Malware

Mint.Zard.5 removal guide

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: 29A403E885E4754620D5.mlw
path: /opt/CAPEv2/storage/binaries/df12acced6067c8c909dfb0803c3d9dd0e11cb9743909cec23c368bf85669d05
crc32: BC825F4C
md5: 29a403e885e4754620d5d791f4046337
sha1: 971191a4e1800adc0791a24eb8cf364e0d34a33b
sha256: df12acced6067c8c909dfb0803c3d9dd0e11cb9743909cec23c368bf85669d05
sha512: dabd0a264e2caf2f88dc072629029c866c690137ab9708bc92d7bb058dc1fb20da9d8dcb0ae26133802c41460b62b9932685db3773401889f48aaaf1c64fb4dc
ssdeep: 6144:gKvWdpqOMgTbAtxEXIeoWwONgh7wcaJ/ht9xoR/LcvOEMtaLuGzSQm4y6/mHl/N:gUWdpqOMQkxE1wONgFwlpi/LFBgKGzS7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16164D0099698D1B9C00058B27C66D3315F6AFC36CDFD858232CE73BB9AF3164A666353
sha3_384: 9cdd9d60c64c2df0fce6b6aeb3e984dcec7c9c31af8c0e1ad1e9105ecca4a3efd5be34a567c9081df0ef0b79dcd3d850
ep_bytes: e87c480000e989feffff8bff558bec81
timestamp: 2022-08-06 10:35:24

Version Info:

CompanyName: Simple Launcher User
FileDescription: Simple Launcher Executable
FileVersion: 1.1.0.14
InternalName: w32.exe
LegalCopyright: Copyright (C) Simple Launcher User
OriginalFilename: w32.exe
ProductName: Simple Launcher
ProductVersion: 1.1.0.14
Translation: 0x0409 0x04b0

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Senoval.n!c
AVGWin32:Patched-AWW [Trj]
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGeneric.mg.29a403e885e47546
SkyhighBehavesLike.Win32.Generic.fc
McAfeeArtemis!29A403E885E4
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005ab4bf1 )
AlibabaTrojan:Win32/Senoval.90427e0c
K7GWTrojan ( 005ab4bf1 )
Cybereasonmalicious.885e47
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWW [Trj]
TencentTrojan.Win32.Pathced_ya.16001052
SophosW32/Patched-CD
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Beetle.3
VIPREGen:Variant.Mint.Zard.5
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Mint.Zard.5 (B)
AviraTR/Patched.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Patched
Kingsoftmalware.kb.a.841
MicrosoftTrojan:Win32/Doina.RPX!MTB
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
GDataWin32.Trojan.PSE.16VFYLR
VaristW32/Patched.GQ1.gen!Eldorado
VBA32BScope.Trojan.Meterpreter
ALYacGen:Variant.Mint.Zard.5
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:K54CFjeE42Ed5hckCLSGhg)
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Patched.IP!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment