Malware

What is “Mint.Zard.5”?

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mint.Zard.5?


File Info:

name: D11C0BEA17526026F0A6.mlw
path: /opt/CAPEv2/storage/binaries/d03a2967a4ef494e346a705ca28a9339ac369e1e3f4c2e4fde4e4750cebe3734
crc32: E49A5AEB
md5: d11c0bea17526026f0a6cf0cf59af1a6
sha1: 9e7fdaa59b4949eb33374900faafb2e4702f7617
sha256: d03a2967a4ef494e346a705ca28a9339ac369e1e3f4c2e4fde4e4750cebe3734
sha512: 5177604f4bb841e694dc0d8c588d8661eb687b619746caf99c69363b8f2b91e43948c071b2412eeaace37a0fba471bc7c1443858831a1c6bf7073034b15ad08c
ssdeep: 12288:2v3kJcKECnTZK/iv/z7w1uD0kmTZGrYQBIjbqn2fbyL5f:2sy5oT+iv/zM1u7hknqzLZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C6C4BE053BF9C8BAD24345328A4D5BA8A4F9A7BA4C605A4363C40D6DFB35DCEC359F09
sha3_384: fc179da66776fce8316db776c20d69e2accd519b0f0e05d78827829bd53f43d5f266f9a0bab9fd83b9362a352779dc66
ep_bytes: 558bec6aff6840ce430068b03d430064
timestamp: 2018-12-30 12:58:27

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7-Zip Console
FileVersion: 18.06
InternalName: 7z
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7z.exe
ProductName: 7-Zip
ProductVersion: 18.06
Translation: 0x0409 0x04b0

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Sinowal.n!c
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGeneric.mg.d11c0bea17526026
CAT-QuickHealTrojan.InjukePMF.S31351714
SkyhighBehavesLike.Win32.PWSZbot.hc
McAfeeArtemis!D11C0BEA1752
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Sinowal.Win32.22191
SangforSuspicious.Win32.Save.ins
AlibabaVirus:Win32/Senoval.eddb1343
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZexaF.36744.Hy0@aShtC9fi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKP
APEXMalicious
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWX [Trj]
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Variant.Mint.Zard.5 (B)
F-SecureHeuristic.HEUR/AGEN.1369791
VIPREGen:Variant.Mint.Zard.5
SophosMal/Generic-S
MAXmalware (ai score=84)
GDataGen:Variant.Mint.Zard.5
GoogleDetected
AviraHEUR/AGEN.1369791
VaristW32/Injuke.BI.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.Sinowal
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
MicrosoftTrojan:Win32/Conteban.A!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R606966
VBA32BScope.Backdoor.Sinowal
ALYacGen:Variant.Mint.Zard.5
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:w0W3d7zZa7tLOcyx6dDNPA)
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/Adware_AGen
AVGWin32:Patched-AWX [Trj]
DeepInstinctMALICIOUS

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment