Threat Database Stealers HEUR.Stealer.MSIL.Generic

HEUR.Stealer.MSIL.Generic

By CagedTech in Stealers

Threat Scorecard

Popularity Rank: 5,643
Threat Level: 100 % (High)
Infected Computers: 4,717
First Seen: July 23, 2019
Last Seen: June 29, 2026
OS(es) Affected: Windows

The detection of HEUR.Stealer.MSIL.Generic indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to steal sensitive information from infected computers, and it's essential to take immediate action to remove it and prevent further damage.

What Is HEUR.Stealer.MSIL.Generic?

HEUR.Stealer.MSIL.Generic is a type of Trojan-type threat that is designed to steal sensitive information, such as login credentials, credit card numbers, and other personal data. The "HEUR" prefix suggests that this threat has been detected using heuristic analysis, which means that it has been identified based on its behavior and characteristics rather than a specific signature or pattern. The "Stealer" part of the name indicates that this threat is designed to steal sensitive information, while "MSIL" refers to the Microsoft Intermediate Language, which is a programming language used to create.NET applications.

How HEUR.Stealer.MSIL.Generic Operates

HEUR.Stealer.MSIL.Generic operates by infiltrating a computer system and establishing a connection with a remote server. Once connected, it can transmit sensitive information back to the server, where it can be used for malicious purposes. This type of threat can also install additional malware, create backdoors, and modify system settings to maintain its presence on the infected computer. The exact mechanisms used by HEUR.Stealer.MSIL.Generic can vary, but its primary goal is to steal sensitive information and compromise the security of the infected system.

Symptoms of Infection

Symptoms of HEUR.Stealer.MSIL.Generic infection can vary, but common indicators include unusual system behavior, slow performance, and unexpected pop-ups or alerts. You may also notice that your browser settings have been changed, or that new programs have been installed without your consent. In some cases, you may not notice any symptoms at all, which is why it's essential to use reputable antivirus software and keep your system up to date.

  • Unusual system crashes or freezes
  • Slow system performance
  • Unexpected pop-ups or alerts
  • Changed browser settings
  • New programs installed without consent

How to Remove HEUR.Stealer.MSIL.Generic

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable antivirus tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs that may have been installed by the malware, and be cautious when installing new software to avoid re-infecting your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your antivirus tool to ensure that the malware has been completely removed.

Conclusion

Removing HEUR.Stealer.MSIL.Generic from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above and using reputable antivirus software, you can help to ensure that your system is clean and secure. Remember to always be cautious when installing new software, and keep your system up to date to prevent future infections. If you're unsure about any aspect of the removal process, consider seeking the help of a professional to ensure that your system is properly cleaned and secured.

Analysis Report

General information

Family Name: HEUR.Stealer.MSIL.Generic
Signature status: No Signature

Known Samples

MD5: c369b9fcf82024ded30b7c12790872f6
SHA1: abd6ee2a3099e40256aba489c5a6a39c73d39898
SHA256: BF428802168CE48610A91F9ADF3F08D02F5FE51CE370C4F2762FDA5D34C60A83
File Size: 64.51 KB, 64512 bytes
MD5: 9b230780e7022de6bad5d27be8f129a6
SHA1: 8313ca35384052fd7c44304ea2339e82007cfe50
SHA256: 68E747133CA8304FB25F3FABCFD90F726375ADD6572C5FE571F515F7D2D357F6
File Size: 65.02 KB, 65024 bytes
MD5: 2f23da75bfbe05ba899b49e427eda626
SHA1: 6026acce9c47f6bbbde5d23132a2aa1a7138182b
SHA256: F0A18CB5E44288B63114936EB290AE43CB4840B6D54D86637CFD514B02F833EC
File Size: 6.86 MB, 6863872 bytes
MD5: 4064ec81289b5dbf82772f8b81e9eda6
SHA1: d9e9d8008ed47e377c8c8209029b9f94b9db9e06
SHA256: 66592877E123559DA6C15BFA1EC5645C99166870FA06EC67977D8183BCB2B082
File Size: 64.51 KB, 64512 bytes
MD5: 4087128f065e3429a964e4ccc1183c58
SHA1: 191d370ff84e7eaf503a0c3233853f65e7959e7f
SHA256: 8107CD1EA0E83865F0D14A8346DEE054D10F5361700627201226D1C662A14338
File Size: 64.51 KB, 64512 bytes
Show More
MD5: 65fa854c76580ba892a61ed4cd877e3e
SHA1: d84cd77e889cfa99fda33a5953647b684a652772
SHA256: F8F6352A5C726A00DEEDE0FE925C28F36A8F2696F18379F68B3254D697E22889
File Size: 64.51 KB, 64512 bytes
MD5: f9630d275763760c167e2b411cd1cdd2
SHA1: 93aff6ec0fccbcbb0e0308b1ccb2b4975dc9b9f0
SHA256: 66B2170A8D4FDCA83EAB9C79599CAB63256E3BCD6CDFD76986093EA20B746FCE
File Size: 976.38 KB, 976384 bytes
MD5: 095b430e6231ca0992f938c8a77a8a13
SHA1: 5c619efa0e16e13e67211b40a22fd1891145c37e
SHA256: 11A5801E4ADDD72B2D007BA3F4A8CC77D53C0426F3A74D6BEBCBD34A3B76A2BA
File Size: 47.62 KB, 47616 bytes
MD5: 0f6653acc361c7e08adc4752d5cb10a0
SHA1: 3214e3d9eef5bb789edc1673e5a9b94cf5c0000a
SHA256: AB44FA23EE0ABB174DD0370BC4C6713A19884012E6CAA1F2F0B07713C4C487C2
File Size: 64.51 KB, 64512 bytes
MD5: d3fe8c9f36a7ce0f7fbdb31fe4866c70
SHA1: 73fe00e9bf4d6265bf78ab16c4bc8c916519e435
SHA256: 02B53AC14271A1E3CBD2C64E3CBF8935B08DCFC1CFEA25BF01162A4F2D92AAFD
File Size: 1.87 MB, 1868288 bytes
MD5: d285698235dea8ae7e088919feedef11
SHA1: c584ab38bbe377c84ac5d817b0820c6c84c629ca
SHA256: C413D08829F1DA9E20E13C2E9BE797CF8447F1041F52C48F12124AD615EA3E8E
File Size: 273.92 KB, 273920 bytes
MD5: 338c3004347f455a0414c31a760fddf3
SHA1: 5738f8649686d7e842b27c414e7407e1739fcebf
SHA256: 405E6CB319FCA3D7BA8BC58901E1726041EB4CA4B534EDE246FFE64792B85AB3
File Size: 1.62 MB, 1624576 bytes
MD5: dc37cc1f7f48c2c19292f132186e3269
SHA1: 65c91f94eacbaf5af85e05b4c13bc7e14bc411d1
SHA256: 1833D47A38F01631A3360C6E76BB3E5BD6B14AC25BBC2E2E8AFBB6C5C8852C77
File Size: 3.27 MB, 3266048 bytes
MD5: 0da569183f9abca369f1c1c08ee42295
SHA1: b1fb07141071222c02437f76aa559bf0634ee97a
SHA256: 2E6C49B58EA424622D0F669AC0A76C3485CC4EBD41B3F38DD5D4101623ACFA5E
File Size: 187.90 KB, 187904 bytes
MD5: d0064d8d5ba9e57d080d706fc9cb9246
SHA1: df98ef6bdfbaa87ccb23a13e02050b3aba8ce7d7
SHA256: 5B20CB36ABBACC69EE5D0C7008F1AD081DB2767625659B4BB8EBA6ECC511BD2A
File Size: 1.95 MB, 1950208 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 4.18.23110.3
  • 2.4.5.0
  • 1.6.6.0
  • 1.6.0.0
  • 1.4.1.0
  • 1.2.0.0
  • 1.0.9.0
  • 1.0.8.0
  • 1.0.0.0
  • 0.0.0.0
Comments
  • KeePass 2.x plugin which imports credentials from various browsers.
  • Microsoft
Company Name
  • Janis Estelmann
  • Microsoft
  • Microsoft Corporation
File Description
  • KeePassBrowserImporter
  • Microsoft
  • Microsoft Malware Protection DLP Command Line Utility
  • Quasar Client
  • Systems
  • WinSc32
File Version
  • 4.18.23.0
  • 2.4.5
  • 1.6.6
  • 1.6.0
  • 1.4.1
  • 1.2.0.0
  • 1.0.9.0
  • 1.0.8.0
  • 1.0.0.0
  • 0.0.0.0
Internal Name
  • ARCANE.exe
  • assemblychange.exe
  • Client.exe
  • KeePassBrowserImporter.dll
  • MpDlpCmd.exe
  • VioletH.exe
Legal Copyright
  • Copyright © 2025
  • Copyright © MaxXor 2023
  • Copyright © Microsoft
  • © Microsoft Corporation. All rights reserved.
Legal Trademarks Microsoft
Original Filename
  • ARCANE.exe
  • assemblychange.exe
  • Client.exe
  • KeePassBrowserImporter.dll
  • MpDlpCmd.exe
  • VioletH.exe
Product Name
  • KeePass Plugin
  • Microsoft
  • Microsoft® Windows® Operating System
  • Quasar
  • Systems
  • WinSc32
Product Version
  • 4.18.23110.3
  • 2.4.5
  • 1.6.6
  • 1.6.0
  • 1.4.1
  • 1.2.0.0
  • 1.0.9.0
  • 1.0.8.0
  • 1.0.0.0
  • 0.0.0.0

File Traits

  • .NET
  • 2+ executable sections
  • Agile.net
  • CreateThread
  • CryptUnprotectData
  • dll
  • Fody
  • HighEntropy
  • NewLateBinding
  • No CryptProtectData
Show More
  • ntdll
  • RijndaelManaged
  • Run
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 861
Potentially Malicious Blocks: 303
Whitelisted Blocks: 252
Unknown Blocks: 306

Visual Map

x x ? x x x ? ? 0 ? 0 ? 0 0 ? ? ? ? ? ? 0 ? x x 0 0 ? ? x ? x x 0 0 0 x 0 x 0 x ? ? x x x ? ? ? 0 ? ? ? x ? ? ? ? ? ? ? 0 ? ? ? ? ? x x x 0 x 0 0 0 0 0 ? ? 0 0 0 x ? x ? x ? x x x ? ? ? ? ? ? ? ? ? ? ? ? x 0 x x x x 0 x x x 0 x x ? 0 x ? 0 ? 0 x x ? x x x ? ? 0 x ? x 0 ? ? x 0 x x x x x x x x x x x x x x 0 0 x x x x x x x 0 0 0 0 0 ? x x x x x ? x x 0 x x x x x x x x x x ? ? ? ? x 0 x ? ? ? x x x 0 x ? 0 0 0 0 0 0 0 x 0 0 0 0 ? ? x ? ? ? ? x ? ? ? 0 0 0 0 0 0 x ? ? ? ? 0 0 x ? ? ? ? 0 ? 0 x ? ? ? ? 0 ? ? 0 0 x x x 0 0 x x ? 0 ? ? x x x x ? x x x x ? x x x 0 x 0 x 0 0 0 x ? ? ? ? ? ? ? 0 ? 0 x ? ? 0 x x x x ? ? ? 0 ? 0 x ? 0 0 0 x 0 0 x x 0 0 ? 0 0 0 0 x ? 0 0 0 0 ? ? 0 x ? ? ? x x x x x x x x x x 0 ? ? ? ? ? 0 ? 0 0 x ? x x x ? x ? ? ? 0 ? x x x ? ? ? 0 ? ? 0 0 ? 0 0 x ? 0 x 0 0 x 0 0 0 x x ? ? ? ? ? 0 ? 0 ? 0 0 0 0 x 0 x x 0 0 x 0 x x x x 0 x 0 0 ? x x 0 x ? ? x ? x ? ? 0 x x 0 x x x x 0 0 ? 0 0 x 0 x ? ? ? x 0 0 x 0 0 ? ? x x ? 0 ? 0 0 0 0 x x x x x x x x x x x x 0 0 0 0 x x x x x ? x x 0 x x x x x x x x 0 x x ? x x 0 x x x ? x 0 x x x x x x x x x x 0 x x ? x 0 0 0 x 0 x 0 ? ? ? x ? ? ? 0 ? ? ? ? x x x ? ? x ? ? x ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 0 0 ? 0 x ? x ? ? ? ? 0 ? x x 0 x 0 ? ? 0 ? ? 0 0 x ? ? ? ? ? ? ? ? x 0 0 ? 0 ? 0 ? ? ? ? ? 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 ? ? ? 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 ? 0 x ? ? x 0 x 0 x x 0 x x x 0 0 x x x x x 0 x x 0 0 0 x 0 0 0 0 x 0 0 x x x ? ? ? ? ? ? ? ? ? ? 0 x x x x ? ? x x x ? ? ? ? x x x x x ? x ? ? x 0 ? x x x x x ? x x x ? ? x x x ? 0 ? ? x x x x 0 0 x x 0 0 ? x x 0 x x 0 x x x x x ? ? ? ? x ? x x x x 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Mardom.SF
  • MSIL.Quasar.B
  • MSIL.Quasar.CA
  • MSIL.Quasar.CB
  • MSIL.Spy.RC
Show More
  • MSIL.Spy.RCB

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\uwdcgzxjadvj.bat Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tXjg�8 �� �v �Z ��T��������%���5��3bBx�<#�#��$kF&� &�-(�(X�(�)E)�`*J*9*�"+�[-!R1`1�1HO1�D5,]9ߔ=�@V�A��G�IH[uH�pI��K��N$N�R20Z^�_�z`�2b"hc�wc�zg�Xh�r RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data �4 ��|�dh�\��lkh�m� Q]#6 ������ ��'L-T;������̩� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection

58 additional items are not displayed above.

User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Network Winsock2
  • WSAGetOverlappedResult
  • WSASocket
  • WSAStartup
Network Winsock
  • bind
  • closesocket
  • setsockopt
Other Suspicious
  • AdjustTokenPrivileges
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 728

Related Posts

Trending

Most Viewed

Loading...