Malware

Should I remove “Ser.MSILHeracles.197 (B)”?

Malware Removal

The Ser.MSILHeracles.197 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.MSILHeracles.197 (B) virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Ser.MSILHeracles.197 (B)?


File Info:

name: A8417AAF02C08325B367.mlw
path: /opt/CAPEv2/storage/binaries/2443c37fb56dd90692e11a313e492827759910ea075f92580ae0ca9c8ff0bdfd
crc32: 11992640
md5: a8417aaf02c08325b367f63c6e7a3371
sha1: a9472b47c50e63126a67b03336ecc6978952e213
sha256: 2443c37fb56dd90692e11a313e492827759910ea075f92580ae0ca9c8ff0bdfd
sha512: 25e0404c726de301ef223fa214523d0f3df723f658f88c5ce558db363e5b42ccedbab52b29fb60cdd38c5b36a3818a5e4bf8744b7e87555cd7a327664b29dbdd
ssdeep: 12288:60mixBFmqmQLRw4TbdKv2l0OA4q6pW6sdVrGcnzpHWvIFk:60mi1dtw4FzlqopiVSuWwFk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104E40303692C94B2EF38A33E40150DC992F41C5C56CDB62A17B9BC3DC9BD5225E1FA6E
sha3_384: 79f53702e5e6a640ff2c26c5a6f7cc94e7d96f485fe103a48f282808a461173e8de8019f5691bc72b113a60e87487f36
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-25 14:00:27

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Rogers Peet
FileDescription: Biblan
FileVersion: 5.6.0.0
InternalName: CMSUSAGEPATTE.exe
LegalCopyright: Copyright © Rogers Peet
LegalTrademarks:
OriginalFilename: CMSUSAGEPATTE.exe
ProductName: Biblan
ProductVersion: 5.6.0.0
Assembly Version: 8.0.6.0

Ser.MSILHeracles.197 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47494984
FireEyeGeneric.mg.a8417aaf02c08325
CylanceUnsafe
K7AntiVirusTrojan ( 0058aedd1 )
BitDefenderTrojan.GenericKD.47494984
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZemsilF.34294.Pm1@aGMN3Nd
CyrenW32/Kryptik.CMR.gen!Eldorado
SymantecScr.Malcode!gdn30
ESET-NOD32a variant of MSIL/Kryptik.ADOI
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
Ad-AwareTrojan.GenericKD.47494984
SophosTroj/Krypt-FD
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Ser.MSILHeracles.197 (B)
APEXMalicious
MAXmalware (ai score=86)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.47494984
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4789509
MalwarebytesTrojan.Crypt.MSIL
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.FOAM!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove Ser.MSILHeracles.197 (B)?

Ser.MSILHeracles.197 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment