Malware

Marsilia.5387 removal

Malware Removal

The Marsilia.5387 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Marsilia.5387 virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Marsilia.5387?


File Info:

name: 4DA1C4B5B1DD079418F0.mlw
path: /opt/CAPEv2/storage/binaries/88a4a38a19f907ccc1ea3881b9909cace0a66faa2b1bd481fb610025c042d232
crc32: BB20484A
md5: 4da1c4b5b1dd079418f07e7a2e632674
sha1: ee400e56e3517e9819e011e6c99d133c3d146b6a
sha256: 88a4a38a19f907ccc1ea3881b9909cace0a66faa2b1bd481fb610025c042d232
sha512: 34552c804d25a16eec18493916b47eed0322e40f83bac3eaf283f6f3fa6f431d0da5c35f45b4a202c7a945837cbe3a5fd05d0f876f0a6814b1631c13dd8a609b
ssdeep: 3072:RJhML73DrsnvS57/nPRQmMUVyzeFHFcL9eH+FQ1Xi3:Rq7WWTJZdFK9e/Xi3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T113F3EF92DF96CE05CC3A2931ECB30E5C0355E9C249E5568B4B9EAE47BD677003EC68D2
sha3_384: da67587ce7ff93d54cd50d4c230e4d4ba6e90fbe77baf54afaf80e21385938284456c15df621ea3c1a486118e51d11cd
ep_bytes: ff250020400000000000000000000000
timestamp: 2061-10-21 05:46:26

Version Info:

Translation: 0x0000 0x04b0
CompanyName: WinFormApp
FileDescription: WinFormApp
FileVersion: 1.0.0.0
InternalName: WinFormApp.exe
LegalCopyright:
OriginalFilename: WinFormApp.exe
ProductName: WinFormApp
ProductVersion: 1.0.0
Assembly Version: 1.0.0.0

Marsilia.5387 also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Marsilia.5387
FireEyeGeneric.mg.4da1c4b5b1dd0794
SkyhighBehavesLike.Win32.Agent.ch
McAfeeRDN/Real Protect-LS
MalwarebytesTrojan.MalPack.MSIL
ZillyaTrojan.Kryptik.Win32.3938529
SangforBackdoor.Msil.Kryptik.Voaf
AlibabaBackdoor:MSIL/Bladabindi.50b4c784
K7GWTrojan ( 00596f0f1 )
K7AntiVirusTrojan ( 00596f0f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AFKG
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Tedy-10017698-0
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Marsilia.5387
NANO-AntivirusTrojan.Win32.Kryptik.jtcuzk
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.13bb0578
EmsisoftGen:Variant.Marsilia.5387 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader21.28154
VIPREGen:Variant.Marsilia.5387
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/MSIL_Kryptik.KEP.gen!Eldorado
Antiy-AVLTrojan/MSIL.Kryptik
ArcabitTrojan.Marsilia.D150B
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
GDataGen:Variant.Marsilia.5387
AhnLab-V3Trojan/Win.Generic.C5271286
ALYacGen:Variant.Marsilia.5387
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Chgt.AA
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:wpf8RS+g8uydAXK4CcZYlw)
YandexTrojan.Kryptik!xSB4/0cw/SU
IkarusTrojan.MSIL.Agent
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.36804.km3@aqIVLFm
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Marsilia.5387?

Marsilia.5387 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment