Threat Database Trojans Trojan.MSIL.FakeMS.RC

Trojan.MSIL.FakeMS.RC

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: July 29, 2025
Last Seen: September 2, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.FakeMS.RC on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to deceive users and compromise the security of their computers. It is essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.

What Is Trojan.MSIL.FakeMS.RC?

Trojan.MSIL.FakeMS.RC is a type of Trojan horse malware that can infect a computer without the user's knowledge or consent. The name suggests that it may be related to fake or malicious Microsoft (MS) components, but the exact nature and purpose of this malware can vary. Trojans are known for their ability to disguise themselves as legitimate software, making them difficult to detect and remove. They can be used for a variety of malicious purposes, including data theft, unauthorized access, and the distribution of additional malware.

How Trojan.MSIL.FakeMS.RC Operates

Once installed, Trojan.MSIL.FakeMS.RC can operate in the background, potentially allowing unauthorized access to the infected computer. It may communicate with its creators or other malicious entities to receive instructions or transmit stolen data. The malware could also be used to download and install additional malicious software, further compromising the security of the system. Understanding how this malware operates is crucial for developing an effective removal strategy.

Symptoms of Infection

Identifying the symptoms of a Trojan.MSIL.FakeMS.RC infection can be challenging, as it is designed to remain stealthy. However, common signs of malware infection include unexpected changes in system performance, such as slow operation, frequent crashes, or the appearance of unwanted programs or toolbars. Users may also notice unusual network activity or find that their personal data has been compromised. Being vigilant and monitoring system behavior can help in early detection.

How to Remove Trojan.MSIL.FakeMS.RC

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove all components of the Trojan.MSIL.FakeMS.RC malware.
  3. Uninstall any suspicious programs or applications that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings that the malware may have altered.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that all malware components have been removed.

Conclusion

Removing Trojan.MSIL.FakeMS.RC requires careful attention to detail and a systematic approach to ensure that all components of the malware are eliminated. By understanding the nature of this threat and following the steps outlined for removal, users can protect their computers and personal data from further compromise. It is also essential to maintain good security practices, including keeping software up to date, using strong antivirus protection, and being cautious when downloading and installing software from the internet. Preventing reinfection is key to maintaining a secure computing environment.

Analysis Report

General information

Family Name: Trojan.MSIL.FakeMS.RC
Signature status: No Signature

Known Samples

MD5: b2c1e516caffe56c4dfb48c98be18ca3
SHA1: 55aa71d0c158abf2e168051b1fd400aaec8c87de
SHA256: 545D1B4CF052B36A2DB1532520BD48F6D31D9804381147BB70717E654B9322FB
File Size: 29.18 KB, 29184 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name FabFilter-Plugins-Reset-Trial.exe
Original Filename FabFilter-Plugins-Reset-Trial.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 49
Potentially Malicious Blocks: 0
Whitelisted Blocks: 49
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.FakeMS.QN
  • MSIL.FakeMS.QR
  • MSIL.FakeMS.QS
  • MSIL.FakeMS.RC
  • MSIL.FakeMS.RD
Show More
  • MSIL.FakeMS.SB

Files Modified

File Attributes
\device\namedpipe\pshost.134024104825645951.2768.defaultappdomain.55aa71d0c158abf2e168051b1fd400aaec8c87de_0000029184 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\__psscriptpolicytest_oqvihay0.51l.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_u2qizvw5.yl3.ps1 Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile

2 additional items are not displayed above.

User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges

Related Posts

Trending

Most Viewed

Loading...