Ransom

Ransom:Win32/ContiCrypt.PL!MTB removal guide

Malware Removal

The Ransom:Win32/ContiCrypt.PL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/ContiCrypt.PL!MTB virus can do?

  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom:Win32/ContiCrypt.PL!MTB?


File Info:

name: 978F1D41E19785CD8456.mlw
path: /opt/CAPEv2/storage/binaries/1dff32b41bc1bbad741bd0d48f468b5cac362f45cb0eccb07b36cda1c1499aeb
crc32: 59F29F46
md5: 978f1d41e19785cd84562f80a837f82f
sha1: bdd1b26357416797fdd5b616373629b1b7c1f489
sha256: 1dff32b41bc1bbad741bd0d48f468b5cac362f45cb0eccb07b36cda1c1499aeb
sha512: 3d510964982e36460119088d73bdb77f08fa307f33e74adb07f5cf206129fb6fc0b773fbc6580bfefec6d8198f54dd7b4ecdfd519171280c2bbfd1a29ddcf805
ssdeep: 24576:kfLDdS9r3NS/f99uav96bfLDdS9r3NS/f99uav96bfLDdS9r3NS/f99uav964zPB:kf9GIXGywbf9GIXGywbf9GIXGywQhf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD55F0BAF955E8D1D4598530CCE3C9F51959BC6AC8A0082336E97F0FF9322E5B42385E
sha3_384: 5f6f82297042d5a1b7fb44fb17da8582388cf3d2275a850a53acf24aab7fd02827e6b40c170e2d74126dce45613fe549
ep_bytes: 8bc68bca8bd8ff151d4d40008bf0ff15
timestamp: 1970-01-01 00:00:00

Version Info:

FileVersion: 9, 4, 5, 3
CompanyName: Star Force
FileDescription: Skeeg
InternalName: Promptuary
OriginalFilename: Paraphrasian
PrivateBuild: Archcriminal
Translation: 0x0409 0x04e4

Ransom:Win32/ContiCrypt.PL!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38801056
FireEyeGeneric.mg.978f1d41e19785cd
CAT-QuickHealTrojan.IGENERIC
ALYacTrojan.GenericKD.38801056
MalwarebytesMalware.AI.849362132
SangforSuspicious.Win32.Attribute.HighConfidence
K7AntiVirusTrojan ( 0058ca041 )
BitDefenderTrojan.GenericKD.38801056
K7GWTrojan ( 0058ca041 )
Cybereasonmalicious.357416
BitDefenderThetaGen:NN.ZexaF.34232.vn1@aORt5doi
CyrenW32/Kryptik.FSK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FMWP
TrendMicro-HouseCallTrojan.Win32.KRYPT.USASHB322
AlibabaTrojan:Win32/GenKryptik.51fe6ad4
AvastWin32:Trojan-gen
RisingTrojan.Woreflint!8.F5EA (CLOUD)
Ad-AwareTrojan.GenericKD.38801056
SophosMal/Generic-S
ComodoMalware@#1rxmb0c7td1ci
ZillyaTrojan.GenKryptik.Win32.128947
TrendMicroTrojan.Win32.KRYPT.USASHB322
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.GenericKD.38801056 (B)
APEXMalicious
AviraTR/AD.GenSteal.jbpym
MicrosoftRansom:Win32/ContiCrypt.PL!MTB
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2500EA0
GDataTrojan.GenericKD.38801056
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!978F1D41E197
CylanceUnsafe
MAXmalware (ai score=84)
FortinetW32/Kryptik.HODI!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.139108139.susgen

How to remove Ransom:Win32/ContiCrypt.PL!MTB?

Ransom:Win32/ContiCrypt.PL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment