Ransom

Ransom:Win64/ContiCrypt.PE!MTB removal tips

Malware Removal

The Ransom:Win64/ContiCrypt.PE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win64/ContiCrypt.PE!MTB virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win64/ContiCrypt.PE!MTB?


File Info:

crc32: 065A1C16
md5: d7bf01f9fb24176f2d42d770d79e8c2c
name: D7BF01F9FB24176F2D42D770D79E8C2C.mlw
sha1: 9b8eeaf746cd5d903f70c3b245b9466c40b74c5d
sha256: 6f7043b24d9b4c30006781402f0cef2543c8f3e9087d79f6bcff43b1418ad21d
sha512: 0f299b9637c92098eda3a0d27a384e62d9fbaac4a2042cce84f5b1437eea1a17534331931ea5e6a68d79077cefb8678411900165b79fb4040578afaef354ee79
ssdeep: 3072:2xA/+tFAQDsFRa03B6jD3MIKud2nLxFVucrUK8af+1lwS:GA/+t6QDsL3kjD3UjfVWsS
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win64/ContiCrypt.PE!MTB also known as:

Elasticmalicious (high confidence)
ALYacGen:Variant.Bulz.360963
CylanceUnsafe
K7GWTrojan ( 0057cb8c1 )
K7AntiVirusTrojan ( 0057cb8c1 )
AvastWin32:Conti-B [Ransom]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Cryptor.gen
BitDefenderGen:Variant.Bulz.360963
NANO-AntivirusTrojan.Win32.Cryptor.ivslox
MicroWorld-eScanGen:Variant.Bulz.360963
TencentMalware.Win32.Gencirc.11c48392
Ad-AwareGen:Variant.Bulz.360963
SophosTroj/Conti-C
BitDefenderThetaGen:NN.ZedlaF.34050.mu4@aGW2Ljpi
McAfee-GW-EditionRansom-Conti!D7BF01F9FB24
FireEyeGeneric.mg.d7bf01f9fb24176f
EmsisoftGen:Variant.Bulz.360963 (B)
JiangminTrojan.Cryptor.vu
Antiy-AVLTrojan/Generic.ASMalwS.3340E5D
MicrosoftRansom:Win64/ContiCrypt.PE!MTB
ArcabitTrojan.Bulz.D58203
ZoneAlarmHEUR:Trojan-Ransom.Win32.Cryptor.gen
GDataGen:Variant.Bulz.360963
AhnLab-V3Ransomware/Win.Conti.R374597
McAfeeRansom-Conti!D7BF01F9FB24
MAXmalware (ai score=89)
VBA32BScope.Trojan.Agent
MalwarebytesTrojan.Downloader
PandaTrj/GdSda.A
RisingRansom.Conti!1.D637 (CLASSIC)
IkarusTrojan-Ransom.Conti
FortinetW32/Conti.N!tr.ransom
AVGWin32:Conti-B [Ransom]
Qihoo-360HEUR/QVM40.1.EF5F.Malware.Gen

How to remove Ransom:Win64/ContiCrypt.PE!MTB?

Ransom:Win64/ContiCrypt.PE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment