Malware

PWS:MSIL/Mintluks!pz removal

Malware Removal

The PWS:MSIL/Mintluks!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/Mintluks!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Compiles .NET code into an executable and executes it
  • Deletes executed files from disk

How to determine PWS:MSIL/Mintluks!pz?


File Info:

name: 848A46B9763B02DB6E76.mlw
path: /opt/CAPEv2/storage/binaries/e28331f6fd68b781a3218fb0398df3e652746c2be2fa5c24043c0e7e20eb61c4
crc32: 082716D9
md5: 848a46b9763b02db6e7698ee2f3c4e17
sha1: e68d70633c4d13d023f117add998a7d182241af9
sha256: e28331f6fd68b781a3218fb0398df3e652746c2be2fa5c24043c0e7e20eb61c4
sha512: b2c7617c61043ddb0379d903be239b8e92b7b116a71f872c1d44a74db7ca95ed4d96f5afc8a54ef3ac47dd5ee6d976ef9439c54d6386a89f22c0915b628fef9d
ssdeep: 1536:/V5jS6dy0MochZDsC8Kl/99Z242UdIAkn3jKZPjoYaoQtC649/YS1dm:/V5jS1n7N041QqhgQ9/y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A73BF15AE810D08E7F80B3215DC36CA0ABFFB4EEA7057CA5D1E65A81B37B9059E0764
sha3_384: bed14272b2040246fd022315e28bdad8edb088879bbe1742ee03b432aac643dc722bfa1792dc1f4f8d062b5982b7c441
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-05-25 16:09:09

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: tmp6344.tmp.exe
LegalCopyright:
OriginalFilename: tmp6344.tmp.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

PWS:MSIL/Mintluks!pz also known as:

BkavW32.FamVT.Deb123TTc.Worm
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKDZ.95500
ClamAVWin.Malware.Avlj-9877624-0
FireEyeGeneric.mg.848a46b9763b02db
CAT-QuickHealTrojan.Generic.TRFH959
SkyhighBehavesLike.Win32.Generic.lc
McAfeeGenericRXCZ-AI!848A46B9763B
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.AgentGen.Win32.91
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/csharp.ali2000008
K7GWTrojan ( 005690671 )
K7AntiVirusTrojan ( 0056ae4d1 )
ArcabitTrojan.Generic.D1750C
BitDefenderThetaGen:NN.ZemsilF.36744.em0@aGxJN4j
VirITTrojan.Win32.Dnldr7.DCEA
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.MSS
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.95500
NANO-AntivirusTrojan.Win32.Generic.euparm
AvastWin32:Agent-AVLJ [Trj]
TencentTrojan.MSIL.Zilla.ha
TACHYONTrojan/W32.DN-Agent.80384.BK
SophosMal/MSIL-TU
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader7.54184
VIPRETrojan.GenericKDZ.95500
TrendMicroTROJ_MINTLUKS.SM
EmsisoftTrojan.GenericKDZ.95500 (B)
IkarusTrojan.Dropper
JiangminTrojan/Generic.ujws
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.c.1000
XcitiumTrojWare.MSIL.Mintluks.JJC@7axq6t
MicrosoftPWS:MSIL/Mintluks!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Trojan.PSE.105TIS2
VaristW32/MSIL_Kryptik.AZD.gen!Eldorado
AhnLab-V3Trojan/Win32.Kryptik.R361449
VBA32OScope.TrojanDropper.MSIL.Mintluks
ALYacTrojan.GenericKDZ.95500
MAXmalware (ai score=87)
Cylanceunsafe
TrendMicro-HouseCallTROJ_MINTLUKS.SM
RisingBackdoor.njRAT!1.AE81 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.JJC!tr
AVGWin32:Agent-AVLJ [Trj]
DeepInstinctMALICIOUS

How to remove PWS:MSIL/Mintluks!pz?

PWS:MSIL/Mintluks!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment