Malware

About “Heur.Mint.Autorunner.1” infection

Malware Removal

The Heur.Mint.Autorunner.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.Autorunner.1 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Heur.Mint.Autorunner.1?


File Info:

name: C5F534DB721D07DF2C4F.mlw
path: /opt/CAPEv2/storage/binaries/b1d8fdf12d6e1126598cb52c643bacc8dd92dea318530accd9a3c2d7bc46839d
crc32: 013E43F1
md5: c5f534db721d07df2c4faac0053276ac
sha1: 85b3dd0878ea6a1266c9395d3e87095cd0f3b72e
sha256: b1d8fdf12d6e1126598cb52c643bacc8dd92dea318530accd9a3c2d7bc46839d
sha512: b543f08e29e2c31c53569d1941c5f3232c7778267c4dd92b6b837170bcbbdb1e76bf96f7c21306abbe9e9022927b17c3c69778fbff2f437bb38d2b19c5f3d59f
ssdeep: 49152:8WWqs8LIWfX5DZDmNQCfzqrGOS9NmDta4cUv3:8WvsgzhNDm4mCs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179B5E012ABD0C472D67303318CF6B6B6A2BEFD7146218A0B77D85E091E717D1BA26713
sha3_384: 1427c97e48a2cdfaa625f6ccc60fd206ac429c46269bc75b21ddf0978e5b6fb989b5211d8fe32ffe8cdb1c6bf00c0c78
ep_bytes: 81ec8401000053555633db57895c2418
timestamp: 2013-12-25 05:01:41

Version Info:

CompanyName: Mozilla Corporation
FileDescription: Mozilla Webapp Runtime App Uninstaller
FileVersion: 43.0.1
LegalCopyright: Mozilla Corporation
OriginalFilename: webapp-uninstaller.exe
ProductName: Mozilla Webapp Runtime App Uninstaller
ProductVersion: 43.0.1
Translation: 0x0409 0x04e4

Heur.Mint.Autorunner.1 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Heur.Mint.Autorunner.1
FireEyeGeneric.mg.c5f534db721d07df
ALYacGen:Heur.Mint.Autorunner.1
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
CyrenW32/Pajetbin.K.gen!Eldorado
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Trojan.Bulz-9860169-0
AvastWin32:VB-FBX
VIPREGen:Heur.Mint.Autorunner.1
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.vc
Trapminesuspicious.low.ml.score
SentinelOneStatic AI – Suspicious PE
JiangminPacked.Krap.gvue
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!C5F534DB721D
MalwarebytesVB.Virus.FileInfector.DDS
RisingWorm.VB!1.DA3E (CLASSIC)
IkarusTrojan.Win32.Vindor
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:VB-FBX

How to remove Heur.Mint.Autorunner.1?

Heur.Mint.Autorunner.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment