Gary
Thanks.
If I uninstall eM Client do I have to save anything? Will I get all my emails back by reinstalling it?

During the uninstall you will be asked if you want to delete the database.

image

If you choose NO, all your accounts and data will still be there after the reinstall.

I reinstalled eM client, but Defender detects the same files as viruses. :frowning:

Then that is probably a false positive as all our files are 100% virus free. You will need to contact Microsoft for assistance.

1 Like

jueves 19 octubre 2023 :: 1855hrs (UTC +0100)

As @Gary says all eMC files are 100% Virus free, however, as you say that almost ALL eMC files are infected there is a possibility that the infection is also in the database.
Personally I would use the FREE Malwarebytes utility.

Under the Personal ->Solutions heading download and run: Free virus scan & removal

Nothing is a guarantee but is worth a shot!

skybat

¡Los mejores desde Sevilla y mantente a salvo!

[email protected]

Hablo español, luego portugués, inglés, francés y alemán
con conocimiento de varios otros idiomas.

1 Like