Malware

What is “MSILHeracles.100564”?

Malware Removal

The MSILHeracles.100564 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.100564 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Binary compilation timestomping detected

How to determine MSILHeracles.100564?


File Info:

name: 5CF58D6BA27DCC9AA5BB.mlw
path: /opt/CAPEv2/storage/binaries/3082a841a75c759a2e6cc3f1a7be5acb633f3e048e48b455196e71433d58b976
crc32: E328AA9E
md5: 5cf58d6ba27dcc9aa5bbcc9900e35e84
sha1: 44b5c2d4c438f52192e427dd0a81eee094d48d66
sha256: 3082a841a75c759a2e6cc3f1a7be5acb633f3e048e48b455196e71433d58b976
sha512: cf8f286e6727b10c0e57089458fe4590cef83968fc06f81ab8ba6a121b14d9305f756351f3ee77d13ed4c28535be534d36bb52bdac23288db6ea939160dda91a
ssdeep: 384:VK/IXbcp1BX/sdOnwHf8tfDo6owDbuh/cxqBqgapbHwX21pQdXa0qnCXgRiTunDs:VKPd/sdOwH4oCwkEYTpbv+vV+LlJG
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1F1D2F708B7F98664F2FF4F78A87616008A32F947AA32D32D19D9405D1E72B448D60FB3
sha3_384: 437660f851b6f80d761220218b7005c527dbf80dcfe3d1823e60ed9de6cdb761d077a2e10d4812fb934fe1e1cc68b520
ep_bytes: ff250020001000000000000000000000
timestamp: 2056-01-31 03:26:38

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: KrnlAPI.dll
LegalCopyright:
OriginalFilename: KrnlAPI.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSILHeracles.100564 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.DllInject.4!c
MicroWorld-eScanGen:Variant.MSILHeracles.100564
SkyhighRDN/Generic.dx
McAfeeRDN/Generic.dx
MalwarebytesRiskWare.DllInjector
ZillyaTrojan.DllInject.Win32.20126
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWUnwanted-Program ( 005784731 )
K7AntiVirusUnwanted-Program ( 005784731 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/DllInject.AQC potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002H09I223
BitDefenderGen:Variant.MSILHeracles.100564
AvastWin32:Malware-gen
EmsisoftGen:Variant.MSILHeracles.100564 (B)
VIPREGen:Variant.MSILHeracles.100564
FireEyeGeneric.mg.5cf58d6ba27dcc9a
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=80)
GoogleDetected
VaristW32/ABRisk.KDPT-7091
Antiy-AVLRiskWare/MSIL.DllInject
ArcabitTrojan.MSILHeracles.D188D4
ViRobotAdware.Dllinject.30720
GDataGen:Variant.MSILHeracles.100564
AhnLab-V3Trojan/Win.Generic.C5482453
ALYacGen:Variant.MSILHeracles.100564
Cylanceunsafe
IkarusPUA.MSIL.Dllinject
MaxSecureTrojan.Malware.217282578.susgen
FortinetAdware/DllInject
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove MSILHeracles.100564?

MSILHeracles.100564 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment