Threat Database Trojans Trojan.MSIL.Agent.FDS

Trojan.MSIL.Agent.FDS

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,625
Threat Level: 80 % (High)
Infected Computers: 9
First Seen: November 5, 2024
Last Seen: July 13, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.FDS on your system indicates a potential security threat. This report aims to provide you with general guidance on understanding and removing the detected threat. It's essential to approach this situation with caution and follow the recommended steps to ensure the security of your system and data.

What Is Trojan.MSIL.Agent.FDS?

Trojan.MSIL.Agent.FDS is identified as a Trojan-type threat, which means it is a type of malware that can cause harm to your system by allowing unauthorized access, stealing data, or disrupting system operations. The name itself does not specify a particular malware family, but it indicates the type of threat and its potential impact on your system.

How Trojan.MSIL.Agent.FDS Operates

Trojan-type threats like Trojan.MSIL.Agent.FDS typically operate by exploiting system vulnerabilities or disguising themselves as legitimate programs to gain unauthorized access to your system. Once inside, they can perform a variety of malicious activities, including data theft, system compromise, or the installation of additional malware. Understanding how these threats operate is crucial for taking the necessary steps to protect your system and remove the detected threat.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Agent.FDS infection can vary, but common indicators include unusual system behavior, slow performance, unexpected pop-ups, or changes to your system settings without your consent. If you have noticed any of these symptoms, it's essential to take immediate action to address the potential threat and prevent further damage to your system or data.

How to Remove Trojan.MSIL.Agent.FDS

  1. Boot your system in Safe Mode with Networking to limit the malware's ability to spread or cause further damage. This will also make it easier to remove.
  2. Conduct a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the threat.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time the threat was detected.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that may have been altered by the malware.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the threat have been removed.

Conclusion

Removing Trojan.MSIL.Agent.FDS from your system requires careful attention to detail and a thorough approach to ensure that all components of the malware are eliminated. By following the steps outlined in this report and maintaining vigilance in your online activities, you can help protect your system and data from future threats. Remember, prevention is key, so always be cautious when downloading software, opening email attachments, or clicking on links from unknown sources.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.FDS
Signature status: Self Signed

Known Samples

MD5: 9981c444d5f195628f704b723b9dba78
SHA1: d5245030b98123a7d2e6dfd32387ca57d190003b
SHA256: 51375C45CAFFE716FD583AD39D4FD88C449C83B2528B3976C3382A334CEEA00A
File Size: 130.12 KB, 130120 bytes
MD5: 4c23443e5f870ecc903eb0d1e9edc3b5
SHA1: 6fa95f4f6735fdb9942173bc0908ee54df22b4ff
SHA256: 78344749FEBC7C494A8DF21AB303F4FBB0F0A58842F337996AE9849A656A660F
File Size: 62.02 KB, 62024 bytes
MD5: 495a1e91999bb8fdbd1704e0631d84a0
SHA1: 97fb570b13ccad86c06ef8c328756ccaadac0508
SHA256: 419F3163A090C2B62DDE175FD0D5446793822D2B3255D92B11BA17377AD254A4
File Size: 28.16 KB, 28160 bytes
MD5: 8268e8f5d5672b32fb0e927c06d5e694
SHA1: 3fb8e004dc641fe4180785e74d3448b7f509390b
SHA256: 9DAA3D0E77AED212ADF0253937A416293D6DC162F93E3850FB2021A70B19AF76
File Size: 26.70 KB, 26696 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 6.20.0.0
  • 1.6.1.0
  • 1.0.0.0
Comments Raw Accel Gui
Company Name Raw Accel
File Description
  • AdobePhotoshop
  • DriverEasy
  • hdsentine
  • RawAccel
File Version
  • 6.20.0.0
  • 1.6.1.0
  • 1.0.0.0
Internal Name
  • AdobePhotoshop.exe
  • DriverEasy.exe
  • hdsentine.exe
  • RawAccel-v1.6.1.exe
Legal Copyright
  • AdobePhotoshop
  • Copyright © RawAccel
  • DriverEasy
  • hdsentine
Legal Trademarks
  • AdobePhotoshop
  • DriverEasy
  • hdsentine
Original Filename
  • AdobePhotoshop.exe
  • DriverEasy.exe
  • hdsentine.exe
  • RawAccel-v1.6.1.exe
Product Name
  • AdobePhotoshop
  • DriverEasy
  • hdsentine
  • Raw Accel
Product Version
  • 6.20.0.0
  • 1.6.1.0
  • 1.0.0.0

Digital Signatures

Signer Root Status
Advantium Consulting Inc. SSL.com EV Code Signing Intermediate CA RSA R3 Self Signed

File Traits

  • .NET
  • HighEntropy
  • x64
  • x86

Block Information

Total Blocks: 3
Potentially Malicious Blocks: 3
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.FDS

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134069658443899084.840.defaultappdomain.d5245030b98123a7d2e6dfd32387ca57d190003b_0000130120 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134101591572773511.6664.defaultappdomain.6fa95f4f6735fdb9942173bc0908ee54df22b4ff_0000062024 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134161724779098917.7040.defaultappdomain.97fb570b13ccad86c06ef8c328756ccaadac0508_0000028160 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134224996543182845.4972.defaultappdomain.3fb8e004dc641fe4180785e74d3448b7f509390b_0000026696 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_2gdviwkh.wxq.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_3fbloedb.njw.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_4dzyszqq.5fy.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_h5djbdrn.b3y.ps1 Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\__psscriptpolicytest_hfatyw14.yr1.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_kpjxn252.lnf.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_ssqdruv4.kb5.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_y2ble05r.txx.ps1 Generic Write,Read Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\07298ee8eba9732300ae62bdca6b6898 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\fe17bec2a573bc9ae36869d0274ffa19_6da81f04c5f9ead2cd0268808fce61e1 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\07298ee8eba9732300ae62bdca6b6898 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\fe17bec2a573bc9ae36869d0274ffa19_6da81f04c5f9ead2cd0268808fce61e1 Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\b7ab3308d1ea4477ba1480125a6fbda936490cbb::blob  H��#?=<]�v�#Ee��%}�Q��L�r RSSL.com Root Certification Authority RSA L0J++ +�7   +�7 +++b �fjV.�\�%�؉ ov�~ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeletePortSection
Show More
  • ntdll.dll!NtAlpcDeleteSectionView
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcDisconnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeDirectoryFile
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent

27 additional items are not displayed above.

User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Cert Store Read
  • CertOpenStore

Related Posts

Trending

Most Viewed

Loading...