Malware

Heur.Mint.Murphy.57 removal tips

Malware Removal

The Heur.Mint.Murphy.57 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.Murphy.57 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

How to determine Heur.Mint.Murphy.57?


File Info:

name: 8298BB2923A3E276DA35.mlw
path: /opt/CAPEv2/storage/binaries/6ea19883766e9b296a507418336f845d5e6603948438daebd14e9b7d43ac9b85
crc32: 13DDD6D1
md5: 8298bb2923a3e276da3533d380f700fb
sha1: 9abc14162d25cc7fa4c12ecd2f9404276b48f08f
sha256: 6ea19883766e9b296a507418336f845d5e6603948438daebd14e9b7d43ac9b85
sha512: 06ec4cc472a4448809e7acd6422195ba32f95a6e5c2ea47e815421433f2263f73225f85acb26eb441bfc0d4c4982204458d2fab5ea2c62cc600a6aa0ef563a73
ssdeep: 49152:/1s0E21GeA8lx2xISLEuDMQnsfyUEHTgk8:/1LEOGeGn6Y8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AC54C13BA88523AD0661E3A4CB79650E83F79602A159C4B2FE41F5C1F3E6407E3BE57
sha3_384: ab184cf209039e37b63f557a99afbfbd3ba9492956d292a6345adfb8af32e36c3e4ff8a22ae2f7005db2954833410a91
ep_bytes: 558bec83c4f0b87ce95d00e8ec15e2ff
timestamp: 2020-11-15 09:58:07

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Heur.Mint.Murphy.57 also known as:

LionicTrojan.Win32.Murphy.4!c
MicroWorld-eScanGen:Heur.Mint.Murphy.57
ALYacGen:Heur.Mint.Murphy.57
CylanceUnsafe
VIPREGen:Heur.Mint.Murphy.57
K7AntiVirusTrojan ( 0052f6241 )
AlibabaTrojanDownloader:Win32/Banload.398e5cda
K7GWTrojan ( 0052f6241 )
Cybereasonmalicious.923a3e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.TXE
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Banload.gen
BitDefenderGen:Heur.Mint.Murphy.57
AvastWin32:Malware-gen
RisingDownloader.Banload!8.15B (CLOUD)
Ad-AwareGen:Heur.Mint.Murphy.57
EmsisoftGen:Heur.Mint.Murphy.57 (B)
TrendMicroTROJ_GEN.R002C0WH422
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
FireEyeGen:Heur.Mint.Murphy.57
SophosMal/Generic-S
IkarusTrojan.Win32.Delf
GDataGen:Heur.Mint.Murphy.57
JiangminTrojanDownloader.Banload.btcj
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.F0
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win.Generic.C5219956
McAfeeArtemis!8298BB2923A3
VBA32BScope.Trojan.Bitrep
TrendMicro-HouseCallTROJ_GEN.R002C0WH422
TencentWin32.Trojan-downloader.Banload.Dzto
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.TXE!tr
BitDefenderThetaAI:Packer.71EB8D9C19
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Heur.Mint.Murphy.57?

Heur.Mint.Murphy.57 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment