Malware

Heur.Mint.Zard.35 (file analysis)

Malware Removal

The Heur.Mint.Zard.35 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.Zard.35 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes

Related domains:

maksaebali2.ddns.net
redirector.gvt1.com
r4—sn-4g5e6nzz.gvt1.com

How to determine Heur.Mint.Zard.35?


File Info:

crc32: 61941037
md5: 4844813436961a45964d1e348112f31a
name: 123.exe
sha1: dffd473941e6a0c8d8602c48ace9a58a005c5691
sha256: 7a74e50568ea6c113c29a3d14580fb2cd7d91d934dc3755bc56e582eab4c5c21
sha512: fca0161f6095723c0b9db8127306a6d1e94322914ea602e9ff10ed3e3563ba2c4c203fd47b0c4b5c3c27ff75adfb3429e11449f20ed7ff375122443347a7118c
ssdeep: 6144:mcNYk1yuwEDBum3qYWnl0pd0EX3Zq2b6wfIDYm0PHQ:mcWkbgTYWnYnt/IDYhP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Heur.Mint.Zard.35 also known as:

BkavW32.BitwanD.Trojan
MicroWorld-eScanGen:Heur.Mint.Zard.35
FireEyeGeneric.mg.4844813436961a45
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric.gj
CylanceUnsafe
ZillyaTrojan.Fynloski.Win32.742
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Heur.Mint.Zard.35
K7GWTrojan ( 004bc4d11 )
CrowdStrikewin/malicious_confidence_100% (D)
TrendMicroBKDR_FYNLOS.SMM
BaiduWin32.Backdoor.Agent.l
F-ProtW32/Fynloski.BA
SymantecBackdoor.Breut!gm
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.DarkKomet-1
GDataWin32.Trojan-Spy.DarkComet.J
KasperskyBackdoor.Win32.DarkKomet.gwbu
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
RisingBackdoor.Pontoeb!1.6637 (RDMK:cmRtazrlkmzfBWDkg1vC//S+bsh0)
Endgamemalicious (moderate confidence)
EmsisoftBackdoor.DarkKomet (A)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
VIPREBackdoor.Win32.Fynloski.A (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
MaxSecureBackdoor.W32.DarkKomet.aagr
Trapminemalicious.moderate.ml.score
CMCBackdoor.Win32.DarkKomet!O
SophosTroj/Fynlosk-AK
IkarusBackdoor.Win32.DarkKomet
CyrenW32/Fynloski.FWDO-2352
JiangminTrojan/Genome.bomw
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
MAXmalware (ai score=85)
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
ArcabitTrojan.Mint.Zard.35
SUPERAntiSpywareTrojan.Agent/Gen-Delf
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
BitDefenderThetaAI:Packer.AC3F6FA81C
ALYacGen:Heur.Mint.Zard.35
TACHYONBackdoor/W32.DP-DarkKomet.674816.B
VBA32Backdoor.Tordev
MalwarebytesBackdoor.Packed.DK
PandaTrj/Genetic.gen
ZonerTrojan.Win32.29578
ESET-NOD32a variant of Win32/Fynloski.AN
TrendMicro-HouseCallBKDR_FYNLOS.SMM
TencentBackdoor.Win32.DarkKomet.zem
YandexTrojan.Comet.Gen.LO
SentinelOneDFI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.DB56!tr
Ad-AwareGen:Heur.Mint.Zard.35
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.436961
Qihoo-360HEUR/QVM11.1.D019.Malware.Gen

How to remove Heur.Mint.Zard.35?

Heur.Mint.Zard.35 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment