Threat Database Trojans Trojan.MSIL.Downloader.FD

Trojan.MSIL.Downloader.FD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,382
Threat Level: 80 % (High)
Infected Computers: 796
First Seen: November 25, 2021
Last Seen: June 22, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.FD indicates that your system has been compromised by a potentially malicious threat. This type of threat is designed to download and install additional malware onto your system, which can lead to a range of problems, including data theft, system crashes, and unauthorized access to your computer. It is essential to take immediate action to remove this threat and prevent further damage.

What Is Trojan.MSIL.Downloader.FD?

Trojan.MSIL.Downloader.FD is a type of Trojan horse malware that is designed to download and install additional malware onto your system. The name "Trojan.MSIL.Downloader.FD" suggests that it is a downloader Trojan, which means its primary function is to download and execute other malicious programs. This type of malware can be particularly dangerous, as it can lead to a range of problems, including data theft, system crashes, and unauthorized access to your computer.

How Trojan.MSIL.Downloader.FD Operates

Trojan.MSIL.Downloader.FD operates by exploiting vulnerabilities in your system or tricking you into downloading and installing it. Once installed, it can connect to a remote server to download and execute additional malware. This can include a range of malicious programs, such as keyloggers, ransomware, and spyware. The malware can also modify system settings, create new user accounts, and disable security software to avoid detection.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Downloader.FD infection can vary, but common signs include slow system performance, unexpected pop-ups and ads, and unfamiliar programs or icons on your desktop. You may also notice that your system is crashing or freezing frequently, or that your antivirus software is disabled. In some cases, you may not notice any symptoms at all, which is why it's essential to run regular virus scans and keep your security software up to date.

How to Remove Trojan.MSIL.Downloader.FD

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed recently.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Downloader.FD requires immediate attention to prevent further damage to your system. By following the steps outlined above, you can help to ensure that your system is safe and secure. It's also essential to take steps to prevent future infections, such as keeping your operating system and security software up to date, avoiding suspicious downloads and email attachments, and using strong passwords and enabling two-factor authentication. By being proactive and taking the necessary precautions, you can help to protect your system and your personal data from malicious threats like Trojan.MSIL.Downloader.FD.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.FD
Signature status: No Signature

Known Samples

MD5: f4adfd7fd8aecaabe06eed52260654d0
SHA1: 16852daf1c2a4cfdaadf4a8249f543b879bc70a2
SHA256: 8E0F5D724813D8B9853DA96DA3CBD681EAA6D2A7F489F9C779389C556D45C997
File Size: 584.19 KB, 584192 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.1.0.0
Comments Greeter
Company Name M_D
File Description Greeter
File Version 1.1.0.0
Internal Name Greeter.exe
Legal Copyright Copyright © 2014
Legal Trademarks VietPAL
Original Filename Greeter.exe
Product Name Greeter
Product Version 1.1.0.0

File Traits

  • .NET
  • CryptoObfus
  • HighEntropy
  • NewLateBinding
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 516
Potentially Malicious Blocks: 69
Whitelisted Blocks: 255
Unknown Blocks: 192

Visual Map

? 0 ? x ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? x ? x x x ? 0 0 0 0 0 ? ? 0 0 0 0 x 0 0 0 ? 0 ? x ? 0 ? ? 0 ? 0 ? ? ? ? ? 0 ? 0 0 x 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 x 0 0 ? 0 0 ? 0 0 0 0 x 0 0 0 x 0 x 0 x 0 x 0 0 0 x 0 x 0 x 0 x 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 x ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 x 0 x ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 x 0 x 0 0 0 x 0 x 0 0 ? 0 ? 0 x 0 x 0 0 x 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 ? 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 0 ? ? x ? 0 x 0 0 0 x 0 0 0 ? ? ? ? 0 ? ? ? 0 0 0 x 0 x 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 x 0 x 0 0 x 0 x 0 x 0 0 x 0 x 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 x 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 x 0 0 ? ? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81z��B�8 �6 �v y� z �Z xy �� �a ۀT�B������1�����5����ee +Bx�<����5�R � �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�-&�x'�(�(X�)�`*J*9*�^+�[ RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱槛峟ʏ耀氅歿浟켜ʚ꺇뺶켜ʚ꺇뺶켜ʚ꺇뺶켜ʚ릵犱洎ʫ赲荓涜픋˹耀뫹躧픋˹➇ⵌ㭔꘷˿耀뱝鴡揷↑̀ā耀惟탌 RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 848

Related Posts

Trending

Most Viewed

Loading...