Malware

How to remove “VirTool:WinNT/Pitou.B”?

Malware Removal

The VirTool:WinNT/Pitou.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:WinNT/Pitou.B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Oriya
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to restart the guest VM
  • Uses IOCTL_SCSI_PASS_THROUGH control codes to manipulate drive/MBR which may be indicative of a bootkit
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Attempted to write directly to a physical drive

How to determine VirTool:WinNT/Pitou.B?


File Info:

name: E257AAECC4BCC3014392.mlw
path: /opt/CAPEv2/storage/binaries/00ade4ca7c14de504e3feeb567b4b19e91514310174ae019206fa394308391ef
crc32: 00E9611C
md5: e257aaecc4bcc3014392aced5bb11d0c
sha1: 25e5d6bab793dd37416af875ef7ebdd33ba76ff4
sha256: 00ade4ca7c14de504e3feeb567b4b19e91514310174ae019206fa394308391ef
sha512: 43ee962789baecf48ad9eefc54a0405d76a63394bcf2de79cf78c4701485415d2018787a3df35fe7d0e0e3e0e4e071290bf0bffb15944863f455a6abf498a5d1
ssdeep: 12288:gCyAOpFbYsJvHnYR4chmFRdTxLysTbU0slD1Mla0wNEM7unn5:r4p9Ysim1P40sV2a0sLc5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108C4013135EAD570C7530E7048288AA41E7BBC615960944BE7947F8EAFB1EEC86F131E
sha3_384: 3debf6274e4f2a28a48598fe4cece1548679b6b9df9e9bc120a541ebabe34253174a7f4c190aca1522238ca8c59f5d19
ep_bytes: e850440000e979feffffcccccccccccc
timestamp: 2020-12-15 08:48:56

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.27
Translation: 0x0127 0x046a

VirTool:WinNT/Pitou.B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.46790
FireEyeGeneric.mg.e257aaecc4bcc301
ALYacGen:Variant.Fragtor.46790
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
K7GWHacktool ( 700007861 )
Cybereasonmalicious.ab793d
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyVHO:Exploit.Win32.Convagent.gen
BitDefenderGen:Variant.Fragtor.46790
Ad-AwareGen:Variant.Fragtor.46790
SophosML/PE-A + Troj/Krypt-BO
EmsisoftGen:Variant.Fragtor.46790 (B)
IkarusTrojan-Ransom.StopCrypt
GDataGen:Variant.Fragtor.46790
eGambitUnsafe.AI_Score_81%
MicrosoftVirTool:WinNT/Pitou.B
CynetMalicious (score: 100)
Acronissuspicious
McAfeeLockbit-FSWW!E257AAECC4BC
MAXmalware (ai score=84)
VBA32BScope.TrojanDropper.Convagent
CylanceUnsafe
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazoPJMyAes45KWlSpEzw8oev)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34084.Ju0@a87jlGPG
CrowdStrikewin/malicious_confidence_100% (D)

How to remove VirTool:WinNT/Pitou.B?

VirTool:WinNT/Pitou.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment