Malware

Mint.Zard.5 removal guide

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: D80A2D975C09929B2112.mlw
path: /opt/CAPEv2/storage/binaries/d3506782522216f5261ee22ab13e0d00e235b019a2b83a168b43e6ee5449f758
crc32: EE837C9A
md5: d80a2d975c09929b21123083a6c3b2d3
sha1: a2bd8862c9f227dfd09b16b532829ead386cac4d
sha256: d3506782522216f5261ee22ab13e0d00e235b019a2b83a168b43e6ee5449f758
sha512: 3543c323d2204cd0d366fa9ec5e39fab310e13e3dbeededdb912f1b725dfec721cd6b6e23bcd4e4641cbb9d1ba41af3c62487c8c24c322cc7c7169f1dd1d2ffe
ssdeep: 6144:ZvghJFHbhYgThFyOfwHYY7u9R9S50cxtYbqZ20Kf2HMh64VYJcbTtSX0:ZYhJFHbhYLYY7E9S5Dxqp0IqQ6NU00
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17974CF1EF76500F6C08F72B10578826CEB6E5C30667A7ECA2B1AFA345A323919D1771D
sha3_384: da7fdea8e02578cc064d88278ac7bd2b1cae4235a7178ef8b2efbaa4f7229b2b56560cb54c95c8107f64d9700069f8bb
ep_bytes: e83e600000e989feffff8bff558bec81
timestamp: 2022-08-06 21:52:35

Version Info:

CompanyName: Simple Launcher User
FileDescription: Simple Launcher Executable
FileVersion: 1.1.0.14
InternalName: w32.exe
LegalCopyright: Copyright (C) Simple Launcher User
OriginalFilename: w32.exe
ProductName: Simple Launcher
ProductVersion: 1.1.0.14
Translation: 0x0409 0x04b0

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGeneric.mg.d80a2d975c09929b
SkyhighBehavesLike.Win32.Generic.fc
ALYacGen:Variant.Mint.Zard.5
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005ab4bf1 )
AlibabaTrojan:Win32/Senoval.2bf33206
K7GWTrojan ( 005ab4bf1 )
Cybereasonmalicious.2c9f22
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
EmsisoftGen:Variant.Mint.Zard.5 (B)
F-SecureTrojan.TR/Patched.Gen
VIPREGen:Variant.Mint.Zard.5
Trapminemalicious.high.ml.score
SophosW32/Patched-CD
GDataWin32.Trojan.PSE.16VFYLR
VaristW32/Patched.GQ1.gen!Eldorado
AviraTR/Patched.Gen
Antiy-AVLTrojan/Win32.Patched
KingsoftWin32.Infected.AutoInfector.a
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
MicrosoftTrojan:Win32/Doina.RPX!MTB
GoogleDetected
McAfeeArtemis!D80A2D975C09
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Meterpreter
MalwarebytesGeneric.Malware/Suspicious
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Patched.IP!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment