Malware

Mint.Zard.5 malicious file

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: 767752F6B59FD6A60E4B.mlw
path: /opt/CAPEv2/storage/binaries/18523750c4f79fbaffdc1c9693ae8477043c0a45e5b18f43d59abd3e00057b20
crc32: 4110464D
md5: 767752f6b59fd6a60e4bd98565c64ddb
sha1: 9e4e98ead7512ea03544a79ba67fdcd18179b6ca
sha256: 18523750c4f79fbaffdc1c9693ae8477043c0a45e5b18f43d59abd3e00057b20
sha512: 296e165d9046307fa3c165e7f1b3597cba2c7e78478dfe00d166f8a2f03d8aeae440260179bf3684a604ae30d0157e5e3b342bbcadd54bcfcc0ba6d0a7cf7342
ssdeep: 24576:+1RiXKjgJQROcIfvTeaGlRM7iysTPeuRD0:eSJ/nTeaysN80
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11715BF3265604131F6F50573BA28D2306E7DEF282780D5AEE3D0BE1A3E74491A7B7693
sha3_384: 829062ccf8d7f77efd661f4670391c25b13b7bd3f4d906dd18fe4198d76a94851bdf60b393e428c010d306259af5116c
ep_bytes: e839050000e97afeffffcccccccc8b44
timestamp: 2021-09-23 03:54:08

Version Info:

CompanyName: Python Software Foundation
FileDescription: Python 3.11.0 (64-bit)
FileVersion: 3.11.150.0
InternalName: setup
LegalCopyright: Copyright (c) Python Software Foundation. All rights reserved.
OriginalFilename: python-3.11.0-amd64.exe
ProductName: Python 3.11.0 (64-bit)
ProductVersion: 3.11.150.0
Translation: 0x0409 0x04e4

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGeneric.mg.767752f6b59fd6a6
SkyhighBehavesLike.Win32.Backdoor.cc
McAfeeArtemis!767752F6B59F
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Patched.Vy41
K7AntiVirusTrojan ( 005ad28b1 )
AlibabaVirus:Win32/Senoval.28d5a80e
K7GWTrojan ( 005ad28b1 )
BitDefenderThetaGen:NN.ZexaF.36744.2y0@auQzBYpi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWW [Trj]
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Variant.Mint.Zard.5 (B)
F-SecureTrojan.TR/Patched.Gen
VIPREGen:Variant.Mint.Zard.5
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Agent
GDataGen:Variant.Mint.Zard.5
GoogleDetected
AviraTR/Patched.Gen
Antiy-AVLTrojan/Win32.Patched
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/Patched.GQ1.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5487854
VBA32BScope.TrojanDownloader.Emotet
ALYacGen:Variant.Mint.Zard.5
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.94 (RDML:eJLI6zMLSYo92EdoLKCCWA)
FortinetW32/Patched.IP!tr
AVGWin32:Patched-AWW [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment