Malware

Should I remove “MSILHeracles.4200”?

Malware Removal

The MSILHeracles.4200 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.4200 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSILHeracles.4200?


File Info:

crc32: 5CD94432
md5: 58855dce814f68f6d77f6ecbbe0682ce
name: 58855DCE814F68F6D77F6ECBBE0682CE.mlw
sha1: fc542dbcbd102284b2b054bc11c4d23ba8883d7f
sha256: 574efe8cce09da26ed0ae70376857c12d1282c55e113ad65523307364900de16
sha512: b9fca6389a0cfdedbabb4ded134928c39dc56729c02bf0c80fb9aa48edb9764bc0c6c456d76baee04e555b6a80f22eadcc2df69f6a562273349204c5e4d408d5
ssdeep: 6144:c9/OzlMypOQCXrRUeLKRvHDTLX/GqbsJE7ae0ov8b6HNFtfLoEf0qbrG:gOK0OXtUeuRv37/GPE7aeq6d8EfO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright PodVew 2020
Assembly Version: 1.0.0.0
InternalName: PodVew.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: PodVew
ProductVersion: 1.0.0.0
FileDescription: PodVew
OriginalFilename: PodVew.exe

MSILHeracles.4200 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.4200
McAfeeGenericRXMJ-NN!58855DCE814F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.MSILHeracles.4200
K7GWTrojan ( 700000121 )
Cybereasonmalicious.cbd102
ArcabitTrojan.MSILHeracles.D1068
CyrenW32/MSIL_Kryptik.CHW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Exploit.MSIL.Shellcode.gen
AlibabaTrojan:Win32/Starter.ali2000005
AegisLabHacktool.MSIL.Shellcode.3!c
RisingTrojan.Kryptik!8.8 (TFE:C:f0M3KjoXAzM)
Ad-AwareGen:Variant.MSILHeracles.4200
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1139136
DrWebTrojan.Packed2.41837
TrendMicroTROJ_GEN.R002C0PKR20
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
MaxSecureTrojan.Malware.300983.susgen
FireEyeGeneric.mg.58855dce814f68f6
EmsisoftGen:Variant.MSILHeracles.4200 (B)
SentinelOneStatic AI – Malicious PE
JiangminExploit.MSIL.pc
AviraHEUR/AGEN.1139136
MicrosoftTrojan:Win32/Ymacco.AA57
ZoneAlarmHEUR:Exploit.MSIL.Shellcode.gen
GDataGen:Variant.MSILHeracles.4200
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4229791
ALYacGen:Variant.MSILHeracles.4200
MalwarebytesBackdoor.Remcos
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Kryptik.QME
TrendMicro-HouseCallTROJ_GEN.R002C0PKR20
TencentWin32.Trojan.Inject.Auto
MAXmalware (ai score=80)
FortinetMSIL/Kryptik.QME!tr
BitDefenderThetaGen:NN.ZemsilF.34658.sm0@aGZBqjd
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/Trojan.Exploit.d0c

How to remove MSILHeracles.4200?

MSILHeracles.4200 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment