Threat Database Trojans Trojan.MSIL.Agent.RDA

Trojan.MSIL.Agent.RDA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 304
First Seen: August 12, 2024
Last Seen: March 28, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.RDA on a computer system indicates a potential security threat that requires immediate attention. This detection name suggests a type of malicious software, or malware, that could be hiding on an infected computer. Understanding what this detection means and how to address it is crucial for maintaining the security and integrity of the system.

What Is Trojan.MSIL.Agent.RDA?

Trojan.MSIL.Agent.RDA is identified as a Trojan-type threat. Trojans are a class of malware that deceive users into installing them by disguising themselves as legitimate software. Once installed, they can cause a variety of problems, including data theft, system crashes, and the installation of additional malware. The name "Trojan.MSIL.Agent.RDA" itself does not specify a known malware family but indicates it is a type of Trojan written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of the .NET Common Intermediate Language (CIL).

How Trojan.MSIL.Agent.RDA Operates

Trojan.MSIL.Agent.RDA, like other Trojans, operates by exploiting the trust of the user. It may arrive as an attachment in an email, as a download from a compromised website, or bundled with other software. Once executed, it can perform a range of malicious activities, including but not limited to, stealing sensitive information, downloading additional malware, or providing unauthorized access to the infected system. Its operation is typically stealthy, aiming to remain undetected for as long as possible to maximize its malicious impact.

Symptoms of Infection

Systems infected with Trojan.MSIL.Agent.RDA may exhibit a variety of symptoms, though some infections may not display noticeable signs. Common indicators of a Trojan infection include slow system performance, frequent crashes, unexpected pop-ups, and changes to system settings without user intervention. Additionally, there might be signs of unauthorized access or data theft, such as unfamiliar accounts or transactions. It's also possible for an infected system to become part of a botnet, used for spreading spam or participating in DDoS attacks, without the user's knowledge.

How to Remove Trojan.MSIL.Agent.RDA

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download removal tools while restricting the execution of most user-installed programs.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to increase the chances of detecting and removing the Trojan.
  3. Uninstall suspicious programs that were installed around the time the infection was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your system and perform another full scan to ensure the malware has been completely removed.

Conclusion

The removal of Trojan.MSIL.Agent.RDA requires careful and systematic steps to ensure the malware is completely eradicated from the system. Preventing future infections involves a combination of using reputable anti-virus software, being cautious with email attachments and downloads, and keeping the operating system and all software up to date. By understanding the nature of Trojan threats and taking proactive measures, users can significantly reduce the risk of infection and protect their digital assets.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.RDA
Signature status: No Signature

Known Samples

MD5: cbfbea478bd72c373a3aa5e56d1b82aa
SHA1: deb5aa4bcbb411dd199c75d0197af70eddb32cd5
SHA256: BE197E9FB6FA8A652EC7E7496AAFD02B08983BD433DC2B177E886FB925EB8611
File Size: 200.70 KB, 200704 bytes
MD5: e70be8d6ba9dc3fee607ec5fa4b86a07
SHA1: cdfdeafb5518cac5f434789ddad0f11c0edae681
SHA256: 7C72F05BA73FBCCF470F2E849F3538A342036B3FE6AA66E6E202C3A34DAEC9E9
File Size: 186.88 KB, 186880 bytes
MD5: 62abfe8a7ad3a99ea4d57734689952ef
SHA1: 4be1f30fd67930a52139df6716871a243dc68d55
SHA256: 1FD8BAC5CC2B9AECAFC8B0911842C86F0E5E16D58C82A93D717D2527D730AE54
File Size: 530.43 KB, 530432 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments Photoreceptor
Company Name
  • Microsoft Corporation
  • Volatilization Swellings
File Description
  • Auto File System Format Utility
  • Interruptible marbleised
File Version
  • 10.0.19041.3636 (WinBuild.160101.0800)
  • 1.0.0.0
Internal Name
  • autofmt
  • MSG.exe
Legal Copyright
  • Copyright © 2024
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • AUTOFMT.EXE
  • MSG.exe
Product Name
  • Good resorters
  • Microsoft® Windows® Operating System
Product Version
  • 10.0.19041.3636
  • 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 6
Potentially Malicious Blocks: 2
Whitelisted Blocks: 3
Unknown Blocks: 1

Visual Map

0 0 x x ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.RDA
  • MSIL.Agent.RDB

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ૄ㿜討ǜ RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Thread Create Remote
  • CreateRemoteThread
Process Manipulation Evasion
  • NtUnmapViewOfSection
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent

Related Posts

Trending

Most Viewed

Loading...