Malware

Win32/Filecoder.Conti.Z removal tips

Malware Removal

The Win32/Filecoder.Conti.Z is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Conti.Z virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Performs a large number of encryption calls using the same key possibly indicative of ransomware file encryption behavior
  • Exhibits possible ransomware file modification behavior
  • CAPE detected the Conti malware family

How to determine Win32/Filecoder.Conti.Z?


File Info:

name: 5FF3A8043FFCFFCBDA9E.mlw
path: /opt/CAPEv2/storage/binaries/34b6057c2cab6c15488df8f0b8d86c48148596b7b0622cb8c9fb1572c9edf7d1
crc32: C4A20980
md5: 5ff3a8043ffcffcbda9e0259cb788bde
sha1: 5df33ec7912c69cd874886d14d95db6adb076100
sha256: 34b6057c2cab6c15488df8f0b8d86c48148596b7b0622cb8c9fb1572c9edf7d1
sha512: ce4eafe4959c6b4c5eef8b3da24f9ba87eb07f8d772ae5927f9d7beed8b10e06da21c4cbabe14bf9a0df43d8f19582e232d907e0e69c2fa7ae4789f8200999ba
ssdeep: 3072:1LvJt6c5RVs2jbPi6Bz1DPsGT5BfGIA6mhpF4aQFNKW2OBcwA6o+yL8398o:1dtJ3z66ZlPsmaIAHhkFNuOmL83+o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9044B06A24D4779FABA18753AF56A72746DAC38634F89FBB7C2471405709C12232F73
sha3_384: 77d64663cf266d13e71388ed6281bb4746d7d4e446bf4ffd0cf4e3ae6b322497024814fc726d05a23922eaab656b8b38
ep_bytes: e8e0020000e98efeffff558becf64508
timestamp: 2022-07-21 16:38:15

Version Info:

0: [No Data]

Win32/Filecoder.Conti.Z also known as:

MicroWorld-eScanGen:Variant.Midie.110183
FireEyeGeneric.mg.5ff3a8043ffcffcb
CAT-QuickHealRansom.Conti.S28488557
ALYacGen:Variant.Midie.110183
CylanceUnsafe
Cybereasonmalicious.43ffcf
SymantecRansom.Conti!gen12
ElasticWindows.Ransomware.Conti
ESET-NOD32a variant of Win32/Filecoder.Conti.Z
APEXMalicious
ClamAVWin.Ransomware.Conti-9808002-0
KasperskyVHO:Trojan-Ransom.Win32.Gen.gen
BitDefenderGen:Variant.Midie.110183
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Conti-B [Ransom]
Ad-AwareGen:Variant.Midie.110183
EmsisoftGen:Variant.Midie.110183 (B)
VIPREGen:Variant.Midie.110183
TrendMicroRansom.Win32.CONTI.SM.hp
McAfee-GW-EditionBehavesLike.Win32.NetLoader.ch
Trapminemalicious.moderate.ml.score
SophosTroj/Conti-E
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Midie.110183
GoogleDetected
AviraHEUR/AGEN.1213270
MicrosoftRansom:Win32/Conti.AD!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Ransom.R485853
McAfeeGenericRXSR-QO!5FF3A8043FFC
MAXmalware (ai score=87)
VBA32BScope.Trojan.Mansabo
MalwarebytesRansom.Conti
TrendMicro-HouseCallRansom.Win32.CONTI.SM.hp
RisingRansom.Conti!1.DF1E (CLASSIC)
IkarusTrojan-Ransom.Conti
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Conti.F!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34592.lyW@a4pjzVdi
AVGWin32:Conti-B [Ransom]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Filecoder.Conti.Z?

Win32/Filecoder.Conti.Z removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment