Ransom

What is “Ransom:Win32/CONTI!ml”?

Malware Removal

The Ransom:Win32/CONTI!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/CONTI!ml virus can do?

  • Presents an Authenticode digital signature
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Ransom:Win32/CONTI!ml?


File Info:

crc32: 380B502D
md5: 75c9499ca1665c2352bb0415fce39dd5
name: 75C9499CA1665C2352BB0415FCE39DD5.mlw
sha1: 3716e430742530b032ca394411dc76fe89adbf90
sha256: 484621ac6e93632772693378d66e1560032e7329de6d3beff329ca4fdd95620f
sha512: a5184c2835b91e0fbc0dfe6a227f565c33b0f4f12ba8296fda6f839a7a564c589674b08c356da90e1af2e14907219cf2b0819a7d12752dd1080dc5abe1eebe52
ssdeep: 24576:OQLny3OiG7O5fWcmCM4jBg0nWDqVXF1/Vz897cDH6WboJVIb90IDu:OQLy3Z5ecmCMqhnllLNgIHjbiIb9pu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Htxykka
FileVersion: 18.2.8576.36057 (iynalnq_bct.697779-9079)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 18.2.8576.36057
FileDescription: Chf10 Frywncc Lrbxojzzdf
OriginalFilename: JGXYJRF.EXE .ALK
Translation: 0x0409 0x04b0

Ransom:Win32/CONTI!ml also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00576a981 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop16.9852
CynetMalicious (score: 100)
ALYacGen:Variant.Strictor.255164
CylanceUnsafe
ZillyaTrojan.Alien.Win32.1613
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 00576a981 )
Cybereasonmalicious.ca1665
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.CFKFDLE
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Generic-9822957-0
KasperskyHEUR:Trojan.Win32.Alien.vho
BitDefenderGen:Variant.Strictor.255164
MicroWorld-eScanGen:Variant.Strictor.255164
TencentMalware.Win32.Gencirc.10ce325c
Ad-AwareGen:Variant.Strictor.255164
SophosML/PE-A
TrendMicroRansom.Win32.CONTI.SMA.hp
FireEyeGeneric.mg.75c9499ca1665c23
EmsisoftGen:Variant.Strictor.255164 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/CONTI!ml
ArcabitTrojan.Strictor.D3E4BC
ZoneAlarmHEUR:Trojan.Win32.Alien.vho
GDataGen:Variant.Strictor.255164
AhnLab-V3PUP/Win32.RL_Generic.R364225
MAXmalware (ai score=80)
MalwarebytesTrojan.Dropper.WXT.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.CONTI.SMA.hp
RisingDropper.Certutil!1.D0D0 (CLASSIC)
IkarusTrojan.Barys
FortinetW32/Generik.CFKFDLE!tr
AVGWin32:Trojan-gen

How to remove Ransom:Win32/CONTI!ml?

Ransom:Win32/CONTI!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment