Malware

About “MSILHeracles.2130 (B)” infection

Malware Removal

The MSILHeracles.2130 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.2130 (B) virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSILHeracles.2130 (B)?


File Info:

name: 448AD73A08C3CC188DDB.mlw
path: /opt/CAPEv2/storage/binaries/54c5ba78e7f5270fddcb7f88b1fcadef721be87e23affd3588a7a77dc31ba591
crc32: 696C52FE
md5: 448ad73a08c3cc188ddb34e0018c3e28
sha1: 4a80f1fd5bec8b5733df333abbeb7f0ea3884ece
sha256: 54c5ba78e7f5270fddcb7f88b1fcadef721be87e23affd3588a7a77dc31ba591
sha512: 82c3fe7779e9b83050e26fb043f0c9a47f50e677257737ff1adc503f992f43da569483636fdf37bb03d24e8805d7afa69ffc6ead9f34ebace3f103011ebe91fd
ssdeep: 384:hohanwj3+INUSf0a2Er6aObLNWEypf1cSMC0lf7Z:dnwjp0arNObLQyMwZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5826C0563FC9721D1FF1BBA29F259400771F6638A2AEF2E1AD0621E1E373404653B35
sha3_384: 15051b803bf649031342216ca2e89e924ffe449a68b048ac837a3e084abb7aa96d31b52d0d788105d10320ad0a0b8adb
ep_bytes: ff250020400042004300440046004700
timestamp: 2043-01-21 19:11:33

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: lol.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: lol.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSILHeracles.2130 (B) also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.2130
FireEyeGeneric.mg.448ad73a08c3cc18
McAfeeRDN/Generic PWS.y
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 005728161 )
AlibabaTrojanPSW:MSIL/Stealer.03433614
K7GWSpyware ( 005728161 )
Cybereasonmalicious.a08c3c
CyrenW32/MSIL_Agent.BRH.gen!Eldorado
ESET-NOD32MSIL/Spy.Agent.CZU
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Msilheracles-9801549-0
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderGen:Variant.MSILHeracles.2130
NANO-AntivirusTrojan.Win32.Stealer.jpimdc
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10ce27a2
Ad-AwareGen:Variant.MSILHeracles.2130
SophosML/PE-A
DrWebTrojan.DownLoader35.13577
ZillyaTrojan.Stealer.Win32.8681
TrendMicroTrojanSpy.MSIL.INFOSTEAL.SMLV0
McAfee-GW-EditionRDN/Generic PWS.y
EmsisoftGen:Variant.MSILHeracles.2130 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.MSILHeracles.2130
JiangminTrojan.PSW.MSIL.axjr
AviraHEUR/AGEN.1217873
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.C4228553
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34742.bm1@a417Z@m
ALYacGen:Variant.MSILHeracles.2130
MAXmalware (ai score=84)
MalwarebytesSpyware.TelegramBot
TrendMicro-HouseCallTrojanSpy.MSIL.INFOSTEAL.SMLV0
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:okpuIoU5ZJF5YZ8exCeTOg)
YandexTrojanSpy.Agent!1+EsR4gYioI
IkarusTrojan.MSIL.TrojanClicker
FortinetMSIL/Agent.CZU!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSILHeracles.2130 (B)?

MSILHeracles.2130 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment