Ransom

Ransom:Win32/Kitoles.A removal instruction

Malware Removal

The Ransom:Win32/Kitoles.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Kitoles.A virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Modifies boot configuration settings
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
iplogger.com
iplogger.org
ocsp.comodoca.com

How to determine Ransom:Win32/Kitoles.A?


File Info:

crc32: 3B7FF1DC
md5: 7ba57e8e2a5b4e708fcd2055daaee31a
name: 7BA57E8E2A5B4E708FCD2055DAAEE31A.mlw
sha1: f7731960b4e34f3c476fdd01b1e9e5652de4b6c8
sha256: 17b15d86274d28470067a245d5d9be91590dff58e61ca0aa00c6348b915fc207
sha512: 37308ddd3a7bb7c105acf889e4be04cb6f55378fd1d63f881cc7873b935ec3cdd6b5dda5e26ebd9a14d5b229a747380446bccbc9dca5e6da758b838248343847
ssdeep: 1536:0ZbDLwqmhnZF7vB94vkX8sJarpR+eAsVc4BkPMYsrv2I:0ZXLcXF1D3ar77VcnUYS2
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/Kitoles.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26375
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.D20B665D
FireEyeGeneric.mg.7ba57e8e2a5b4e70
ALYacDeepScan:Generic.Ransom.Amnesia.D20B665D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004f6e981 )
BitDefenderDeepScan:Generic.Ransom.Amnesia.D20B665D
K7GWTrojan ( 004f6e981 )
Cybereasonmalicious.e2a5b4
BitDefenderThetaAI:Packer.8568EE4A16
SymantecRansom.CryptXXX
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Scarab-6336012-1
KasperskyHEUR:Trojan-Ransom.Win32.Generic
NANO-AntivirusTrojan.Win32.Filecoder.esjrok
RisingRansom.FileCryptor!8.1A7 (CLOUD)
Ad-AwareDeepScan:Generic.Ransom.Amnesia.D20B665D
TACHYONRansom/W32.DP-Scarab.190976
SophosMal/Generic-S
ComodoMalware@#290x938xtn86c
F-SecureTrojan.TR/Crypt.ULPM.Gen
ZillyaTrojan.Filecoder.Win32.6793
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
EmsisoftDeepScan:Generic.Ransom.Amnesia.D20B665D (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bvqvi
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Kitoles.A
ArcabitDeepScan:Generic.Ransom.Amnesia.D20B665D
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataDeepScan:Generic.Ransom.Amnesia.D20B665D
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!7BA57E8E2A5B
MAXmalware (ai score=100)
VBA32Trojan.Encoder
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Filecoder.FS
TrendMicro-HouseCallMal_Purge
TencentWin32.Trojan.Filecoder.Akph
YandexTrojan.GenAsa!8Lbdq5qQE3M
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Msht.GJ!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Virus.b30

How to remove Ransom:Win32/Kitoles.A?

Ransom:Win32/Kitoles.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment