Threat Database Trojans Trojan.MSIL.FakeHack.Q

Trojan.MSIL.FakeHack.Q

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 11
First Seen: March 2, 2022
Last Seen: March 11, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.FakeHack.Q indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to deceive users into believing their system has been hacked, when in fact, it is the malware itself that is causing the issue. It's essential to understand the nature of this threat and take immediate action to remove it from your system to prevent further damage.

What Is Trojan.MSIL.FakeHack.Q?

Trojan.MSIL.FakeHack.Q is a type of Trojan horse malware that disguises itself as a legitimate program or system file. The name "Trojan" refers to the method of infection, where the malware hides inside a seemingly harmless program or file, allowing it to bypass security measures and gain access to the system. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a platform-independent intermediate representation of the .NET Framework. The "FakeHack" part indicates that the malware is designed to fake a hacking attempt, making it difficult for users to distinguish between a real and fake threat.

How Trojan.MSIL.FakeHack.Q Operates

Once Trojan.MSIL.FakeHack.Q infects a system, it can perform a variety of malicious activities, such as stealing sensitive information, installing additional malware, or disrupting system performance. The malware may also attempt to convince the user that their system has been hacked, displaying fake alerts or messages to create a sense of urgency. This can lead to further compromise, as the user may inadvertently provide sensitive information or install additional malware in an attempt to "fix" the issue.

Symptoms of Infection

Systems infected with Trojan.MSIL.FakeHack.Q may exhibit a range of symptoms, including slow system performance, unexpected pop-ups or alerts, and unusual network activity. Users may also notice that their system is behaving erratically, with programs crashing or failing to respond. In some cases, the malware may attempt to disable security software or prevent the user from accessing certain system features.

  • Unexplained changes to system settings or configuration
  • Appearance of fake alerts or messages
  • Slow system performance or crashes
  • Unusual network activity or connectivity issues

How to Remove Trojan.MSIL.FakeHack.Q

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.FakeHack.Q from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove the malware and prevent further damage to your system. It's essential to remain vigilant and take proactive measures to protect your system from future threats, including keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or links.

Analysis Report

General information

Family Name: Trojan.MSIL.FakeHack.Q
Signature status: No Signature

Known Samples

MD5: 74883bda643e66fd5e07f5d883dac6da
SHA1: 289a358746626fbde90a246eb068068916a16b50
SHA256: 498C158CF45B7BFCD72310B230B199A7B63A0BA07918D27361397082D27F777F
File Size: 27.65 KB, 27648 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description FakeLogonScreen
File Version 1.0.0.0
Internal Name FakeLogonScreen.exe
Legal Copyright Copyright © 2020
Original Filename FakeLogonScreen.exe
Product Name FakeLogonScreen
Product Version 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 16
Potentially Malicious Blocks: 7
Whitelisted Blocks: 9
Unknown Blocks: 0

Visual Map

0 x x 0 x x 0 0 x x x 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.FakeHack.Q

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 704

Related Posts

Trending

Most Viewed

Loading...