Malware

Heur.Mint.Dreidel.fi0axSwnbbli removal instruction

Malware Removal

The Heur.Mint.Dreidel.fi0axSwnbbli is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.Dreidel.fi0axSwnbbli virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Heur.Mint.Dreidel.fi0axSwnbbli?


File Info:

crc32: CB5A5463
md5: 81b66ddd353cf734af955dacbade78a6
name: 81B66DDD353CF734AF955DACBADE78A6.mlw
sha1: 2ab810c9c8e4e1d6d4e069e2196b8ff90251d384
sha256: 0dead9f7ef8378d075caf9039b46e9c220cc5d823a6a1bab85923d3543d79342
sha512: a94924982f9c28e8b616e9c5dc385e1ff8a4f511bb0c38f7350c0b8fa85f8c0a608a859d1aca01339ba58c2f9d04b1f68a20f7b9d5a39d20f123d77847fc9c89
ssdeep: 1536:1NI52jD8FO9Brj9Fp/rso9Ooh12Fv73hEIhNKiZN8XF0O:1NI52XQo3pjV9d32FzxEuNdN8XF0
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

FileVersion: 7.1
CompanyName: TrueCrypt Foundation
LegalTrademarks: TrueCrypt
ProductName: TrueCrypt
ProductVersion: 7.1
FileDescription: TrueCrypt Setup
OriginalFilename: TrueCrypt Setup.exe
Translation: 0x0409 0x04b0

Heur.Mint.Dreidel.fi0axSwnbbli also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e4091 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop3.17446
CynetMalicious (score: 100)
McAfeeGenericR-KJJ!81B66DDD353C
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.158572
SangforSuspicious.Win32.Dreidel.fi0awSwnbbli
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/LockScreen.bdc6742d
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.d353cf
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.AIG
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
ClamAVWin.Trojan.Vbkrypt-25665
KasperskyWorm.Win32.WBNA.bul
BitDefenderGen:Heur.Mint.Dreidel.fi0axSwnbbli
NANO-AntivirusTrojan.Win32.VBKrypt.nceig
MicroWorld-eScanGen:Heur.Mint.Dreidel.fi0axSwnbbli
TencentWin32.Worm.Wbna.Eadi
Ad-AwareGen:Heur.Mint.Dreidel.fi0axSwnbbli
SophosMal/Generic-S + Mal/Generic-L
ComodoMalware@#3g0kdj14h581a
BitDefenderThetaGen:NN.ZexaF.34608.fi0aaSwnbbli
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
FireEyeGen:Heur.Mint.Dreidel.fi0axSwnbbli
EmsisoftGen:Heur.Mint.Dreidel.fi0axSwnbbli (B)
WebrootW32.Trojan.Gen
AviraTR/Dropper.VB.Gen
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftRansom:Win32/Genasom
AegisLabTrojan.Win32.VBKrypt.4!c
GDataGen:Heur.Mint.Dreidel.fi0axSwnbbli
AhnLab-V3Trojan/Win32.Bifrose.C110110
VBA32TScope.Trojan.VB
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1001
PandaGeneric Malware
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.VBKrypt!i/VvwiCf/Sg
IkarusTrojan.Win32.Spy
FortinetW32/VBKrypt.AIG!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
Qihoo-360Win32/Worm.Vobfus.HxMByBAA

How to remove Heur.Mint.Dreidel.fi0axSwnbbli?

Heur.Mint.Dreidel.fi0axSwnbbli removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment