Malware

Bootkit.Pitou removal instruction

Malware Removal

The Bootkit.Pitou is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bootkit.Pitou virus can do?

  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to restart the guest VM
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
redirector.gvt1.com
r4—sn-4g5ednss.gvt1.com
update.googleapis.com

How to determine Bootkit.Pitou?


File Info:

crc32: 1BFE095F
md5: 0104780bca1a942cb7e77cd7c55a9f67
name: 200k.exe
sha1: 190e3d708caf5587f3f32842e3aaa6daf4dccd00
sha256: 9056a4e93e2d6737646d02f678c15acc303845c89f310895eff1621e4d8ed6cb
sha512: a3ceef9e0bc6d1b7ea31b54f415a7c8c1deb55f8ead0c06f8949d2dfc950d3aaa4e5e7563fb44caadb2e5376c7101e767a219e429453b74123ef4c463ce05917
ssdeep: 12288:ez5ladQkUxh87uMdkmHeXnyuVXkuH3JzmmSkJiPSmGsHXI:y5la6kUM7uMmmHaRkuHbSkJtmGCI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bootkit.Pitou also known as:

MicroWorld-eScanGen:Variant.Kazy.330705
FireEyeGeneric.mg.0104780bca1a942c
ALYacGen:Variant.Kazy.330705
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0051ac701 )
BitDefenderGen:Variant.Kazy.330705
K7GWTrojan ( 0051ac701 )
Cybereasonmalicious.bca1a9
TrendMicroTROJ_GEN.R002C0DEL20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Pitou-A [Rtk]
ClamAVWin.Trojan.Agent-7856084-0
GDataGen:Variant.Kazy.330705
KasperskyBackdoor.Win32.Backboot.axm
AlibabaTrojan:Win32/Bulta.b139f8dd
ViRobotTrojan.Win32.S.Agent.431104.CF
AegisLabTrojan.Win32.Backboot.m!c
TencentWin32.Backdoor.Backboot.Ka
Ad-AwareGen:Variant.Kazy.330705
SophosMal/Generic-S
ComodoTrojWare.Win32.Injector.ZRA@54s8j9
F-SecureTrojan.TR/Crypt.XPACK.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
CMCTrojan.Win32.Swizzor.1!O
EmsisoftGen:Variant.Kazy.330705 (B)
IkarusTrojan.Win32.Pitou
CyrenW32/Trojan.YQBW-1364
WebrootW32.Gen.BT
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_97%
Endgamemalicious (high confidence)
ArcabitTrojan.Kazy.D50BD1
ZoneAlarmBackdoor.Win32.Backboot.axm
MicrosoftTrojan:Win32/Bulta!rfn
AhnLab-V3Trojan/Win32.Tepfer.R96475
Acronissuspicious
McAfeeGenericRXHQ-SA!0104780BCA1A
MAXmalware (ai score=89)
VBA32Malware-Cryptor.General.3
MalwarebytesBootkit.Pitou
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Pitou.K
TrendMicro-HouseCallTROJ_GEN.R002C0DEL20
RisingBackdoor.Backboot!8.DE4B (CLOUD)
SentinelOneDFI – Malicious PE
FortinetW32/Pitou.A!tr
BitDefenderThetaAI:Packer.48CF8FD21F
AVGWin32:Pitou-A [Rtk]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Win32/Trojan.dbd

How to remove Bootkit.Pitou?

Bootkit.Pitou removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment