Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

Mint.Zard.5 removal tips

Published Feb 21, 2024 Malware category 3 min read
Report context

What to verify before removal

This report keeps Mint.Zard.5 removal tips in the active library because the detection has enough technical context to support a careful second-opinion scan and cleanup decision.

Start by comparing the local file name with C9C7F4D075F8245B8080.mlw, then review the behavior notes for persistence entries, dropped files, unusual processes, and browser or network changes. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
C9C7F4D075F8245B8080.mlw
  • Compare the suspicious file name with C9C7F4D075F8245B8080.mlw.
  • Confirm the detection name matches Mint.Zard.5 removal tips before removing related files.
  • Review the report for persistence entries, dropped files, unusual processes, and browser or network changes so the cleanup is based on observed behavior, not only the label.
  • Run a full scan, quarantine confirmed detections, and restart before signing back in to sensitive accounts.

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: C9C7F4D075F8245B8080.mlw
path: /opt/CAPEv2/storage/binaries/d210715b0f9b529f818c1de36ad01b86e2d89a2dc83a2b1eda43b63bbe57e8b5
crc32: 293AAA4A
md5: c9c7f4d075f8245b808035b3c7b2f8a2
sha1: 3f58f716b4926497309ae1278f97f074fc82f46e
sha256: d210715b0f9b529f818c1de36ad01b86e2d89a2dc83a2b1eda43b63bbe57e8b5
sha512: f36a8dbd89076deef857dbe788fe21be92d4ff60ebf37141d30b644825dc3f660f49720ca96a67b1398505dc2afe57e1c05c907433bb1c6172d921bb690e6dab
ssdeep: 24576:4SSSO+Gp3/eO4hJ3GinFzaMvVSUqu00Wq8w:lO5zSJ3LJSU4qr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B159F32A5904022E7F102B7BE64D130BE2CAF241754C47EE3D4FD1E6ABD4926BB7256
sha3_384: 0204d4da0123eabb2927061f00b562425f544b814a28c094b43539c19558e8ee29a3bc9ea561b3397d2511d302ed6994
ep_bytes: e81a050000e98efeffff8b4424088b4c
timestamp: 2017-11-18 18:06:49

Version Info:

CompanyName: Python Software Foundation
FileDescription: Python 3.9.2 (64-bit)
FileVersion: 3.9.2150.0
InternalName: setup
LegalCopyright: Copyright (c) Python Software Foundation. All rights reserved.
OriginalFilename: python-3.9.2-amd64.exe
ProductName: Python 3.9.2 (64-bit)
ProductVersion: 3.9.2150.0
Translation: 0x0409 0x04e4

Mint.Zard.5 also known as:

Bkav W32.AIDetectMalware
DrWeb Win32.Beetle.2
MicroWorld-eScan Gen:Variant.Mint.Zard.5
FireEye Generic.mg.c9c7f4d075f8245b
Skyhigh BehavesLike.Win32.Backdoor.cc
McAfee Artemis!C9C7F4D075F8
Cylance unsafe
Zillya Trojan.Convagent.Win32.92980
Sangfor Trojan.Win32.Patched.V5z8
K7AntiVirus Trojan ( 005ad28b1 )
Alibaba Virus:Win32/Senoval.30828770
K7GW Trojan ( 005ad28b1 )
BitDefenderTheta AI:Packer.48B88AFD1F
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Patched.NKM
Kaspersky Virus.Win32.Senoval.a
BitDefender Gen:Variant.Mint.Zard.5
NANO-Antivirus Virus.Win32.Gen-Crypt.ccnc
Avast Win32:Patched-AWW [Trj]
Tencent Trojan.Win32.Pathced_ya.16001052
Emsisoft Gen:Variant.Mint.Zard.5 (B)
F-Secure Trojan.TR/Patched.Gen
VIPRE Gen:Variant.Mint.Zard.5
Trapmine malicious.moderate.ml.score
SentinelOne Static AI – Suspicious PE
GData Win32.Trojan.PSE.12WYU30
Google Detected
Avira TR/Patched.Gen
Varist W32/Convagent.DP.gen!Eldorado
Antiy-AVL Trojan[Backdoor]/Win32.Convagent
Arcabit Trojan.Mint.Zard.5
ZoneAlarm Virus.Win32.Senoval.a
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C5481517
VBA32 BScope.TrojanDownloader.Emotet
ALYac Gen:Variant.Mint.Zard.5
MAX malware (ai score=89)
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Genetic.gen
Rising Trojan.Generic@AI.97 (RDML:9GPFp+2RMPunHx9KKdcpTA)
Ikarus Trojan.Win32.Patched
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Patched.IP!tr
AVG Win32:Patched-AWW [Trj]

How to remove Mint.Zard.5?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.