Malware

Heur.Mint.Autorunner.1 (B) removal guide

Malware Removal

The Heur.Mint.Autorunner.1 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.Autorunner.1 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Unusual version info supplied for binary

How to determine Heur.Mint.Autorunner.1 (B)?


File Info:

name: 198C7BC4CB9025F12075.mlw
path: /opt/CAPEv2/storage/binaries/b3ca5fce4938995090a0531db6b879ccff33900f1977f8ec0fe22ead7fbfaea1
crc32: DF66A5DB
md5: 198c7bc4cb9025f12075b990b1916d23
sha1: 2fb89cabb4c6bbea8614b8bd7df8e7740f86eba1
sha256: b3ca5fce4938995090a0531db6b879ccff33900f1977f8ec0fe22ead7fbfaea1
sha512: a8271896c9f421411133473cdcc6b802ed549d0e07f94ab180854071d3b7b4cf69eed27214d4032e90f9d9a5e2117dc3416b4eb50f91c65f28fa31e2f3750bd5
ssdeep: 12288:jKeKZ6454G2LYmIjE7SlGXd4OvXkLGHj0qTDzk4UP4w7oyXnZgS1MwvUaPVjk:mpw454G47gGmA0UTPS0ynSHwMaPS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2258B593EC0C072C19605F045ED86A48FB97C332921D38F7E8E66AA4F31BE19A76357
sha3_384: 339989c4570856c02ba54f17175fb4a0b2cf9cf7987ece4f25f07a349a8036e6caeabfa0b1dd7e7f844a6a60ab68dd83
ep_bytes: 68e0244000e8eeffffff000000000000
timestamp: 2007-08-17 12:43:04

Version Info:

Translation: 0x0804 0x04b0
Comments: Microsoft Firewall
CompanyName: Xiang Corporation
FileDescription: Microsoft Firewall
LegalCopyright: Microsoft
LegalTrademarks: Microsoft Firewall
ProductName: Microsoft Firewall
FileVersion: 1.00.0007
ProductVersion: 1.00.0007
InternalName: Firewall
OriginalFilename: Firewall.exe

Heur.Mint.Autorunner.1 (B) also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.AutoRun.m9NO
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Autorunner.1
FireEyeGeneric.mg.198c7bc4cb9025f1
SkyhighBehavesLike.Win32.Generic.dh
Cylanceunsafe
ZillyaWorm.AutoRun.Win32.180571
SangforWorm.Win32.VB.DiskBinder
K7AntiVirusVirus ( 0040f57d1 )
AlibabaWorm:Win32/AutoRun.447
K7GWVirus ( 0040f57d1 )
Cybereasonmalicious.4cb902
BitDefenderThetaGen:NN.ZevbaF.36802.8q3@aSOchTbb
VirITWin32.Vindor.A
SymantecW32.Pajetbin
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.NAR
APEXMalicious
TrendMicro-HouseCallWORM_AUTORUN.BTM
ClamAVWin.Worm.Vindor-9886047-0
KasperskyWorm.Win32.AutoRun.vx
BitDefenderGen:Heur.Mint.Autorunner.1
NANO-AntivirusTrojan.Win32.AutoRun.bqzoew
AvastWin32:WormX-gen [Wrm]
TencentWorm.Win32.AutoRun.acc
TACHYONBanker/W32.Banbra.Gen
EmsisoftGen:Heur.Mint.Autorunner.1 (B)
BaiduWin32.Trojan.VB.t
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.547
VIPREGen:Heur.Mint.Autorunner.1
TrendMicroWORM_AUTORUN.BTM
Trapminemalicious.high.ml.score
SophosW32/FakeFire-L
SentinelOneStatic AI – Malicious PE
JiangminWorm.AutoRun.bnt
VaristW32/Pajetbin.K1.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.AutoRun.nar
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Vindor.B
XcitiumWorm.Win32.VB.~HL@5500p
ArcabitTrojan.Mint.Autorunner.1
ZoneAlarmWorm.Win32.AutoRun.vx
GDataWin32.Worm.Pajetbin.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win.AutoRun.R453388
Acronissuspicious
McAfeeGenericRXVJ-MH!198C7BC4CB90
GoogleDetected
MAXmalware (ai score=83)
VBA32Worm.AutoRun
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/PJTbinder.A
RisingWorm.VB!1.DA3E (CLASSIC)
YandexTrojan.GenAsa!g8z8LT30jj4
IkarusTrojan.Autorun
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/AutoRun.RPV!worm
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Heur.Mint.Autorunner.1 (B)?

Heur.Mint.Autorunner.1 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment