Malware

What is “Mint.Zard.5”?

Malware Removal

The Mint.Zard.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mint.Zard.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mint.Zard.5?


File Info:

name: 2D83297D60B09DB63727.mlw
path: /opt/CAPEv2/storage/binaries/b5a74c3eb3fcaa5d4ef5dfb12a460154e177f34bd233938304606e295c02ef8f
crc32: A82393B4
md5: 2d83297d60b09db637276d3ca74d10f4
sha1: 5367c25e431b5bdb44103f419d977f52548efb0d
sha256: b5a74c3eb3fcaa5d4ef5dfb12a460154e177f34bd233938304606e295c02ef8f
sha512: 98e9768f2e798be4e94e793389979862218f048b57e280bc18505d1f4e5904453cf7a42e3f7597262721f5f69c0cb0b843aad41e22c3933d1194086954b6a214
ssdeep: 24576:cBB6IH2VKoLfnYK1qKFIRL60XtGnVHEPN2:cBj2MVIqVXtGVkPs
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T184058D613EBB0375E1231131A5269F63F2E9ED21077098D76995E26E3B214C1CE32B6F
sha3_384: 55802bb4aadc312264ab56b470e4f80f5de1d8244eeb6c4474b484f0d721bf67e9e83fe91ea1e9daccacf3c19d96c0b2
ep_bytes: 558bec837d0c017505e815000000ff75
timestamp: 2022-11-14 11:28:02

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Acrobat SendMail Plug-in
FileVersion: 22.3.20282.0
LegalCopyright: Copyright 1984-2022 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName: Adobe Acrobat
ProductVersion: 22.3.20282.0
OriginalFilename: SendMail.api
Translation: 0x0409 0x04e4

Mint.Zard.5 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Senoval.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Dropper.bc
McAfeeRDN/Generic.hra
SangforTrojan.Win32.Patched.Vlgn
K7AntiVirusTrojan ( 005ab4bf1 )
AlibabaTrojan:Win32/Senoval.04cec58a
K7GWTrojan ( 005ab4bf1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.6
ESET-NOD32a variant of Win32/Patched.NKM
ClamAVWin.Virus.Lazy-10015676-0
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Mint.Zard.5
TencentTrojan.Win32.Pathced_ya.16001052
SophosW32/Patched-CE
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Beetle.2
VIPREGen:Variant.Mint.Zard.5
TrendMicroTROJ_GEN.R002C0DLB23
EmsisoftGen:Variant.Mint.Zard.5 (B)
IkarusTrojan.Win32.Patched
GoogleDetected
AviraTR/Patched.Gen
Antiy-AVLTrojan/Win32.Patched
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
GDataGen:Variant.Mint.Zard.5
VaristW32/Patched.GQ1.gen!Eldorado
AhnLab-V3Trojan/Win.Doina.C5487323
ALYacGen:Variant.Mint.Zard.5
DeepInstinctMALICIOUS
VBA32BScope.TrojanDownloader.Emotet
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DLB23
RisingTrojan.Generic@AI.100 (RDML:pu2/z86tPAAzL2irpj99DQ)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.GNMH!tr
PandaTrj/Genetic.gen

How to remove Mint.Zard.5?

Mint.Zard.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment