Malware

Heur.Mint.Zard.40 malicious file

Malware Removal

The Heur.Mint.Zard.40 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Mint.Zard.40 virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes

Related domains:

tvinky.ddns.net

How to determine Heur.Mint.Zard.40?


File Info:

crc32: D412DBA6
md5: 0ff29b69d35e90def532d1131eddaf78
name: 0FF29B69D35E90DEF532D1131EDDAF78.mlw
sha1: 28024d4cdbec6c77b14788662e66933bedff8cd7
sha256: 78f238d4d7a071b5bf3a4f956a1ad26bed53df57ceb2174c8d12122499cad28f
sha512: 194da7f5fb7312f99733b18f6e72844e3650b7e0054a1975beae48d45d9867132be51aa5597f05f5cee9a2e6bc9360b4f8edcdc3bd01287e2e87064deab64f21
ssdeep: 6144:rcNYk1yuwEDBum3qIWnl0pd0EX3Zq2b6wfIDYm0PHQ:rcWkbgTIWnYnt/IDYhP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Heur.Mint.Zard.40 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.40
FireEyeGeneric.mg.0ff29b69d35e90de
CAT-QuickHealBackdoor.Fynloski.A9
McAfeeGeneric.gj
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
SangforMalware
K7AntiVirusTrojan ( 004bc4d11 )
BitDefenderGen:Heur.Mint.Zard.40
K7GWTrojan ( 004bc4d11 )
Cybereasonmalicious.9d35e9
InvinceaML/PE-A + Troj/Fynlosk-AK
BaiduWin32.Backdoor.Agent.l
CyrenW32/Darkkomet.A.gen!Eldorado
SymantecBackdoor.Breut!gm
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.DarkKomet-1
KasperskyBackdoor.Win32.DarkKomet.gwbu
NANO-AntivirusTrojan.Win32.Tordev.dgnepn
RisingWorm.Soltern!8.1B8 (TFE:3:9sFNK6eeaiK)
Ad-AwareGen:Heur.Mint.Zard.40
EmsisoftTrojan.Fynloski (A)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Tordev.9
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
MaxSecureBackdoor.W32.DarkKomet.aagr
SophosTroj/Fynlosk-AK
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Genome.bomw
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
MAXmalware (ai score=83)
MicrosoftVirTool:Win32/CeeInject.AJJ!bit
GridinsoftBackdoor.Win32.Fynloski.zv!n
ArcabitTrojan.Mint.Zard.40
SUPERAntiSpywareTrojan.Agent/Gen-Delf
ZoneAlarmBackdoor.Win32.DarkKomet.gwbu
GDataWin32.Trojan-Spy.DarkComet.J
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacGen:Heur.Mint.Zard.40
TACHYONBackdoor/W32.DarkKomet.257536.K
MalwarebytesBackdoor.Packed.DK
PandaTrj/Genetic.gen
ZonerTrojan.Win32.29578
ESET-NOD32a variant of Win32/Fynloski.AN
YandexTrojan.Comet.Gen.LO
IkarusBackdoor.Win32.DarkKomet
eGambitUnsafe.AI_Score_100%
FortinetW32/Generic.AC.DB56!tr
BitDefenderThetaAI:Packer.0F02E2241C
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM18.1.4BAF.Malware.Gen

How to remove Heur.Mint.Zard.40?

Heur.Mint.Zard.40 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment