Malware

About “MSILHeracles.43396” infection

Malware Removal

The MSILHeracles.43396 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.43396 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSILHeracles.43396?


File Info:

name: 3AA48AE3FCF3D1BAC3BC.mlw
path: /opt/CAPEv2/storage/binaries/1ee573827745686e7d9ef84e87815fadc224514f3c9f773dc00c329fcd0e756b
crc32: 598079BC
md5: 3aa48ae3fcf3d1bac3bc1b07e368afab
sha1: b68008222305156d3f70ebe4b6a376f6bc9f4ad1
sha256: 1ee573827745686e7d9ef84e87815fadc224514f3c9f773dc00c329fcd0e756b
sha512: 6653a9129987187da3b65f46917f4530fbc8e2efb5608703bc6e5b2853525319d6efefb2f4174dc9d786d5732d9a8050f8eb63c9d03dc3b94b7fe0bc987d9498
ssdeep: 3072:FCPT2XG9jtiOufB9UqkBrfKtI8zHXrTmjhvu:k72XA5i1fBZkBR8zHXHwl
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T174D3FFBE463EF931C9DAAAF244DB14C21B178DB343A9C413F7D61C54A248B5BA3CA1C5
sha3_384: 07380d05504e3cf94a3c1653bb6a8d161393685fa3b9aabcded792a4ec1b35c9a967957a4be68a76eedd84f3b43b7a38
ep_bytes: ff250020001000000000000000000000
timestamp: 2022-01-27 18:52:20

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: RibjrgOndmui.dll
LegalCopyright:
OriginalFilename: RibjrgOndmui.dll
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSILHeracles.43396 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Kryptik.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.43396
FireEyeGen:Variant.MSILHeracles.43396
Cylanceunsafe
VIPREGen:Variant.MSILHeracles.43396
SangforTrojan.Msil.Agent.V19i
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.MSILHeracles.43396
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Agent.VRS
KasperskyHEUR:Trojan.MSIL.Kryptik.gen
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1301100
EmsisoftGen:Variant.MSILHeracles.43396 (B)
VaristW32/MSIL_Agent.GJT.gen!Eldorado
AviraHEUR/AGEN.1301100
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.MSILHeracles.DA984
ZoneAlarmHEUR:Trojan.MSIL.Kryptik.gen
GDataGen:Variant.MSILHeracles.43396
GoogleDetected
ALYacGen:Variant.MSILHeracles.43396
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
TencentMsil.Trojan.Kryptik.Zmhl
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.UUL!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]

How to remove MSILHeracles.43396?

MSILHeracles.43396 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment