Ransom

Should I remove “Ransom:Win32/Conti.ZD”?

Malware Removal

The Ransom:Win32/Conti.ZD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Conti.ZD virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (255 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Ransom:Win32/Conti.ZD?


File Info:

crc32: 74EB1DA1
md5: 4cd6ac6a04eb5234757e84ebf401caf7
name: 4CD6AC6A04EB5234757E84EBF401CAF7.mlw
sha1: 5d067a5e54033f84535a768a3a93539143c65b44
sha256: d2464dd0508e2b8632fe91c5c0447e963026e4c722f078d93cdc97a3ed7c6c51
sha512: efee3e3fa185340bccb914e967f7d4d419607e3364228e9f4524d1626b9b3f790ea4322cd3789fe59cfd0d0073529b8a2f18804859759469e30e131fedf475ba
ssdeep: 12288:Gmx0+R7bgqWijYD58CcSegTyD8nNNkJ3liGo7Wwszl4QztkK:GmSongqWmYSh/qyQNNkJ3sdOzl4QziK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 4234 23
InternalName: 434 23 432
FileVersion: 4324 2 423
LegalTrademarks: 423 4234 324
ProductName: 4 234234
ProductVersion: 234234 23 4234
FileDescription: 342 34 23
OriginalFilename: 2 3 423
Translation: 0x0419 0x04b0

Ransom:Win32/Conti.ZD also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057c4191 )
Elasticmalicious (high confidence)
ALYacTrojan.GenericKD.46273527
SangforTrojan.Win32.Cryptor.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cryptor.cc695b07
K7GWTrojan ( 0057c4191 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Conti.R
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Cryptor.eet
BitDefenderTrojan.GenericKD.46273527
MicroWorld-eScanTrojan.GenericKD.46273527
Ad-AwareTrojan.GenericKD.46273527
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34688.1y3@a0JQgpfc
McAfee-GW-EditionBehavesLike.Win32.Sivis.cm
FireEyeGeneric.mg.4cd6ac6a04eb5234
EmsisoftTrojan.GenericKD.46273527 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Conti.ZD
AegisLabTrojan.Win32.Kpot.i!c
GDataTrojan.GenericKD.46273527
McAfeeArtemis!4CD6AC6A04EB
MAXmalware (ai score=89)
MalwarebytesMalware.AI.860842627
RisingTrojan.Kryptik!1.C9D3 (CLOUD)
FortinetW32/Cryptor.EET!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Conti.ZD?

Ransom:Win32/Conti.ZD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment