Threat Database HEUR Malware HEUR.Malware.FakeMedia.Generic

HEUR.Malware.FakeMedia.Generic

By CagedTech in HEUR Malware, Malware

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 1,703
First Seen: December 31, 2012
Last Seen: March 10, 2026
OS(es) Affected: Windows

The detection of HEUR.Malware.FakeMedia.Generic indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to deceive users into installing or executing malicious code, often by disguising itself as a legitimate media-related application or file. It is essential to take immediate action to remove this threat and prevent further damage to your system.

What Is HEUR.Malware.FakeMedia.Generic?

HEUR.Malware.FakeMedia.Generic is a type of Trojan malware that can infect a system through various means, such as exploited vulnerabilities, phishing attacks, or drive-by downloads. The "HEUR" prefix suggests that this threat has been detected using heuristic analysis, which means that the malware's behavior and characteristics have been identified as potentially malicious, even if it is not a known or previously detected threat.

How HEUR.Malware.FakeMedia.Generic Operates

Once installed, HEUR.Malware.FakeMedia.Generic can operate in various ways, depending on its intended purpose. It may attempt to steal sensitive information, such as login credentials or financial data, or use the infected system as a botnet to conduct further malicious activities. The malware may also try to evade detection by using anti-detection techniques, such as code obfuscation or encryption.

Symptoms of Infection

Systems infected with HEUR.Malware.FakeMedia.Generic may exhibit various symptoms, including slow system performance, unexpected pop-ups or advertisements, and unusual network activity. Users may also notice that their system is behaving erratically or that their personal data is being accessed or stolen. However, some infections may not exhibit any noticeable symptoms, making it essential to regularly scan your system for malware.

How to Remove HEUR.Malware.FakeMedia.Generic

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing HEUR.Malware.FakeMedia.Generic requires a combination of technical expertise and caution. By following the steps outlined above, you can help to ensure that your system is free from this malicious threat. However, prevention is always the best course of action, and users should take steps to protect their systems from infection, such as keeping their operating system and software up to date, using strong antivirus software, and being cautious when clicking on links or downloading attachments from unknown sources.

Analysis Report

General information

Family Name: HEUR.Malware.FakeMedia.Generic
Signature status: No Signature

Known Samples

MD5: 23230bd73dd8cf256495df571bcee580
SHA1: b70ad6b66b4e39faa5226e04ddbfd53952e66769
SHA256: 2F31457C4F275ECB16F1086BCC954B226A34E9762DB48BF68440F6004CA29B41
File Size: 184.83 KB, 184832 bytes
MD5: 222bc520c0a66e54d5b639c32d7b3b2e
SHA1: 7b606e0681ffdfb726d2366b9421c99715594c9d
SHA256: 3A40E1ADC62E96180F95572EAE89BA735BE507EA61983CCF2DAF307DA5F6A58D
File Size: 307.20 KB, 307200 bytes
MD5: 05acb8fea3ce1646a8d4d0fac81e7881
SHA1: 76193bc61eceed825b21448de994dc36ffd80c16
SHA256: 9183B378072EA0DAE92223B2F9BEF97B40AF4532F76A75DB3DDF65740DDADC86
File Size: 202.24 KB, 202240 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 8.0.0.0
Company Name
  • MediaDrug
  • Music Media Helper
File Description
  • MediaDrug Online Installer
  • Music Media Helper
File Version
  • 8.0.0.0
  • 1, 0, 0, 0
Internal Name
  • MediaDrugInstaller
  • Music Media Helper.dll
Legal Copyright Copyright 2013
Original Filename
  • MediaDrugInstaller.exe
  • Music Media Helper.dll
Product Name
  • MediaDrug Installer
  • Music Media Helper
Product Version
  • 1.0.0+ed7fee04ef35e645a7f7e0dcbab7902fa94d04a5
  • 1, 0, 0, 0

File Traits

  • HighEntropy
  • Installer Version
  • packed
  • x64
  • x86

Block Information

Total Blocks: 424
Potentially Malicious Blocks: 1
Whitelisted Blocks: 419
Unknown Blocks: 4

Visual Map

0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\downloads\log-2025-12-27-17-06-52.txt Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\mdi::uid a18edd08-0453-46de-a092-a8dd9fdb9acb-7c68480c6c0dcfef24bdbc9dc634ee3dae0f8c8c RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �k�8��jg�8 �v �Z xy ��T��������5����Bx!wz#�#��$kF%:�&� (�(X�)E)�`*J+�[,��-!R/9�/��1`1�1HO1�D5�09ߔ<.:>3�@V�G�IH[uH�pI��J��K��N$N�R20U_*V �X�.X�_�z`b.`�2b"hc�z RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateTimer2
Show More
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpSendRequest

Related Posts

Trending

Most Viewed

Loading...