Malware

Should I remove “MSILHeracles.51187”?

Malware Removal

The MSILHeracles.51187 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.51187 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Accessed credential storage registry keys
  • Yara detections observed in process dumps, payloads or dropped files

How to determine MSILHeracles.51187?


File Info:

name: A45389771A8A8D714745.mlw
path: /opt/CAPEv2/storage/binaries/d7c61845fbd237071d0b722842c480f6fbe47eb61805a9a333613147d8affc7e
crc32: 914DA59F
md5: a45389771a8a8d714745ac50e3baef0d
sha1: 43f42e5362906225ebfcee878f558db4891c513d
sha256: d7c61845fbd237071d0b722842c480f6fbe47eb61805a9a333613147d8affc7e
sha512: 9fa6d74455ebdb366543598976cceeb415ecb4fedd236cfd605f49f9d5242b53478605a84524fe989c73d02bac02723129c478768b514339acb60798195fbdd9
ssdeep: 196608:Xf2qaIIooJq+eMPwtmMKUAmwEl7fTO4rb1fuS2:X+qaIIDJxk5TwEZfTOQ5f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1617633261159E69DF33F4CF4C85ED0F246066C67CB3AA13BEA287D9037F6A512C760A1
sha3_384: 09c344abacf1aea3c799e3e6f21784f33555a33e25f3f0f1ef1aa7de845f05ff55eae639d7c840dce40b40076ed6749a
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-04-01 12:58:49

Version Info:

Translation: 0x0000 0x04b0
Comments: 超级脱机编程器
CompanyName: www.xwopen.com
FileDescription: 超级脱机编程器
FileVersion: 1.0.0.0
InternalName: 超级脱机编程器.exe
LegalCopyright: Copyright © www.xwopen.com
LegalTrademarks: 超级脱机编程器
OriginalFilename: 超级脱机编程器.exe
ProductName: 超级脱机编程器
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSILHeracles.51187 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.51187
FireEyeGeneric.mg.a45389771a8a8d71
SkyhighBehavesLike.Win32.InstCap.wc
ALYacGen:Variant.MSILHeracles.51187
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.MSILHeracles.DC7F3
BitDefenderThetaGen:NN.ZemsilF.36744.@p0@am8i90c
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.MSILHeracles.51187
AvastWin32:Malware-gen
EmsisoftGen:Variant.MSILHeracles.51187 (B)
F-SecureHeuristic.HEUR/AGEN.1310979
VIPREGen:Variant.MSILHeracles.51187
Trapminemalicious.high.ml.score
SophosMal/Generic-R
VaristW32/MSIL_Agent.FUS.gen!Eldorado
AviraHEUR/AGEN.1310979
Antiy-AVLTrojan/Win32.Sabsik
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.MSILHeracles.51187
GoogleDetected
AhnLab-V3Trojan/Win32.Generic.C233868
McAfeeArtemis!A45389771A8A
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CKH23
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.193395823.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.362906
DeepInstinctMALICIOUS

How to remove MSILHeracles.51187?

MSILHeracles.51187 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment