Threat Database Trojans Trojan.MSIL.Spy.L

Trojan.MSIL.Spy.L

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,986
Threat Level: 80 % (High)
Infected Computers: 45
First Seen: May 8, 2021
Last Seen: June 29, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Spy.L on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to spy on your computer activities, steal sensitive information, and compromise your privacy. It is essential to understand the nature of this threat and take prompt action to remove it from your system to prevent further damage.

What Is Trojan.MSIL.Spy.L?

Trojan.MSIL.Spy.L is a type of spyware that infiltrates your computer system without your knowledge or consent. The name suggests that it is a Trojan horse malware, which disguises itself as a legitimate program or file to gain access to your system. Once inside, it can collect and transmit sensitive information, such as login credentials, credit card numbers, and personal data, to its creators or other malicious parties.

How Trojan.MSIL.Spy.L Operates

Trojan.MSIL.Spy.L operates by exploiting vulnerabilities in your system or using social engineering tactics to trick you into installing it. It can be disguised as a legitimate program, attachment, or download, making it difficult to detect. Once installed, it can run in the background, collecting and transmitting data without your knowledge. It may also install additional malware or create backdoors for remote access, allowing hackers to control your system and steal sensitive information.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Spy.L infection can be subtle, but they may include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups. You may also notice that your browser homepage or search engine has changed, or that you are being redirected to suspicious websites. Additionally, you may receive suspicious emails or messages, or notice that your personal data is being used without your consent.

  • Unexplained changes to your system settings or configuration
  • Unusual network activity or data transmission
  • Suspicious programs or files on your system
  • Unexplained charges or transactions on your credit card or bank statements

How to Remove Trojan.MSIL.Spy.L

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware
  3. Uninstall any suspicious programs or applications that may be related to the malware
  4. Reset your browser settings, including Chrome, Firefox, and Edge, to their default values
  5. Reboot your system and run another scan to ensure that the malware has been completely removed

Conclusion

Removing Trojan.MSIL.Spy.L from your system requires prompt and careful action. By following the steps outlined above, you can help to ensure that your system is clean and secure. However, it is essential to remain vigilant and take steps to prevent future infections, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or attachments. By taking these precautions, you can help to protect your personal data and prevent the spread of malware.

Analysis Report

General information

Family Name: Trojan.MSIL.Spy.L
Signature status: No Signature

Known Samples

MD5: 70303583826be0778f24f603e869e7e5
SHA1: 419f174e933efe3696f545c6f81215d146da5f1c
SHA256: AC6C6FDF8B3E6FA7990E56D1827C5AB852E1211F9C51678C311950D68AC250A6
File Size: 3.45 MB, 3453290 bytes
MD5: a967415b168082fa0b30414e732c3db5
SHA1: 17439d7c29b5cc8ef8a4d6349edd664de3860a5a
SHA256: EEA4FE8005AF47968ECCA673ACB2DE5BBEF8CD5139DA56ADCC050D85B1D510A2
File Size: 2.17 MB, 2169856 bytes
MD5: 320bf830fe6547162fb9f761ddf3c3dc
SHA1: 1684ea753e8b30cf0775cf0b14577a6c4d0e36c0
SHA256: 4960224867211E5FB0DEA2C6F00BC50FAFAF9134A01AE51AE8A7F1C331F693D0
File Size: 43.90 KB, 43896 bytes
MD5: 093fd7bf3862842399c73049061ad51c
SHA1: 00c7219e04a6c55d75c9a5ac553896fd419603f2
SHA256: 4D3A3E0F40E041FEC846F42DD09A9C10ABD01C5C781F2326E08A900D66C37FA5
File Size: 402.32 KB, 402320 bytes
MD5: 893407e01d419e60d9a0a72cfdb1af93
SHA1: cc7ae2a579a9e4cc8f266c48b2dce0214f673a0c
SHA256: 82EC0E218B37F922EDB22D61B1C18C4BEF472C7D108185A8B75EE9516393D884
File Size: 71.04 KB, 71040 bytes
Show More
MD5: 294db97e955742cb4a17ea9d12618081
SHA1: 0acbf2a2e6dc0fcc87c96aba88496e2443330131
SHA256: F9E1DE516867D4D626932F6E0AA85B3C1F6E8DF0B1CF12F62448509145EEE3CF
File Size: 689.22 KB, 689224 bytes
MD5: 1bab3f9647edec776768c9b21c30cc4f
SHA1: 58495c01fc7a04664e631207e683d254bd1c85ba
SHA256: F01179CF2B3DDF244D899594088A30141F60EFCC5B470EBCC3AE608FE72EB64B
File Size: 132.98 KB, 132984 bytes
MD5: 89b53452d611daa1293509753523ce40
SHA1: 0ca0257aa991e499a424cc4d82418eee73bcf713
SHA256: 9F0F268E19978B3FF22D76228742E06D5DBD65F01B08D50C7518099035143DF2
File Size: 3.97 MB, 3971584 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments FREE 4 ALL
Company Name
  • Cheaters Inc
  • Synaptics
File Description
  • AUTHMTKV6
  • DPF DTC EGR Remover
  • MTKV6
  • Synaptics Pointing Device Driver
  • XiaoMiFlash
  • XYNO-FRP
File Version
  • 1.0.24.0
  • 1.0.0.4
  • 1.0.0.0
Internal Name
  • Auth.exe
  • DaVinci.EXE
  • XiaoMiFlash.exe
  • XYNO COMPANY FRP TOOLS V2.exe
  • XYNO COMPANY TOOLS V2.exe
Legal Copyright
  • Copyrights (C) 2020-2021 FREE
  • Copyright © 2015
  • Copyright © 2023
  • Copyright © 2025
Legal Trademarks Trademarks (R) 2020-2021 FREE
Original Filename
  • Auth.exe
  • DaVinci_EGR_DPF_DTC.exe
  • XiaoMiFlash.exe
  • XYNO COMPANY FRP TOOLS V2.exe
  • XYNO COMPANY TOOLS V2.exe
Product Name
  • DaVinci DPF EGR DTC
  • MEMEK
  • QX-FRP
  • Synaptics Pointing Device Driver
  • XiaoMiFlash
  • XynoMediatekV6
Product Version
  • 1.0.24.0
  • 1.0.0.0

Digital Signatures

Signer Root Status
Tonycstech Tonycstech Self Signed

File Traits

  • .NET
  • Goliath
  • HighEntropy
  • NewLateBinding
  • No Version Info
  • ntdll
  • RijndaelManaged
  • x86

Block Information

Similar Families

  • MSIL.Gamehack.FMD

Files Modified

File Attributes
c:\programdata\synaptics Synchronize,Write Attributes
c:\programdata\synaptics\rcxe7da.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\synaptics.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\synaptics\synaptics.exe Synchronize,Write Attributes
c:\programdata\synaptics\synaptics.exe Synchronize,Write Data
c:\users\user\appdata\local\temp\pxcmhis.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\server.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\winsl Synchronize,Write Attributes
c:\users\user\appdata\roaming\winsl\l5\4\2026 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_0ca0257aa991e499a424cc4d82418eee73bcf713_0003971584 Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\downloads\._cache_0ca0257aa991e499a424cc4d82418eee73bcf713_0003971584 Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\a6fb6cc46b6fa6c9610329b6ef61e0d3::hp aGVqYXh4LTQ0Njg4LnBvcnRtYXAuaG9zdDo0NDY4OCw= RegNtPreCreateKey
HKCU\software\a6fb6cc46b6fa6c9610329b6ef61e0d3::i ! RegNtPreCreateKey
HKCU::di ! RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\environment::see_mask_nozonechecks 1 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::a6fb6cc46b6fa6c9610329b6ef61e0d3 "C:\Users\Bpoxvapr\AppData\Local\Temp\server.exe" .. RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::a6fb6cc46b6fa6c9610329b6ef61e0d3 "C:\Users\Bpoxvapr\AppData\Local\Temp\server.exe" .. RegNtPreCreateKey
Show More
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㩞삙盧ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 播숈盧ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m�8��8z�jg�B�8 �� �6 �v z �Z xy �� �a��T���B�����������5���� +Bx�<��5�R �!wz"Wc#�#��$kF$��%:�%`�%�&� &�-(�(X�)E)�`*J*9*�"+�[,��-!R/9�/��0P%1` RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::synaptics pointing device driver C:\ProgramData\Synaptics\Synaptics.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �  xy* �/��Y�d�kP~� ��ރ�p$��^�o�eeTVs}$kP~$��1B��7 ���ﺃe"e��� ��1-��fe��g� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m�8��8z�jg�B�8 �� �6 �v z �Z xy �� �a��T���B�����������5���� +Bx�<��5�R �!wz"Wc#�#��$kF$��%:�%`�%�&� &�-(�(X�)E)�`*J*9*�"+�[,��-!R/9�/��0P%1` RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess
Keyboard Access
  • GetAsyncKeyState
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Network Winsock2
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • bind
  • closesocket
  • gethostbyname
  • getsockname
  • setsockopt
  • socket
Service Control
  • OpenSCManager
Network Winhttp
  • WinHttpOpen
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile

Shell Command Execution

(NULL) C:\Users\Bpoxvapr\AppData\Local\Temp\server.exe
netsh firewall add allowedprogram "C:\Users\Bpoxvapr\AppData\Local\Temp\server.exe" "server.exe" ENABLE
runas c:\users\user\downloads\._cache_0ca0257aa991e499a424cc4d82418eee73bcf713_0003971584
runas C:\ProgramData\Synaptics\Synaptics.exe InjUpdate

Related Posts

Trending

Most Viewed

Loading...