Malware

Heur.Mint.Zard.35 (B) removal instruction

Malware Removal

The Heur.Mint.Zard.35 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.Zard.35 (B) virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Heur.Mint.Zard.35 (B)?


File Info:

crc32: D6C73A6F
md5: 4ae797a84a33b3700328e5f02e8c76b5
name: sukablat.scr
sha1: 7e87df292e83f1a887c3c5ea7e2ad50a4b830e8f
sha256: 95eba4263d159c4840056d23a5eac32aa801acec88b1c243107751dcb4e74ae2
sha512: ec2b39514fa93577e8c768e1add6e73107f83b855aacc962faedddce7b6fce07d46360c835830671abe6e4a87ed736823c266c7e32e469bfeccf95b5f63952c1
ssdeep: 6144:BcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PD:BcWkbgTYWnYnt/IDYhP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Heur.Mint.Zard.35 (B) also known as:

BkavW32.BitwanD.Trojan
MicroWorld-eScanGen:Heur.Mint.Zard.35
CMCBackdoor.Win32.DarkKomet!O
ALYacGen:Heur.Mint.Zard.35
CylanceUnsafe
ZillyaTrojan.Fynloski.Win32.742
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Heur.Mint.Zard.35
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.84a33b
TrendMicroBKDR_FYNLOS.SMM
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Fynloski.BA
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
ClamAVWin.Trojan.DarkKomet-1
GDataWin32.Trojan-Spy.DarkComet.J
KasperskyBackdoor.Win32.DarkKomet.gwbu
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
TencentBackdoor.Win32.DarkKomet.zem
Ad-AwareGen:Heur.Mint.Zard.35
EmsisoftGen:Heur.Mint.Zard.35 (B)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
VIPREBackdoor.Win32.Fynloski.A (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
MaxSecureBackdoor.W32.DarkKomet.aagr
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.4ae797a84a33b370
SophosTroj/Fynlosk-AK
SentinelOneDFI – Malicious PE
CyrenW32/Fynloski.FWDO-2352
JiangminTrojan/Genome.bomw
AviraBDS/Backdoor.Gen
Endgamemalicious (moderate confidence)
ArcabitTrojan.Mint.Zard.35
SUPERAntiSpywareBackdoor.Fynloski/Variant
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
TACHYONBackdoor/W32.DP-DarkKomet.674304.B
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
McAfeeGeneric.gj
MAXmalware (ai score=86)
VBA32Backdoor.Tordev
MalwarebytesBackdoor.Packed.DK
PandaTrj/Genetic.gen
ZonerTrojan.Win32.88734
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazr/8HiVnY/R1mMIZUUHSlIU)
YandexTrojan.Comet.Gen.LO
IkarusBackdoor.Win32.DarkKomet
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
BitDefenderThetaAI:Packer.E525F1FD1C
AVGMSIL:GenMalicious-CHX [Trj]
AvastMSIL:GenMalicious-CHX [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM11.1.E0C2.Malware.Gen

How to remove Heur.Mint.Zard.35 (B)?

Heur.Mint.Zard.35 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment