Malware

How to remove “Win32/Filecoder.Conti.K”?

Malware Removal

The Win32/Filecoder.Conti.K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Conti.K virus can do?

  • Creates RWX memory
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs

How to determine Win32/Filecoder.Conti.K?


File Info:

crc32: B69C3EC5
md5: 390d5e1f5e996b7e7b09b5e9fc030bed
name: 390D5E1F5E996B7E7B09B5E9FC030BED.mlw
sha1: 29179742e1653c1a9a31488c577c48bc558e6c38
sha256: d1f09689b4328f75473906a44ed57eface89170049d25cd22c94a871d3674faa
sha512: 1f86cc6aa78417de3663878a002145587e3dc5fb4a8f75a6baa50510f7da7fc6da1355b97e68d43c4d21bbc390e5e224934684fd890688044cc98a9614980484
ssdeep: 3072:6C3T2z7lRNj7US4IroIZzUtKe6oibrpYjOe8RYUTXzH4LBcS:T2z7lRNj77ffWKe65ZI8YuS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.Conti.K also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005749d01 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Conti
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.17627
SangforRansom.Win32.Genasom.mt
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000027
K7GWTrojan ( 005749d01 )
Cybereasonmalicious.f5e996
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Conti.K
APEXMalicious
AvastWin32:Conti-B [Ransom]
KasperskyHEUR:Trojan-Ransom.Win32.Cryptor.gen
BitDefenderGen:Variant.Zusy.356529
NANO-AntivirusTrojan.Win32.Cryptor.illzzl
ViRobotTrojan.Win32.S.Ransom.200192.A
MicroWorld-eScanGen:Variant.Zusy.356529
TencentWin32.Trojan.Cryptor.Ligz
Ad-AwareGen:Variant.Zusy.356529
SophosMal/Generic-S
ComodoMalware@#63vvpaxnsw63
F-SecureHeuristic.HEUR/AGEN.1138121
BitDefenderThetaGen:NN.ZexaF.34790.muW@a46wiufi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Ransom
FireEyeGeneric.mg.390d5e1f5e996b7e
EmsisoftGen:Variant.Zusy.356529 (B)
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1138121
Antiy-AVLTrojan/Generic.ASMalwS.3137D9E
MicrosoftRansom:Win32/Conti.ZC
ArcabitTrojan.Zusy.D570B1
AegisLabTrojan.Multi.Generic.4!c
GDataGen:Variant.Zusy.356529
AhnLab-V3Malware/Win32.Generic.C4075041
McAfeeRDN/Ransom
MAXmalware (ai score=100)
VBA32BScope.Trojan.Mansabo
MalwarebytesRansom.FileLocker
PandaTrj/GdSda.A
RisingRansom.Conti!1.D637 (CLASSIC)
IkarusTrojan-Ransom.Conti
FortinetW32/Conti.F!tr.ransom
AVGWin32:Conti-B [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cryptor.HwoC8ckA

How to remove Win32/Filecoder.Conti.K?

Win32/Filecoder.Conti.K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment