Malware

Mint.Zard.5 malicious file

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: 9B6174B5A757234F0830.mlw
path: /opt/CAPEv2/storage/binaries/b8ef84cb5824dc56f4410f8d995dccad9154758bee9654606fc82b71db2261e1
crc32: 7B41B722
md5: 9b6174b5a757234f08301080aa0521a9
sha1: d3733a3fd2807a5e8eb4ad6ff94b80b983ee7e3d
sha256: b8ef84cb5824dc56f4410f8d995dccad9154758bee9654606fc82b71db2261e1
sha512: 57a931f7c1ad7e9089e1822084c917a0b016d4e989575046d4fed902796927423197370a3961397446e79891ed95fa2203796e9392d5b754ed3b78a0cbd94874
ssdeep: 24576:1Yhs1XpqJRnA+y0Pk0ccGyjWL0yXkiT/nsrnl+A3wrvL47kUjhB9XhomUOJ/1:1Cs1XU/5y0Pk0ccGyU0usrn8AAzLIkUd
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T16455AE11F7F5C4B4C98E46308A29ABF510F8E719CA10A8C76B80FE6F6F32CD5D225959
sha3_384: 732af630416261a550829d4911da270ea9bb7fdd3d4f08078851f60e53356141ed659228a7865ce8a59293741cea9bda
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2018-12-30 08:54:44

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Plugin
FileVersion: 18.06
InternalName: 7z
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7z.dll
ProductName: 7-Zip
ProductVersion: 18.06
Translation: 0x0409 0x04b0

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGen:Variant.Mint.Zard.5
SkyhighBehavesLike.Win32.Qakbot.tc
McAfeeArtemis!9B6174B5A757
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Mint.Zard.5
SangforTrojan.Win32.Agent.Venr
BitDefenderGen:Variant.Mint.Zard.5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
AlibabaTrojan:Win32/DropperX.b493a1b1
RisingTrojan.Generic@AI.100 (RDML:3q5XW+JhdOaRetr94wLaBQ)
ZillyaTrojan.Patched.Win32.170801
EmsisoftGen:Variant.Mint.Zard.5 (B)
IkarusTrojan.Win32.Patched
GDataGen:Variant.Mint.Zard.5
GoogleDetected
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/S-4eb225e0!Eldorado
AhnLab-V3Dropper/Win.Generic.C5483017
ALYacGen:Variant.Mint.Zard.5
MAXmalware (ai score=88)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H09I523
TencentTrojan.Win32.Pathced_ya.16001052
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IP!tr
AVGWin32:Patched-AWX [Trj]
AvastWin32:Patched-AWX [Trj]

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment