Malware

MSILHeracles.39475 malicious file

Malware Removal

The MSILHeracles.39475 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.39475 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Collects and encrypts information about the computer likely to send to C2 server
  • Likely virus infection of existing system binary

How to determine MSILHeracles.39475?


File Info:

name: EDB23C4A96C2965773FD.mlw
path: /opt/CAPEv2/storage/binaries/5d5f831dd6c3407a654ad81206b63845f969f6c7c3171a0e90f0ca02875b959b
crc32: 33E8118B
md5: edb23c4a96c2965773fd778e34346f5a
sha1: fb7f533f1e0ff635cba265e5e7178629b93f7ce5
sha256: 5d5f831dd6c3407a654ad81206b63845f969f6c7c3171a0e90f0ca02875b959b
sha512: 4f805a297fcd7b2ddc275b720abbb2d5c362322910c29cf406a5825a3d37c7c6afe1e3fbbde0cf942562c1ae04ae4001657309fd563ff0f05305a4757a56afdf
ssdeep: 1536:8K0EdwmxqV+KAWjMV2MU2oHe3hwpAFxsoEjqsZqhubE5xCO:8K0EdN2MJJxsoEjqschubEb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127630A8973DD4603C89EA6FD98B1570243B0E8678727D7AF0CD9B5B809373E84B05A97
sha3_384: 410e288cb3d0dc9e0ebb3d75f55770192609904b0f1fe800f6b2e157a2331dedd84f322fb2dfd896256d9a8866d2ff1d
ep_bytes: ff250020400000000000000000000000
timestamp: 2012-11-27 10:25:27

Version Info:

Translation: 0x0000 0x04b0
CompanyName: google
FileDescription:
FileVersion: 0.0.0.0
InternalName: csrss.exe
LegalCopyright:
OriginalFilename: csrss.exe
ProductVersion: 0.0.0.0
Assembly Version: 1.3.4.3

MSILHeracles.39475 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.39475
FireEyeGeneric.mg.edb23c4a96c29657
ALYacGen:Variant.MSILPerseus.132493
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005082b31 )
K7GWTrojan ( 005082b31 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Autorun.Agent.BW
APEXMalicious
ClamAVWin.Packed.Barys-7008062-0
KasperskyHEUR:Trojan.MSIL.Fsysna.gen
BitDefenderGen:Variant.MSILHeracles.39475
AvastMSIL:GenMalicious-RJ [Trj]
Ad-AwareGen:Variant.MSILHeracles.39475
EmsisoftGen:Variant.MSILHeracles.39475 (B)
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.KeyloggerNET.14
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.MSILHeracles.39475
AviraTR/Spy.Gen
MAXmalware (ai score=81)
ArcabitTrojan.MSILHeracles.D9A33
ZoneAlarmHEUR:Trojan.MSIL.Fsysna.gen
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 99)
AhnLab-V3Spyware/Win.Generic.C5180947
McAfeeRDN/Generic PWS.y
RisingSpyware.Keylogger!1.647D (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.BW!tr
BitDefenderThetaGen:NN.ZemsilF.34742.em0@a8T@Zil
AVGMSIL:GenMalicious-RJ [Trj]
Cybereasonmalicious.a96c29

How to remove MSILHeracles.39475?

MSILHeracles.39475 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment