Malware

Heur.Mint.Porcupine.fmKfau1QFHobg removal instruction

Malware Removal

The Heur.Mint.Porcupine.fmKfau1QFHobg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.Porcupine.fmKfau1QFHobg virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (10 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking

Related domains:

www.baidu.com
ossweb-img.qq.com
www.easyicon.net
www.bccn.net
sdk.51.la
widget.angelfz.com
vip.d0.baidupan.com
dev34.baidupan.com

How to determine Heur.Mint.Porcupine.fmKfau1QFHobg?


File Info:

crc32: F2441ADA
md5: b50b5a17f283e79a2f69d4aa7fb405d6
name: B50B5A17F283E79A2F69D4AA7FB405D6.mlw
sha1: ef0b759a20a596757efca63c6ffdb28df75695e0
sha256: 81d0d68f4dce6c44cad7ea067aeccf5510b5f9d03d446bc2e2ccafd9f0a968e1
sha512: cc9c797c8d9e4e9a3ac5a68c5ae346e97daf432a0a46dcfe1b4ca6db9a8f65fb75ffb2283d6bc77a032c81fcd2e77bb331e214eb92ee24e1740c3bc1fc59c60d
ssdeep: 1536:vTn6jq4LVUAokbrzv+2VhC2HCKCqZXc3ibZFvOEMnouy8Rj:b+vTbhxCyMSbZFmfout9
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: QQ337855632
FileVersion: 1.0.0.0
CompanyName: QQ337855632
Comments: x98dex8f66x8f85x52a9
ProductName: x98dex8f66x8f85x52a9
ProductVersion: 1.0.0.0
FileDescription: QQx98dex8f66x767dx5ad6x8f85x52a9
Translation: 0x0804 0x04b0

Heur.Mint.Porcupine.fmKfau1QFHobg also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005328801 )
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.68
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Kilonepag.25975
ALYacGen:Heur.Mint.Porcupine.fmKfau1QFHobg
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Invader.7b2eec0a
K7GWTrojan ( 005328801 )
Cybereasonmalicious.7f283e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BBYK
APEXMalicious
AvastWin32:Dh-A [Heur]
KasperskyHEUR:Trojan.Win32.Invader
BitDefenderGen:Heur.Mint.Porcupine.fmKfau1QFHobg
MicroWorld-eScanGen:Heur.Mint.Porcupine.fmKfau1QFHobg
Ad-AwareGen:Heur.Mint.Porcupine.fmKfau1QFHobg
SophosGeneric ML PUA (PUA)
BitDefenderThetaAI:Packer.5334A4231F
TrendMicroTROJ_GEN.R005C0WES21
McAfee-GW-EditionBehavesLike.Win32.Trojan.mc
FireEyeGeneric.mg.b50b5a17f283e79a
EmsisoftGen:Heur.Mint.Porcupine.fmKfau1QFHobg (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Hijacker.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Mint.Porcupine.fmKfau1QFHobg
GDataGen:Heur.Mint.Porcupine.fmKfau1QFHobg
AhnLab-V3Trojan/Win.Generic.C4498457
McAfeeArtemis!B50B5A17F283
MAXmalware (ai score=87)
VBA32Malware-Cryptor.Inject.gen
MalwarebytesMalware.AI.1867582213
TrendMicro-HouseCallTROJ_GEN.R005C0WES21
YandexTrojan.GenAsa!kCz5PKmzQNc
IkarusAdWare.Win32.BlackMoon
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.BBYK!tr
AVGWin32:Dh-A [Heur]
Paloaltogeneric.ml

How to remove Heur.Mint.Porcupine.fmKfau1QFHobg?

Heur.Mint.Porcupine.fmKfau1QFHobg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment