Malware

How to remove “PWS:MSIL/Mintluks!pz”?

Malware Removal

The PWS:MSIL/Mintluks!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:MSIL/Mintluks!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Compiles .NET code into an executable and executes it
  • Deletes executed files from disk

How to determine PWS:MSIL/Mintluks!pz?


File Info:

name: 3AA983CCA589334DB0DE.mlw
path: /opt/CAPEv2/storage/binaries/bb62267affc612bca9c7c5e6068a3da80065bae749510cdf47d92816cd978461
crc32: 9E67BF88
md5: 3aa983cca589334db0deced502fe5d17
sha1: 75663f271b862bacab2125a747758aae6dab1aaf
sha256: bb62267affc612bca9c7c5e6068a3da80065bae749510cdf47d92816cd978461
sha512: 4a4c065425f4f420589182cf923896914473eddde05026a2aef99dd0d4f9242cfd03bcd0d9c923d124c89f92a675e6e33f7851b6e3fe516125170b2712b784ee
ssdeep: 1536:kV5mdy0MochZDsC8Kl/99Z242UdIAkn3jKZPjoYaoQtx6to9/iE1Ey:kV5Rn7N041QqhgB9/v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A573BF16BE810D08E7F80B3205DC36CA06BFFB4EE67056CE5D2E69A85B37B9059D0754
sha3_384: c8ec5d61b49a36dfdecee896c83974dda6fcad3ff1f0e14ce4fda9ff691c6105a2006cfe8dcf9785ad881af0ec433324
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-05-25 19:22:12

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: tmp6EA9.tmp.exe
LegalCopyright:
OriginalFilename: tmp6EA9.tmp.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

PWS:MSIL/Mintluks!pz also known as:

BkavW32.FamVT.Deb123TTc.Worm
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKDZ.96283
FireEyeGeneric.mg.3aa983cca589334d
CAT-QuickHealTrojan.Generic.TRFH959
SkyhighBehavesLike.Win32.Generic.lc
ALYacTrojan.GenericKDZ.96283
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.AgentGen.Win32.91
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/csharp.ali2000008
K7GWTrojan ( 005690671 )
K7AntiVirusTrojan ( 0056ae4d1 )
BitDefenderThetaGen:NN.ZemsilF.36744.em0@aC8jIAl
VirITTrojan.Win32.Dnldr7.DCEA
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.MSS
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Avlj-9877624-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.96283
NANO-AntivirusTrojan.Win32.Generic.euparm
AvastWin32:Agent-AVLJ [Trj]
TencentTrojan.MSIL.Zilla.ha
TACHYONTrojan/W32.DN-Agent.80384.BJ
EmsisoftTrojan.GenericKDZ.96283 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader7.54184
VIPRETrojan.GenericKDZ.96283
TrendMicroTROJ_MINTLUKS.SM
SophosMal/MSIL-TU
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan.PSE.153ZQSC
JiangminTrojan/Generic.ujws
WebrootW32.Trojan.Mintluks
VaristW32/MSIL_Kryptik.AZD.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.MSIL.Mintluks.JJC@7axq6t
ArcabitTrojan.Generic.D1781B
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:MSIL/Mintluks!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Injector.R344347
McAfeeGenericRXCZ-AI!3AA983CCA589
MAXmalware (ai score=81)
VBA32OScope.TrojanDropper.MSIL.Mintluks
Cylanceunsafe
TrendMicro-HouseCallTROJ_MINTLUKS.SM
RisingBackdoor.njRAT!1.AE81 (CLASSIC)
YandexTrojan.Agent!TSr2rMNVhZA
IkarusTrojan-Dropper.MSIL
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.JJC!tr
AVGWin32:Agent-AVLJ [Trj]
Cybereasonmalicious.71b862
DeepInstinctMALICIOUS

How to remove PWS:MSIL/Mintluks!pz?

PWS:MSIL/Mintluks!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment