Ransom

Ransom:Win32/ContiCrypt.RER!MTB removal guide

Malware Removal

The Ransom:Win32/ContiCrypt.RER!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/ContiCrypt.RER!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ransom:Win32/ContiCrypt.RER!MTB?


File Info:

name: F877EB8B27E4980C22C4.mlw
path: /opt/CAPEv2/storage/binaries/58ce9588e73d2d9740b98b114d4ab079562b3bde93feadf9d32e85b366757c1b
crc32: 7888944E
md5: f877eb8b27e4980c22c4f16cfaba4a90
sha1: 0a07baf9fe3503ad298dd1856fbe4ff6ab75a241
sha256: 58ce9588e73d2d9740b98b114d4ab079562b3bde93feadf9d32e85b366757c1b
sha512: 18d5997c0ee7e245882bfc0e755e22b01dce11a9f4e06ebc298ffd40c1615fc92cb9e39ff905f4c14e660ae305d63226be8c89dc59f860ec5a915f7819bb3219
ssdeep: 12288:G7omjlY65L1yjMdnbnmgRDqdy8KW9+EqmPyi:Ghr5pzF9RDqHKWDqW9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T114E4D0212A3EE12FFC5AE6BB6DC6F09B5E509031CB7237C36361695803529EB137C568
sha3_384: 373a6b88480c48f394c2e37198912a611a52e91b24934d22c2336ee0fcdfc14c8c83519791b77cd10884b4b31aca3377
ep_bytes: 83ec40e871bd0a00e901000000c3e86c
timestamp: 2015-02-07 09:53:36

Version Info:

0: [No Data]

Ransom:Win32/ContiCrypt.RER!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.mt7t
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Virlock.Gen.3
FireEyeGeneric.mg.f877eb8b27e4980c
McAfeeW32/VirRansom.b!F877EB8B27E4
CylanceUnsafe
ZillyaVirus.Virlock.Win32.2
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040fa5c1 )
K7GWTrojan ( 0040fa5c1 )
Cybereasonmalicious.b27e49
BitDefenderThetaAI:FileInfector.AE99F02013
CyrenW32/S-11daff79!Eldorado
SymantecW32.Virlock!gen1
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Virlock.J
BaiduWin32.Virus.Virlock.e
TrendMicro-HouseCallPE_VIRLOCK.A-O
ClamAVWin.Virus.Virlock-6804475-0
KasperskyVirus.Win32.PolyRansom.f
BitDefenderWin32.Virlock.Gen.3
NANO-AntivirusVirus.Win32.Virlock.dsdros
CynetMalicious (score: 100)
AvastWin32:Nabucur-A [Trj]
TencentVirus.Win32.Polyransom.f
Ad-AwareWin32.Virlock.Gen.3
TACHYONVirus/W32.VirRansom.D
EmsisoftWin32.Virlock.Gen.3 (B)
ComodoVirus.Win32.VirLock.GA@7lv9go
DrWebWin32.VirLock.16
VIPREWin32.Virlock.Gen.3
TrendMicroPE_VIRLOCK.A-O
McAfee-GW-EditionBehavesLike.Win32.VirRansom.jc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosML/PE-A + W32/VirRnsm-E
APEXMalicious
JiangminWin32/Polyransom.f
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASVirus.1FC
MicrosoftRansom:Win32/ContiCrypt.RER!MTB
GDataWin32.Virlock.Gen.3
GoogleDetected
AhnLab-V3Win32/Nabucur.D.X1506
ALYacWin32.Virlock.Gen.3
MAXmalware (ai score=82)
VBA32Virus.Virlock.gen.01
MalwarebytesPolyRansom.Virus.FileInfector.DDS
RisingTrojan.Win32.Snc.a (CLASSIC)
IkarusVirus.Win32.Virlock
MaxSecureVirus.PolyRansom.b
FortinetW32/Virlock.B
AVGWin32:Nabucur-A [Trj]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/ContiCrypt.RER!MTB?

Ransom:Win32/ContiCrypt.RER!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment