Ransom

How to remove “Ransom:Win32/Conti.RJ!MTB”?

Malware Removal

The Ransom:Win32/Conti.RJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Conti.RJ!MTB virus can do?

  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (255 unique times)
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior

How to determine Ransom:Win32/Conti.RJ!MTB?


File Info:

crc32: 06C32CBE
md5: 9e44305c3e6f66db3a0e1b142f6bb088
name: 9E44305C3E6F66DB3A0E1B142F6BB088.mlw
sha1: 1f8dce63618475f34d583ffdebfe3de962ba7425
sha256: 63b8a0fc17f2c36d24294d46ba6b7a7d38726e4519ab11b759dca7fa8485a28c
sha512: 6a4824aa0c253540d7165ea4ebcac2838a6db3758b11579f978f3b301ed81c29d6732daafe21a143a720dd83c75e6abaf775271df7d1b7756d912ca060d82af4
ssdeep: 3072:1jgaKcGA5zR7gExANUuPCnl8PiCApCxdi/dHFKHmdsWwxk5Sxz9o:5gAGm4KnlXYdEFK84xxo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Conti.RJ!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.32708
CynetMalicious (score: 99)
ALYacTrojan.Ransom.Conti
CylanceUnsafe
SangforRansom.Win32.NetWalker.MTB
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/NetWalker.2092a384
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c3e6f6
CyrenW32/Trojan.JPJO-7302
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Filecoder.Conti.F
APEXMalicious
AvastWin32:Conti-B [Ransom]
ClamAVWin.Ransomware.Conti-9808002-0
KasperskyTrojan-Ransom.Win32.Encoder.kbq
BitDefenderGeneric.Ransom.Conti.57C16005
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGeneric.Ransom.Conti.57C16005
TencentWin32.Trojan.Encoder.Hviy
Ad-AwareGeneric.Ransom.Conti.57C16005
SophosMal/Generic-S
ComodoMalware@#y8eh66bgqdj
BitDefenderThetaGen:NN.ZexaF.34790.lyW@am6J9qji
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.CONTI.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.9e44305c3e6f66db
EmsisoftGeneric.Ransom.Conti.57C16005 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Encoder.yz
AviraHEUR/AGEN.1103459
Antiy-AVLTrojan/Generic.ASMalwS.30F53C1
MicrosoftRansom:Win32/Conti.RJ!MTB
ArcabitGeneric.Ransom.Conti.57C16005
AegisLabTrojan.Win32.Encoder.j!c
GDataGeneric.Ransom.Conti.57C16005
AhnLab-V3Trojan/Win32.RansomCrypt.C4196467
McAfeeRansom-Conti!9E44305C3E6F
MAXmalware (ai score=100)
VBA32BScope.Trojan.Mansabo
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.CONTI.SM.hp
RisingRansom.Conti!1.D637 (CLASSIC)
YandexTrojan.Filecoder!hlxlNL62XGs
IkarusTrojan-Ransom.Conti
MaxSecureTrojan.Malware.106607411.susgen
FortinetW32/Conti.F!tr.ransom
AVGWin32:Conti-B [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Encoder.HwoCBvsC

How to remove Ransom:Win32/Conti.RJ!MTB?

Ransom:Win32/Conti.RJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment