Malware

About “Mint.Zard.5” infection

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: CFA217F6BB37418ABD9B.mlw
path: /opt/CAPEv2/storage/binaries/c03194c0977f32af1e01ebedf3487d8a70a3541a50cfd7e2b7b9be81272fccf3
crc32: 26A38BB1
md5: cfa217f6bb37418abd9bd2672bb9016c
sha1: e70f2ea1f2041e93fab52a8def563ce1c779c915
sha256: c03194c0977f32af1e01ebedf3487d8a70a3541a50cfd7e2b7b9be81272fccf3
sha512: dd3ca6daf9f4a4081bdb906e61b8e8ca197183c48a4b0172498ba04c247704ba6f83761ddd744e5d31d278a7da224e06acb2d0497979621a4bda5b9d51aa316d
ssdeep: 12288:T0C0CmIS4cipxGQvuZw1/AtC/1b4ez2+Biw:T2x1pimQvua1/AM/1co2+Bi
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15CB4BE027BF8C476D34341338A59AFD6A0FAA29A4D61484367C41E5DFE32DD6D334B2A
sha3_384: 3e13763ad96497f953965a75891770899de8d9fc07731cba2cae31d8b4ec85519c98415649f8d874841d96c2e07216c2
ep_bytes: 558bec6aff6840ce430068b03d430064
timestamp: 2018-12-29 23:36:58

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7-Zip Console
FileVersion: 18.06
InternalName: 7z
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7z.exe
ProductName: 7-Zip
ProductVersion: 18.06
Translation: 0x0409 0x04b0

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGeneric.mg.cfa217f6bb37418a
CAT-QuickHealTrojan.InjukePMF.S31351714
SkyhighBehavesLike.Win32.Generic.hc
McAfeeArtemis!CFA217F6BB37
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
AlibabaVirus:Win32/Senoval.98653f75
BitDefenderThetaGen:NN.ZexaF.36744.Gy0@aim8qZki
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWW [Trj]
RisingTrojan.Generic@AI.100 (RDML:y9lwdlr7mLSw/nyZzZnvqQ)
EmsisoftGen:Variant.Mint.Zard.5 (B)
F-SecureHeuristic.HEUR/AGEN.1369791
VIPREGen:Variant.Mint.Zard.5
Trapminesuspicious.low.ml.score
GDataGen:Variant.Mint.Zard.5
GoogleDetected
AviraHEUR/AGEN.1369791
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/Injuke.BI.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R606966
ALYacGen:Variant.Mint.Zard.5
VBA32BScope.Backdoor.Sinowal
Cylanceunsafe
TencentTrojan.Win32.Pathced_ya.16001052
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/Adware_AGen
AVGWin32:Patched-AWW [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment