Ransom

About “Generic.Ransom.Conti.041CF16B” infection

Malware Removal

The Generic.Ransom.Conti.041CF16B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Conti.041CF16B virus can do?

  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.Conti.041CF16B?


File Info:

crc32: FCE86CDB
md5: 3c55ee6753408bff2e3e6a392ed9f2a0
name: 3C55EE6753408BFF2E3E6A392ED9F2A0.mlw
sha1: 9d3b22a0347cf91270466389745ba3c224e5bf41
sha256: 0b0b902af452e1c949a609a3b29a9de21dac639846c77427de06e6e63c1fe904
sha512: 10d43624f0641f537afb393acddc60170ff323915d9387048873c8f22646fd2ec8a57021dd895aa3a3c288004aef8767685bc6a211f20de3b8e169e0f89415b6
ssdeep: 768:7d8ZZ1ILwhbvRbG1e2NrrABiTAtApWBzDxVnbCoGXmbDLT3prZU9V+VzhXjcp+L:xO1GybvRye2JAB2YHy4vzCeFzf5ZCZZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Conti.041CF16B also known as:

K7AntiVirusTrojan ( 0056854b1 )
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.32370
CynetMalicious (score: 100)
CAT-QuickHealTrojan.CryptorRI.S16139237
ALYacTrojan.Ransom.Conti
CylanceUnsafe
ZillyaTrojan.Cryptor.Win32.548
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cryptor.c7bc0db3
K7GWTrojan ( 0056854b1 )
Cybereasonmalicious.753408
SymantecRansom.Conti
ESET-NOD32a variant of Win32/Filecoder.Conti.D
APEXMalicious
AvastWin32:Conti-B [Ransom]
ClamAVWin.Ransomware.Conti-9826703-0
KasperskyTrojan-Ransom.Win32.Conti.f
BitDefenderGeneric.Ransom.Conti.041CF16B
NANO-AntivirusTrojan.Win32.Cryptor.hwaiws
MicroWorld-eScanGeneric.Ransom.Conti.041CF16B
TencentWin32.Trojan.Cryptor.Llhl
Ad-AwareGeneric.Ransom.Conti.041CF16B
SophosMal/Generic-S
ComodoMalware@#orhn95l9qgz0
BitDefenderThetaAI:Packer.3EBC10DE1F
TrendMicroRansom.Win32.CONTI.SMW
McAfee-GW-EditionPWS-Zbot.gen.aft
FireEyeGeneric.mg.3c55ee6753408bff
EmsisoftGeneric.Ransom.Conti.041CF16B (B)
JiangminTrojan.Cryptor.si
AviraTR/FileCoder.nflan
Antiy-AVLTrojan/Generic.ASMalwS.30E81E3
MicrosoftRansom:Win32/Conti.MAK!MTB
ArcabitGeneric.Ransom.Conti.041CF16B
ZoneAlarmTrojan-Ransom.Win32.Conti.f
GDataGeneric.Ransom.Conti.041CF16B
AhnLab-V3Trojan/Win32.Filecoder.C4194000
McAfeePWS-Zbot.gen.aft
MAXmalware (ai score=89)
VBA32BScope.Trojan.StartPage
MalwarebytesRansom.Conti
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.CONTI.SMW
RisingRansom.Conti!1.D637 (CLASSIC)
IkarusTrojan-Ransom.Conti
MaxSecureTrojan.Malware.106656876.susgen
FortinetW32/Cryptor.CDDC!tr.ransom
AVGWin32:Conti-B [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cryptor.HxQBQecA

How to remove Generic.Ransom.Conti.041CF16B?

Generic.Ransom.Conti.041CF16B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment