Ransom

Ransom:Win32/Pitroxin.A removal guide

Malware Removal

The Ransom:Win32/Pitroxin.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Pitroxin.A virus can do?

  • Uses Windows utilities for basic functionality
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Writes a potential ransom message to disk
  • Anomalous binary characteristics

How to determine Ransom:Win32/Pitroxin.A?


File Info:

crc32: 73B23D12
md5: 55d69700887871670fce52fa7340219b
name: 55D69700887871670FCE52FA7340219B.mlw
sha1: 6b707938403ff87ce466637f1ba04c56ad135680
sha256: 18c0461c0ab207d11e5407c5b0f7156aa62252e2896799bf6b573497b41e0333
sha512: b9b461ac10d03d0f4103d94e6af49130447c387c81f31515f2ff80be17717dd8e3159b769b24bdad61ca6c14eabac1b26476a3cdbf830b7e2306d87fda0f882b
ssdeep: 1536:YNx32nZ7n9Ji4+IrLFAAi524020CVdDATOwt77X0goavwiv:Y/2nR9Ji4+IrLW240FCVBATEgoavP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Pitroxin.A also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052b6931 )
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.281
CynetMalicious (score: 100)
ALYacGeneric.Ransom.MBRLocker.2.307C6F65
CylanceUnsafe
ZillyaTrojan.Carbanak.Win32.7
SangforTrojan.Win32.Atosev.rfn
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanSpy:Win32/KillMBR.72cfe477
K7GWTrojan ( 0052b6931 )
Cybereasonmalicious.088787
CyrenW32/Carbanak.TVJG-0788
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/KillMBR.NCO
ZonerTrojan.Win32.66962
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.UselessDisk-6492359-0
KasperskyHEUR:Trojan-Spy.Win32.Carbanak.gen
BitDefenderGeneric.Ransom.MBRLocker.2.307C6F65
NANO-AntivirusTrojan.Win32.Carbanak.ezedbo
MicroWorld-eScanGeneric.Ransom.MBRLocker.2.307C6F65
TencentMalware.Win32.Gencirc.11492840
Ad-AwareGeneric.Ransom.MBRLocker.2.307C6F65
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34670.luX@aGF1h4f
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MBRLOCKER.SMALY
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.55d6970088787167
EmsisoftGeneric.Ransom.MBRLocker.2.307C6F65 (B)
JiangminTrojanSpy.Carbanak.a
AviraTR/KillMBR.wsjln
eGambitUnsafe.AI_Score_73%
Antiy-AVLTrojan[Spy]/Win32.Carbanak
MicrosoftRansom:Win32/Pitroxin.A
ArcabitGeneric.Ransom.MBRLocker.2.307C6F65
AegisLabTrojan.Win32.Carbanak.tpmX
GDataGeneric.Ransom.MBRLocker.2.307C6F65
TACHYONTrojan-Spy/W32.Carbanak.180265
AhnLab-V3Trojan/Win32.RL_DiskWriter.R355055
McAfeeGenericRXAA-AA!55D697008878
MAXmalware (ai score=80)
VBA32BScope.TrojanSpy.Carbanak
MalwarebytesRansom.Petya
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_MBRLOCKER.SMALY
RisingRansom.Pitroxin!1.B225 (CLOUD)
IkarusTrojan.Win32.KillMBR
FortinetW32/KillMBR.NCO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.MBRlock.HwIApQsA

How to remove Ransom:Win32/Pitroxin.A?

Ransom:Win32/Pitroxin.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment