Threat Database HEUR Malware HEUR.Malware.Fody.Generic

HEUR.Malware.Fody.Generic

By CagedTech in HEUR Malware, Malware

Threat Scorecard

Popularity Rank: 5,549
Threat Level: 100 % (High)
Infected Computers: 929
First Seen: May 15, 2024
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of HEUR.Malware.Fody.Generic indicates that your system has been compromised by a potentially malicious program. This type of threat is categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. The "HEUR" prefix suggests that the malware was detected using heuristic analysis, which means that the antivirus software identified suspicious behavior rather than matching a known signature. It's essential to take immediate action to remove the malware and prevent further damage to your system.

What Is HEUR.Malware.Fody.Generic?

HEUR.Malware.Fody.Generic is a type of malware that can infect your system through various means, such as exploited vulnerabilities, phishing emails, or drive-by downloads. The "Fody" part of the name may indicate a specific characteristic or behavior of the malware, but without further information, it's difficult to determine its exact nature. What's important is that this malware has been detected, and you should take steps to remove it as soon as possible.

How HEUR.Malware.Fody.Generic Operates

Malware like HEUR.Malware.Fody.Generic can operate in various ways, depending on its intended purpose. Some common behaviors include data theft, unauthorized access to system resources, or the installation of additional malware. The malware may also attempt to communicate with its command and control servers to receive updates or transmit stolen data. It's crucial to remove the malware to prevent further damage and protect your personal data.

Symptoms of Infection

Systems infected with HEUR.Malware.Fody.Generic may exhibit various symptoms, including slow performance, unexpected crashes, or unusual network activity. You may also notice suspicious programs or processes running in the background, or unfamiliar icons on your desktop. In some cases, the malware may not exhibit any noticeable symptoms, making it difficult to detect without the help of antivirus software.

  • Unexplained changes to system settings or configuration
  • Appearance of suspicious pop-ups or advertisements
  • Unusual network activity or connectivity issues
  • System crashes or freezes

How to Remove HEUR.Malware.Fody.Generic

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing HEUR.Malware.Fody.Generic requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above, you can help protect your system and prevent further damage. It's essential to remain vigilant and to regularly scan your system for malware to prevent future infections. Remember to always use reputable antivirus software and to keep your operating system and applications up to date to reduce the risk of infection.

Analysis Report

General information

Family Name: HEUR.Malware.Fody.Generic
Signature status: No Signature

Known Samples

MD5: a91e3f01be6c6dfabc713555e50a1a16
SHA1: 6ed1290638b4b9f716a5bf5ed0d433e0c84bc573
SHA256: DE877AE586F16E215AF777AC8C97DE076D7EB88CAAD3F00949C6E57143582264
File Size: 1.63 MB, 1628160 bytes
MD5: 7ba1850dda1b1fe786038ce8bdf7e188
SHA1: 7c59091f0bcf246823f13a04884472892621eb7e
SHA256: 00C5C5C082EC2D3906284B04787C5DCA1DA3954E9145C74D39B2A82CBA352664
File Size: 3.34 MB, 3341312 bytes
MD5: cf0ba3d181fb2fe83c8dc3414b591924
SHA1: de798c58ab9014ea570a9c1ea6101aa93a7a4f09
SHA256: 0E07062D202127A089B9E5020B168F997CE10EC270A284725BDDF8525E82FB12
File Size: 969.22 KB, 969216 bytes
MD5: 2641eac5d46aef52db9dd2fca8d4cd49
SHA1: e2b7500fc12764a9dae37d2e3085c7fbf44a562d
SHA256: 1572E893BE25025A69510395E96DCAF4A387B376C601CDA4B74D49C0A272E9D6
File Size: 772.61 KB, 772608 bytes
MD5: 6adca9cc8c79a1819f2ead405ba3f3b3
SHA1: 4dfb50e43ae12586ecd4a287d7f2af4a8362dfad
SHA256: 3E771155062469FEF5C8FF0639B66EDA63FEE9D2DDC0C38112FF9468E4E44F3D
File Size: 6.47 MB, 6467584 bytes
Show More
MD5: 815ac1b71586705746ffe7bde27ae6be
SHA1: f922835e63e4bd98269554761ab8b56aead7ba84
SHA256: C8FECDCDF203795B6AB9C8A54A844C4A14432BB690181773408455468EA18EB6
File Size: 1.11 MB, 1108480 bytes
MD5: 3aac3a35a0bbbe83a99adc3a132a7455
SHA1: 575e35d54df0e17073ecc047e475d10736a673a5
SHA256: 131D67C8D342B190CE62AECE505BFBDEDA069D219BBBE81999B124E77D832BC9
File Size: 3.94 MB, 3940352 bytes
MD5: 44edf349b13fccfcc507f9f9d2a2293b
SHA1: 1e7ba8fb326003c57827ccab2b9e002cb76763a2
SHA256: F2969A89ACCFE37428912F32E4052F692E74D7A1FF4A7CC1659E120D2EA53C1F
File Size: 515.50 KB, 515500 bytes
MD5: 55605d7f46429b3c56c8436be2b7d50d
SHA1: 12187d62532d0f5f6e2e2b75364378d41f1e0f8d
SHA256: BD3012374E46FF15B8CF1A9B1CAE7A11140338429EA6B77068A5E82968713AF2
File Size: 236.03 KB, 236032 bytes
MD5: a5af601687a95c5d4997ab2e8dcbe256
SHA1: bc905d49c5159b3b2b9126c58d958c82a7d3afdd
SHA256: 1E074CE222303E9BB35184CEBEB2A2C9588C58105ACA2CBF4B996ADFD7AB075C
File Size: 786.43 KB, 786432 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.0.0.440
  • 1.0.0.0
Company Name
  • miyzvuk
  • REMONDIS
  • yDqwI
File Description
  • Application
  • WindowsFormsApp1
  • WindowsFormsApp2
  • WindowsFormsApp3
File Version
  • 1.00.00.00
  • 1.0.0.0
Internal Name
  • AAITS.exe
  • MusicLyricApp.exe
  • WindowsFormsApp1.exe
  • WindowsFormsApp2.exe
Legal Copyright
  • Author © 2006
  • Copyright © 2017
  • Copyright © 2019
  • Copyright © 2020
  • Copyright © 2023
  • Copyright © 2025
  • Copyright © REMONDIS 2018
  • Copyright © yDqwI 2026
Original Filename
  • AAITS.exe
  • MusicLyricApp.exe
  • WindowsFormsApp1.exe
  • WindowsFormsApp2.exe
Product Name
  • MiyZvuk
  • WindowsFormsApp1
  • WindowsFormsApp2
  • WindowsFormsApp3
Product Version 1.0.0.0

File Traits

  • .NET
  • Agile.net
  • Fody
  • HighEntropy
  • RijndaelManaged
  • WriteProcessMemory
  • x64
  • x86

Block Information

Total Blocks: 31
Potentially Malicious Blocks: 1
Whitelisted Blocks: 19
Unknown Blocks: 11

Visual Map

0 0 0 0 0 0 ? ? ? ? ? ? ? x ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.DllInject.MD

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsa378a.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsa378a.tmp\modern-wizard.bmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsa378a.tmp\nsdialogs.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation::575e35d54df0e17073ecc047e475d10736a673a5_0003940352.exe RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Encryption Used
  • BCryptOpenAlgorithmProvider
Keyboard Access
  • GetKeyState
Other Suspicious
  • AdjustTokenPrivileges
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Network Winsock2
  • WSASend
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • bind
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • setsockopt
Network Winhttp
  • WinHttpOpen

Related Posts

Trending

Most Viewed

Loading...