Threat Database Spyware HEUR.Spyware.MSIL.Generic

HEUR.Spyware.MSIL.Generic

By CagedTech in Spyware

Threat Scorecard

Popularity Rank: 12,101
Threat Level: 100 % (High)
Infected Computers: 721
First Seen: July 23, 2019
Last Seen: June 13, 2026
OS(es) Affected: Windows

The detection of HEUR.Spyware.MSIL.Generic indicates that your system has been compromised by a type of spyware. This type of malware is designed to gather sensitive information from your computer without your knowledge or consent. It's essential to take immediate action to remove the threat and prevent further damage.

What Is HEUR.Spyware.MSIL.Generic?

HEUR.Spyware.MSIL.Generic is a generic detection name for a type of spyware that is written in MSIL (Microsoft Intermediate Language). This means that the malware is designed to run on the .NET framework, which is a part of the Windows operating system. The "HEUR" prefix indicates that the detection is heuristic, meaning that it's based on the behavior of the malware rather than a specific signature.

How HEUR.Spyware.MSIL.Generic Operates

Once installed on your system, HEUR.Spyware.MSIL.Generic can operate in various ways to gather sensitive information. It may monitor your browsing habits, collect login credentials, or even capture keystrokes. The malware may also communicate with its command and control server to transmit the collected data or receive further instructions. In some cases, the malware may also install additional components or update itself to evade detection.

Symptoms of Infection

If your system is infected with HEUR.Spyware.MSIL.Generic, you may notice some suspicious activity. Your browser may be redirected to unwanted websites, or you may see pop-up ads or fake alerts. Your system may also become slower or more unstable, and you may notice unusual network activity. However, in many cases, the malware may operate silently, making it difficult to detect without the help of antivirus software.

  • Unexplained changes to your browser settings or homepage
  • Pop-up ads or fake alerts
  • Slow system performance or crashes
  • Unusual network activity or data usage

How to Remove HEUR.Spyware.MSIL.Generic

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing HEUR.Spyware.MSIL.Generic requires a combination of technical expertise and caution. By following the steps outlined above, you can help to ensure that your system is free from the malware and prevent further damage. It's also essential to take preventive measures, such as keeping your antivirus software up to date, avoiding suspicious downloads, and being cautious when clicking on links or opening email attachments. By staying vigilant and taking the necessary precautions, you can help to protect your system and sensitive information from spyware and other types of malware.

Analysis Report

General information

Family Name: HEUR.Spyware.MSIL.Generic
Signature status: No Signature

Known Samples

MD5: 5e49d1cb042257863f3ac5ce305bd5de
SHA1: 15277cd3de5cb739a2d2dc4ce8b62aa35261adea
SHA256: B03878A4F02E83F53E65D11E6E5BC80C4AC30F4633775CBCE4FA61DB52CA2B38
File Size: 2.57 MB, 2568192 bytes
MD5: adf640c1f0f68f437be569689225fc0b
SHA1: d9daacd5589b7c822383ee86e89d5cc18cd1a5e0
SHA256: F22522D8EF08EC32BE689ED8A23ED0C7EC27EB6F21F758444F40120BBDE45A36
File Size: 9.90 MB, 9900032 bytes
MD5: e42c87e4e16c3b0619a13234b99e9e44
SHA1: 655a0fae9b2cd51e31725cf966f89bea8c1c91d8
SHA256: 952AC15D63C149FE69BF8244BAA71FEA739CCB58A22E2CBA83B01D6DBF688BAB
File Size: 24.06 KB, 24064 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 4.2.0.0
  • 1.0.0.112
Comments ELS.NET - Datenbank-Programm (V4.2 R7)
Company Name
  • DOM Sicherheitstechnik
  • Isoil
File Description
  • els4
  • Mcp
File Version
  • 4.2.0.7
  • 1.0.0.112
Internal Name
  • els4.exe
  • Mcp.exe
Legal Copyright
  • Copyright © 2022
  • Copyright © DOM Sicherheitstechnik 2010
Original Filename
  • els4.exe
  • Mcp.exe
Product Name
  • DOM ELS ELS42
  • Mcp
Product Version
  • 4.2.0.7
  • 1.0.0.112

File Traits

  • .NET
  • NewLateBinding
  • No Version Info
  • ntdll
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 28
Potentially Malicious Blocks: 25
Whitelisted Blocks: 3
Unknown Blocks: 0

Visual Map

x x x x x x 0 0 x x x x x x x x x x x x x x x 0 x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Bladabindi.A
  • MSIL.FakeMS.OA

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\server.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\279d9875560cf85d9f3bc76b45479fdf.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\279d9875560cf85d9f3bc76b45479fdf.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\downloads\els4.err Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �mC �vT�������Bx#��&� &�-(�(X�)�`*J*91�1HO@V�G�IH[uN�_�zb"hh�rk`k�ql(�lR q�Xr�BtǤvy�w�ny�9{b�~D�P������7�M�������6������.����� [�m�Ù��'N�]��#��c�IV�gi����$�8 RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱峕馐ʊ耀Ś 隞̃錁耀꧌Öž RegNtPreCreateKey
HKCU::di ! RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��  xy* �/��Y�d�kP~� ��ރ�p*��^�o�eebVs}EkP~E��1D��7 ���ﺃePe���"D��1W��fe��g� RegNtPreCreateKey
HKCU\environment::see_mask_nozonechecks 1 RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ޑ좁ǜ RegNtPreCreateKey
Show More
HKCU\local settings\muicache\1b\52c64b7e::@c:\windows\system32\firewallcontrolpanel.dll,-12122 Windows Defender Firewall RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::279d9875560cf85d9f3bc76b45479fdf "C:\Users\Qxklobni\AppData\Local\Temp\server.exe" .. RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcImpersonateClientOfPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
Show More
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePort
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
Service Control
  • OpenSCManager
  • OpenService
Process Terminate
  • TerminateProcess
Keyboard Access
  • GetAsyncKeyState
  • GetKeyState
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock
  • closesocket
  • inet_addr
  • setsockopt

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 792
(NULL) C:\Users\Qxklobni\AppData\Local\Temp\server.exe
netsh firewall add allowedprogram "C:\Users\Qxklobni\AppData\Local\Temp\server.exe" "server.exe" ENABLE

Related Posts

Trending

Most Viewed

Loading...