Malware

Mint.Zard.5 removal

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: CCD0E21718DCB2B20C0F.mlw
path: /opt/CAPEv2/storage/binaries/e65763c03b4780269040a98efa5cbc4f5152ae2e59d86c742f53768884df3f54
crc32: 690DACF4
md5: ccd0e21718dcb2b20c0ffe5c1ea0e776
sha1: e4ca096ca8954c0a47bcd7395ac7dce1fed1198f
sha256: e65763c03b4780269040a98efa5cbc4f5152ae2e59d86c742f53768884df3f54
sha512: ac68e1f286087c5baeb0bd23fbf80c31fb0b24b294a006bbb20a13dd647173d194e2ca9ef185e117ee530ea32a86ff78ddbbb5a03ca069146ca0d4043c5ba180
ssdeep: 24576:WVN6uqrLj7s1MNNcgqx8fT4zDa14kiTxkornl+APwrvL43kUjhB9L0CVdCtt8KcN:W36uqPXhNNcgqx8fT4aNorn8AozLYkUt
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T14955AE15F7F5C4B4C98E45308A29ABF500F8E71DCA2068C76B90FF6E6F328D5D229949
sha3_384: b05868512787bdb02e469e64bb158287ef1544a6ee3e8dd55e0bfda113e6a6db202ff51c662c3df4fd8b91fdddc45059
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2018-12-29 23:28:59

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Plugin
FileVersion: 18.06
InternalName: 7z
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7z.dll
ProductName: 7-Zip
ProductVersion: 18.06
Translation: 0x0409 0x04b0

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGen:Variant.Mint.Zard.5
SkyhighBehavesLike.Win32.Qakbot.tc
ALYacGen:Variant.Mint.Zard.5
Cylanceunsafe
SangforTrojan.Win32.Patched.Vrsh
AlibabaVirus:Win32/Senoval.16994f98
ArcabitTrojan.Mint.Zard.5
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
AvastWin32:Patched-AWW [Trj]
RisingTrojan.Generic@AI.100 (RDML:gAWf39sX+nW6r/vzFqAofA)
EmsisoftGen:Variant.Mint.Zard.5 (B)
SophosMal/Generic-S
IkarusTrojan.Win32.Patched
GoogleDetected
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmVirus.Win32.Senoval.a
GDataGen:Variant.Mint.Zard.5
VaristW32/S-4eb225e0!Eldorado
AhnLab-V3Dropper/Win.Generic.C5483017
McAfeeArtemis!CCD0E21718DC
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentTrojan.Win32.Pathced_ya.16001052
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IP!tr
AVGWin32:Patched-AWW [Trj]
DeepInstinctMALICIOUS

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment