Malware

What is “MSILHeracles.38554 (B)”?

Malware Removal

The MSILHeracles.38554 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.38554 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid

How to determine MSILHeracles.38554 (B)?


File Info:

name: 4C256867B73F40645648.mlw
path: /opt/CAPEv2/storage/binaries/e8c7008f671b28118123ff6a380b06ddeee6d9ff55c187f5577528f2b48e5786
crc32: D99EC1B1
md5: 4c256867b73f4064564845f5fcbe0b8a
sha1: e1a3ce84183f60b71dc1f3723857e64e7840bfa9
sha256: e8c7008f671b28118123ff6a380b06ddeee6d9ff55c187f5577528f2b48e5786
sha512: 58e3d0fa8f5c951aa800eec61f84dbfa40c22334be532f29336a2404ff189957c80de17323bde5c03ff2889c2ed901c41af846651f49e9d16940e1effc84cfbc
ssdeep: 3072:3LV+pl26XYvydgT36Wn7OMl0j81sx0kQ6i5MDK2Z:3L0pl26Xsn7jlmak+5MO2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD04093C42EF5FB5EFEE0576C0B2E5948A1064EB5CA6E36E50804DF1BE406DA41216BF
sha3_384: 1703b38c2f7805399b8289e5e84614cb4d78ca88abbc2ed1c5601aeb90521ff00936b38bd8ae68454e774052fd270b82
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-12 14:10:21

Version Info:

0: [No Data]

MSILHeracles.38554 (B) also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.38554
FireEyeGeneric.mg.4c256867b73f4064
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.MSILHeracles.38554
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.7b73f4
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.Q
APEXMalicious
ClamAVWin.Packed.njRAT-9809336-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.MSILHeracles.38554
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.MSILHeracles.38554
EmsisoftGen:Variant.MSILHeracles.38554 (B)
VIPREGen:Variant.MSILHeracles.38554
TrendMicroTROJ_GEN.R014C0DHD22
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.MSILHeracles.38554
GoogleDetected
AviraHEUR/AGEN.1202127
MAXmalware (ai score=82)
ArcabitTrojan.MSILHeracles.D969A
MicrosoftBackdoor:MSIL/Bladabindi.BN
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5222815
McAfeeArtemis!4C256867B73F
TrendMicro-HouseCallTROJ_GEN.R014C0DHD22
RisingTrojan.Generic/MSIL@AI.91 (RDM.MSIL:Ic9RVKG4I7i/s6QebQbMbA)
IkarusTrojan.MSIL.MultiPacked
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.Q!tr
BitDefenderThetaGen:NN.ZemsilF.34592.liW@a8vKk5o
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSILHeracles.38554 (B)?

MSILHeracles.38554 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment