Threat Database Trojans Trojan.MSIL.FakeMS.E

Trojan.MSIL.FakeMS.E

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,364
Threat Level: 80 % (High)
Infected Computers: 136
First Seen: October 26, 2021
Last Seen: July 19, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.FakeMS.E on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to deceive and manipulate users, making it essential to understand its characteristics and take prompt action to remove it. In this report, we will provide an overview of Trojan.MSIL.FakeMS.E, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.MSIL.FakeMS.E?

Trojan.MSIL.FakeMS.E is a type of Trojan horse malware that can infect your system without your knowledge or consent. The name Trojan.MSIL.FakeMS.E suggests that it is a malicious program designed to mimic legitimate software, making it difficult to detect. Trojans are known for their ability to disguise themselves as harmless programs, allowing them to bypass security measures and gain unauthorized access to your system.

How Trojan.MSIL.FakeMS.E Operates

Once Trojan.MSIL.FakeMS.E infects your system, it can operate in various ways, including stealing sensitive information, installing additional malware, or providing unauthorized access to your system. It may also attempt to deceive you into installing fake software updates or security patches, which can further compromise your system's security. The primary goal of Trojan.MSIL.FakeMS.E is to remain undetected while causing harm to your system and exploiting your personal data.

Symptoms of Infection

Identifying the symptoms of Trojan.MSIL.FakeMS.E infection can be challenging, as it is designed to operate stealthily. However, you may notice unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also receive fake alerts or notifications, attempting to trick you into installing additional malware or revealing sensitive information. If you suspect that your system is infected with Trojan.MSIL.FakeMS.E, it is essential to take immediate action to remove it.

How to Remove Trojan.MSIL.FakeMS.E

  1. Boot your system in Safe Mode with Networking to prevent Trojan.MSIL.FakeMS.E from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Trojan.MSIL.FakeMS.E.
  3. Uninstall any suspicious programs or software that may be related to the Trojan.MSIL.FakeMS.E infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that Trojan.MSIL.FakeMS.E has been completely removed.

Conclusion

Removing Trojan.MSIL.FakeMS.E from your system requires careful attention to detail and a thorough understanding of its operating methods. By following the steps outlined in this report, you can effectively remove the malware and prevent future infections. It is essential to remain vigilant and take proactive measures to protect your system and personal data from malicious threats like Trojan.MSIL.FakeMS.E. Remember to always use reputable anti-malware tools, keep your software up-to-date, and be cautious when installing new programs or clicking on unfamiliar links.

Analysis Report

General information

Family Name: Trojan.MSIL.FakeMS.E
Signature status: No Signature

Known Samples

MD5: 886a98062e9eb1f248b7529c4d04e43a
SHA1: 56367e6775da7447ea5434c3e37507a4b23f816c
SHA256: 6766ACCCA65CD5106457A70BEAE67D82A1BE2786499D4B46A3C1FEC1D9996F93
File Size: 51.20 KB, 51200 bytes
MD5: ce165c1af5e76e46b1ee10ed3f681980
SHA1: 00ea8189fda64a7ea5b0709ef6d66cb4ddc59ce6
SHA256: 4D92CD1C7647F45AAA0D0871F18298EDC2325A5E8BE1A7D01E4949752C7E864D
File Size: 106.50 KB, 106496 bytes
MD5: b9b30ed77137e1543bc612c95874c258
SHA1: ecb3d7b1a2d368257887300549162df5a77823d5
SHA256: FA1EA04FA577489427FEC919419D086E95208A9965EECAA8590AE1CC76F37CA8
File Size: 110.59 KB, 110592 bytes
MD5: a2b3a55f7f4d933423694d205205336b
SHA1: 6473638df45995098ef50deb181785859d899a8c
SHA256: F415F35BF0C745879896A8B0152E4E70222CF191E44E273570C410A65A582321
File Size: 25.09 KB, 25088 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • DSE_dialog.exe
  • Setup.exe
  • teste.exe
  • x.exe
Original Filename
  • DSE_dialog.exe
  • Setup.exe
  • teste.exe
  • x.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • Installer Version
  • x86

Block Information

Total Blocks: 35
Potentially Malicious Blocks: 14
Whitelisted Blocks: 21
Unknown Blocks: 0

Visual Map

0 0 0 0 x 0 0 0 0 0 x x x x x 0 x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.FakeMS.E
  • MSIL.FakeMS.EA
  • MSIL.FakeMS.GR

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.133991004159764480.6740.defaultappdomain.56367e6775da7447ea5434c3e37507a4b23f816c_0000051200 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134147759162776737.5948.defaultappdomain.ecb3d7b1a2d368257887300549162df5a77823d5_0000110592 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134160870304590853.6896.defaultappdomain.6473638df45995098ef50deb181785859d899a8c_0000025088 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_b5ent00l.fxf.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_kyyivwcf.nna.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_lst2gs05.pxk.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_qs44i4ax.hp2.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_trd1goo2.z3t.psm1 Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\__psscriptpolicytest_w2hys01e.fwc.ps1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows\currentversion\policies\system::consentpromptbehavioradmin RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ��B��� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId

8 additional items are not displayed above.

User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges

Related Posts

Trending

Most Viewed

Loading...