Ransom

Ransom:Win32/Conti removal

Malware Removal

The Ransom:Win32/Conti is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Conti virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Conti?


File Info:

crc32: BD2A751B
md5: 9eb1d5dbe3722be30545c9b63565d2eb
name: 9EB1D5DBE3722BE30545C9B63565D2EB.mlw
sha1: 78adabc1ac2c1cf58a30ac7bea53062a1e11c9b4
sha256: 0951fde8a8ea9cd45d2be14d63e6e55c8e87af0da45cf3776b495871652aa862
sha512: 2360ab53c10995daafdd118755b98439baba79232865d8daf10a97bfb9e136f16e49ab315ae804a768593d27f7dc86e8e1708385a13653fad4a850de7c56400b
ssdeep: 6144:ud8FpUeW9Xb7cE4luAoF6hS1g0cmpSZ/gdRKOMsaVGKMBaoU2x0jPX3lAa/ac:u39XbgE/AMLLSZId/adpr7/ac
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Conti also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
McAfeeEmotet-FSF!9EB1D5DBE372
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zenpak.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/EmotetCrypt.e27912b0
K7GWTrojan ( 005719a71 )
K7AntiVirusTrojan ( 005719a71 )
CyrenW32/Trojan.ZUVP-2282
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderTrojan.EmotetU.Gen.BqW@iGCO7@gi
NANO-AntivirusTrojan.Win32.Zenpak.iaxaug
MicroWorld-eScanTrojan.EmotetU.Gen.BqW@iGCO7@gi
Ad-AwareTrojan.EmotetU.Gen.BqW@iGCO7@gi
SophosMal/Generic-S
ComodoMalware@#2hmn0arhkc4a2
DrWebTrojan.MailBot.29
ZillyaTrojan.Zenpak.Win32.4235
TrendMicroTrojanSpy.Win32.EMOTET.SMU.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.9eb1d5dbe3722be3
EmsisoftTrojan.EmotetU.Gen.BqW@iGCO7@gi (B)
MaxSecureTrojan.Malware.73832973.susgen
MAXmalware (ai score=99)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Conti
ArcabitTrojan.EmotetU.Gen.E92FF6
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataTrojan.EmotetU.Gen.BqW@iGCO7@gi
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34688.BqW@aGCO7@gi
ALYacTrojan.Ransom.Conti
TACHYONRansom/W32.Conti.444928
VBA32BScope.Malware-Cryptor.Emotet
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HGYC
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMU.hp
RisingTrojan.Generic@ML.90 (RDMK:wOsESJcsXom5oZ8QwXps0A)
IkarusTrojan.Agent
eGambitUnsafe.AI_Score_83%
FortinetW32/Kryptik.HEOE!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.1ac2c1
AvastWin32:Trojan-gen
Qihoo-360Generic/HEUR/QVM10.2.E005.Malware.Gen

How to remove Ransom:Win32/Conti?

Ransom:Win32/Conti removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment