Malware

Mint.Zard.5 information

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: 8A7DD2FF8CF1733E48B2.mlw
path: /opt/CAPEv2/storage/binaries/89486d75255ad6fe7330755972dc3ac623cc36978b38b0ecd677e1dfd5da04d7
crc32: 5023D892
md5: 8a7dd2ff8cf1733e48b24e81bd8abb25
sha1: 5b9ad6cd128cb6e9daa5d0d9a54c4553678e750f
sha256: 89486d75255ad6fe7330755972dc3ac623cc36978b38b0ecd677e1dfd5da04d7
sha512: 90d9d06bc2cfc70bd4de2f291e10d018e6d0c106d33cdd5ab2e527aa0189cf7e9ba985d9720fab7df7503997ff36ec7d3b82dab5fe320f6ad4cb71cd1ba90b66
ssdeep: 24576:z/+luLVRg7pTpuWN+5ElTlC/zpNzokiTxMJrnl+A3wrvL4rkUjhB9G5tv8av:zmluL30YWN+5ElTlCVNfJrn8AAzLkkUt
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T10E65AF15F7F1C4B4C98E46308A2DABB510E8E71DCA1058C76B80FEAE6F32CD5D239959
sha3_384: 8599593267b81b1240153bda03277a0ef87629c94ffa3b89139e2a16dc6e1901f756022f369287181c40d5940e30cd21
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2018-12-30 10:36:43

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Plugin
FileVersion: 18.06
InternalName: 7z
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7z.dll
ProductName: 7-Zip
ProductVersion: 18.06
Translation: 0x0409 0x04b0

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Mint.Zard.5
SkyhighBehavesLike.Win32.Qakbot.tc
McAfeeArtemis!8A7DD2FF8CF1
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Patched.Win32.176329
SangforTrojan.Win32.Patched.Vei1
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
AvastWin32:Patched-AWW [Trj]
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Variant.Mint.Zard.5 (B)
VIPREGen:Variant.Mint.Zard.5
FireEyeGen:Variant.Mint.Zard.5
SophosMal/Generic-S
GoogleDetected
Antiy-AVLGrayWare/Win32.Wacapew
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
GDataGen:Variant.Mint.Zard.5
VaristW32/S-4eb225e0!Eldorado
AhnLab-V3Dropper/Win.Generic.C5483017
ALYacGen:Variant.Mint.Zard.5
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:EtwZyg3+ytEyrLIZsVi+Wg)
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IP!tr
AVGWin32:Patched-AWW [Trj]
DeepInstinctMALICIOUS

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment