Malware

MSILHeracles.5387 removal guide

Malware Removal

The MSILHeracles.5387 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.5387 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine MSILHeracles.5387?


File Info:

name: 00589CBB46C07E70F7AA.mlw
path: /opt/CAPEv2/storage/binaries/62d069adde632da272f836e5f58b4563f5adefc5cc2ef6a2156f56058ea387b2
crc32: 05F50244
md5: 00589cbb46c07e70f7aabe37b11e0adc
sha1: 986c73125f0536a068df03ec3ce5cfcccaa495d7
sha256: 62d069adde632da272f836e5f58b4563f5adefc5cc2ef6a2156f56058ea387b2
sha512: 6ad0712af232468e5e569d55a2c2fac6ba34f3076cc180523eda5988a2000da30c0ed701abb141bfe720cdb6aa50cec6afe8acc810dc07c1a95b475ad320b8ae
ssdeep: 1536:f8F5T7J0oBCmTATxGjWu+R2mge4a9IoE+rsliGDtWmLcLe77N:6CsATx6Wu+tgeLtfrz5y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D9364C2FE4D93A1C86C2777C4F7152007E19DD3A733E6452E9C7B9949C33A38989A89
sha3_384: f97b3f4c1f23f8797a198c1b7620c41ce275d3e9b7b2e749a95b1fb85a60e7eb11ba1f86b1aaa5b0a7add1e911e4da71
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-26 15:46:43

Version Info:

0: [No Data]

MSILHeracles.5387 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.5387
FireEyeGeneric.mg.00589cbb46c07e70
McAfeeArtemis!00589CBB46C0
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2653599
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/MalwareX.aa2005c2
K7GWTrojan ( 004f635b1 )
K7AntiVirusTrojan ( 004f635b1 )
BitDefenderThetaGen:NN.ZemsilF.34182.fmW@a0AZ5Yd
CyrenW32/Trojan.AOED-2387
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.ALM
TrendMicro-HouseCallTROJ_GEN.R014C0WAS22
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.MSILHeracles.5387
APEXMalicious
TencentWin32.Trojan.Generic.Bxo
EmsisoftGen:Variant.MSILHeracles.5387 (B)
TrendMicroTROJ_GEN.R014C0WAS22
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
eGambitUnsafe.AI_Score_84%
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.351941B
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.MSILHeracles.5387
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4938074
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.MSILHeracles.5387
MalwarebytesTrojan.Crypt
AvastWin32:MalwareX-gen [Trj]
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:1BdPTXK82pvTVeDHT03o1g)
YandexTrojan.Agent!yZY/rQZZq2w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Agent.ALM!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.b46c07
PandaTrj/GdSda.A

How to remove MSILHeracles.5387?

MSILHeracles.5387 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment