Malware

How to remove “Heur.Mint.Titirez.hmGfJOzx6wkG”?

Malware Removal

The Heur.Mint.Titirez.hmGfJOzx6wkG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.Titirez.hmGfJOzx6wkG virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Polish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Heur.Mint.Titirez.hmGfJOzx6wkG?


File Info:

name: 3035C54E914FEA4C8EDD.mlw
path: /opt/CAPEv2/storage/binaries/7ea33d9150bac66d5df7c4df52defd306e031f6d6854f71414f3cb03d0e90246
crc32: 46F56507
md5: 3035c54e914fea4c8eddcc6fef930be5
sha1: 727b4c12d6be8aca9e837b54b8ba2a2b49a372e1
sha256: 7ea33d9150bac66d5df7c4df52defd306e031f6d6854f71414f3cb03d0e90246
sha512: 3616962080c683bb8aeeae21701f861cceddd245da47fa146a618ec16ce4e38cf3cc813ebc4772d3578a9a600c76b9b4b1abc3fd1a53040c5d6ae6748ba74a0b
ssdeep: 3072:xSfgB3mKLHmkpfFaHUqVdFWZD2NSmkqOKe/lr:IopmMFpdfYu2Ndtol
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165B3DF0178ACD619D6A76E32583556B106B3FDD7EA0041CFF6887F5BEC726800A72B23
sha3_384: a1a561935b20177f0cf9fb5b8a758bb0d60847cda2751c4318144750d02c68bd9cb320a437c802c342ecde5bee400194
ep_bytes: 60be00b080008dbe0060bfff5783cdff
timestamp: 2020-02-02 02:00:46

Version Info:

FileVerus: 1.0.2.28
ProductVersys: 1.5.8.29
Translations: 0x0126 0x0276

Heur.Mint.Titirez.hmGfJOzx6wkG also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader38.15246
MicroWorld-eScanGen:Heur.Mint.Titirez.hmGfJOzx6wkG
FireEyeGeneric.mg.3035c54e914fea4c
CAT-QuickHealTrojan.ChapakPMF.S19689934
McAfeePacked-GDK!1C42D5CF176C
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.e914fe
BitDefenderThetaAI:Packer.06F67A6320
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKDV
BitDefenderGen:Heur.Mint.Titirez.hmGfJOzx6wkG
NANO-AntivirusTrojan.Win32.Nekark.itlwha
AvastWin32:PWSX-gen [Trj]
Ad-AwareGen:Heur.Mint.Titirez.hmGfJOzx6wkG
EmsisoftGen:Heur.Mint.Titirez.hmGfJOzx6wkG (B)
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
IkarusTrojan-Banker.UrSnif
GDataGen:Heur.Mint.Titirez.hmGfJOzx6wkG
JiangminTrojan.Agent.dfjp
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1102737
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.323F441
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32Backdoor.Agent
ALYacGen:Heur.Mint.Titirez.hmGfJOzx6wkG
MalwarebytesTrojan.MalPack.GS
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HKDZ!tr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Heur.Mint.Titirez.hmGfJOzx6wkG?

Heur.Mint.Titirez.hmGfJOzx6wkG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment