Malware

Win32/Pitou.K removal instruction

Malware Removal

The Win32/Pitou.K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Pitou.K virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to restart the guest VM
  • Spoofs its process name and/or associated pathname to appear as a legitimate process

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com
update.googleapis.com

How to determine Win32/Pitou.K?


File Info:

crc32: 5E14A543
md5: cc2648b41b0594e44ab8d23d1a5afe27
name: CC2648B41B0594E44AB8D23D1A5AFE27.mlw
sha1: a1e8e745f8b369dda91de3b96429a1cfe5193016
sha256: 230e27010dde41fcff9136f08658979cdc5939abcd8ea5cb59f79cdf80155cc2
sha512: 18452a808d14987c6ecd6a0fc3c65d55a9681e2c9de773588924a4f0ca28d00cfd503f12f7738090eb1a9c7199a9b6bd9adb5d65a8f301fb81053e425765e6d1
ssdeep: 12288:P6nxs56HE8YvLsOLfVZioItuc8FCNqfBqaVjICdO5ya6l6kJy8PJdHptvJ3z3H:PBzz7f7k/8FCNqwaRICmya+fnPvl7H
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Pitou.K also known as:

K7AntiVirusTrojan ( 0051ac071 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Bootkit.GenericKD.32283820
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0051ac071 )
Cybereasonmalicious.41b059
SymantecTrojan Horse
ESET-NOD32Win32/Pitou.K
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyBackdoor.Win32.Backboot.ez
BitDefenderTrojan.Bootkit.GenericKD.32283820
MicroWorld-eScanTrojan.Bootkit.GenericKD.32283820
TencentWin32.Backdoor.Backboot.Syrm
Ad-AwareTrojan.Bootkit.GenericKD.32283820
SophosMal/Generic-S
ComodoMalware@#2o1vnugfboptr
BitDefenderThetaGen:NN.ZexaF.34142.5qW@aS18sFei
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPURSNIF.SMZD2
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.cc2648b41b0594e4
EmsisoftTrojan.Bootkit.GenericKD.32283820 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Backboot.ac
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1128819
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Azorult!ml
ArcabitTrojan.Bootkit.Generic.D1EC9CAC
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmBackdoor.Win32.Backboot.ez
GDataTrojan.Bootkit.GenericKD.32283820
AhnLab-V3Win-Trojan/Sagecrypt.Gen
Acronissuspicious
McAfeeArtemis!CC2648B41B05
MAXmalware (ai score=94)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_HPURSNIF.SMZD2
RisingTrojan.Generic@ML.91 (RDML:/8d2Rtiq6CHrPAJ8f7GQdw)
YandexBackdoor.Backboot!UGafjTVO/tY
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Pitou.K!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove Win32/Pitou.K?

Win32/Pitou.K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment