Malware

Heur.Minggy.4 malicious file

Malware Removal

The Heur.Minggy.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Minggy.4 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Heur.Minggy.4?


File Info:

name: F1BACE3DF961508388BD.mlw
path: /opt/CAPEv2/storage/binaries/5d5d672a615783f14a9c34bf3d11c823e734e50a1eec3e24c118ab39c4ff1c10
crc32: 9B89DA2E
md5: f1bace3df961508388bdba0b5f8b59e3
sha1: 88f36746a4e704b082364d78cf671dff4401f3bd
sha256: 5d5d672a615783f14a9c34bf3d11c823e734e50a1eec3e24c118ab39c4ff1c10
sha512: 01f382f8f22dceb98c3767a6649ed65a4a6384355070077612388a2a658b36bf83a995caee006cd0461ef4cce161c4c53ebc90e862ce3c1117e88642e950e14a
ssdeep: 1536:kY+K5Dn5IiYBCrTfXMxfLw3awEupQEAGlWkbBEP2ePmYj0Sz:v5Dn5FrraZQQYlWkdE7uYYSz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18E63473329B138F7F91206307D82C2B11AA3DB3E2B65D67F90B3D1689822D61B9DC574
sha3_384: 3f0aaed5a853b310a50b8edf02d2d5b8484088e5f06365bb1d207785a85d9779df87f2f14480683de5801f4d42ab3b40
ep_bytes: 5589e583ec08c7042402000000ff154c
timestamp: 2012-12-25 16:41:36

Version Info:

CompanyName:
FileVersion:
FileDescription:
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x041c 0x04e4

Heur.Minggy.4 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Spambot.11349
ClamAVWin.Trojan.Inject-124
FireEyeGeneric.mg.f1bace3df9615083
CAT-QuickHealTrojan.Ransom.A
McAfeeInjection Dropper.B
CylanceUnsafe
VIPRETrojan.Win32.Reveton.a (v)
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0040f03f1 )
AlibabaVirTool:Win32/CeeInject.893da50a
K7GWTrojan ( 0040f03f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34212.eC0@aOA3YAoi
CyrenW32/Zbot.IF.gen!Eldorado
SymantecTrojan.Ransomlock!g41
ESET-NOD32Win32/Injector.AANZ
TrendMicro-HouseCallTROJ_RANSOM.SMCB
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Minggy.4
NANO-AntivirusTrojan.Win32.Jorik.bgctql
SUPERAntiSpywareTrojan.Agent/Gen-Injector
MicroWorld-eScanGen:Heur.Minggy.4
TencentWin32.Trojan.Generic.Ectu
Ad-AwareGen:Heur.Minggy.4
SophosMal/Generic-R + Mal/EncPk-AGE
ComodoTrojWare.Win32.Injector.fn@4tj2ip
ZillyaTrojan.Injector.Win32.407288
TrendMicroTROJ_RANSOM.SMCB
McAfee-GW-EditionBehavesLike.Win32.Trojan.kc
EmsisoftGen:Heur.Minggy.4 (B)
IkarusVirus.Win32.CeeInject
GDataGen:Heur.Minggy.4
JiangminTrojan/Jorik.geeh
WebrootW32.Malware.Gen
AviraTR/Obfuscate.advmna
Antiy-AVLTrojan[PSW]/Win32.Tepfer
KingsoftWin32.Troj.Jorik..(kcloud)
ArcabitTrojan.Minggy.4
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/CeeInject.gen!HL
AhnLab-V3Trojan/Win32.Inject.R47312
Acronissuspicious
VBA32Trojan.EA.01671
ALYacGen:Heur.Minggy.4
MAXmalware (ai score=100)
MalwarebytesTrojan.Agent
APEXMalicious
RisingTrojan.Mingc!1.660C (C64:YzY0Or+nA8Fvkus5)
YandexTrojan.GenAsa!D9sfH/woZ+o
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Zbot.AAU!tr
Cybereasonmalicious.df9615
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.5143819.susgen

How to remove Heur.Minggy.4?

Heur.Minggy.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment