Malware

What is “MSILHeracles.17371”?

Malware Removal

The MSILHeracles.17371 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.17371 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
accmicro.myvnc.com

How to determine MSILHeracles.17371?


File Info:

crc32: 8A9399C9
md5: c4141a359298ad4aa6704717c42a40b9
name: C4141A359298AD4AA6704717C42A40B9.mlw
sha1: 2390d6150922f2c37c76faa884a6e387dc18bbdc
sha256: 20e534bb10101a177e44f846220eac531780b5ed879d03f01d2507c3ddc09eec
sha512: fb2f68017dc727ec96eaad30735c4ca12fd94146a52f3311a9b509dc00c96277bfda90b1531abea7ec3b0dcc974449c74763d217f6033aa4aab273d09913726a
ssdeep: 6144:NZrb8qlayNn6mEDkc4HJViL/z37Rj7N1B39wGsX:NtTla2n6TDkBJqL3t7HgGs
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2018
Assembly Version: 22.0.0.1
InternalName: Microsoft.exe
FileVersion: 22.0.0.1
CompanyName: Google Inc. Microsoft
LegalTrademarks: Microsoft Inc
Comments: Systems Incorporated
ProductName: Copyright 2017 Google Inc. All rights reserved.
ProductVersion: 22.0.0.1
FileDescription: Microsoft
OriginalFilename: Microsoft.exe

MSILHeracles.17371 also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.27656
CynetMalicious (score: 99)
ALYacGen:Variant.MSILHeracles.17371
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.59298a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.EDMCYUC
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Variant.MSILHeracles.17371
NANO-AntivirusTrojan.Win32.Ursu.fffbde
MicroWorld-eScanGen:Variant.MSILHeracles.17371
TencentMsil.Trojan.Agent.Svgu
Ad-AwareGen:Variant.MSILHeracles.17371
SophosMal/Generic-R + Mal/Behav-421
BitDefenderThetaGen:NN.ZemsilF.34294.mm0@aqwAV!k
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.c4141a359298ad4a
EmsisoftGen:Variant.MSILHeracles.17371 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.MSILHeracles.D43DB
GDataGen:Variant.MSILHeracles.17371
AhnLab-V3Win-Trojan/FCN.140610.X1385
McAfeeArtemis!C4141A359298
MAXmalware (ai score=95)
MalwarebytesTrojan.FakeMS.Gen
PandaTrj/GdSda.A
YandexTrojan.Agent!8bgrqt7AyIA
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSILHeracles.17371?

MSILHeracles.17371 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment