Malware

Exploit:Win32/Pidief.C (file analysis)

Malware Removal

The Exploit:Win32/Pidief.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit:Win32/Pidief.C virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Exploit:Win32/Pidief.C?


File Info:

crc32: F8EE04D9
md5: afd45ff9ffb916ac05f29e04f82f71d6
name: AFD45FF9FFB916AC05F29E04F82F71D6.mlw
sha1: aa35e4895522ea17b1faef48720b9a25c7a57e28
sha256: f919d1292f5eed5d62d7f971a50474ca731c7b2b430e8bda938580a8f00fc0fc
sha512: 96fd8ce1ffd513f073d82a11af7fe260ab6ea2e7d9f0e5e26f71138946a0b7bfd48cf6e42d1f89c939df7a371e2f7dee0dea20ed5e6493ce46f7991971f2ee4e
ssdeep: 768:9xvGZ8NczNXNrVWRugHIb7+yG3xMK87iDi4LkaE/QKc5t/D+JMDGJWnq:9kzXVougovxHzakblc5tSZ
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) Microsoft Corp. 1981-1999
InternalName: spoolss.exe
FileVersion: 5.00.2195.7059
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Windows (R) 2000 Operating System
ProductVersion: 5.00.2195.7059
FileDescription: Spooler SubSystem App
OriginalFilename: spoolss.exe
Translation: 0x0409 0x04b0

Exploit:Win32/Pidief.C also known as:

MicroWorld-eScanTrojan.Generic.1870643
Qihoo-360HEUR/QVM19.1.Malware.Gen
McAfeeW32/Tefo
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderTrojan.Generic.1870643
K7GWTrojan ( 005623171 )
K7AntiVirusTrojan ( 005623171 )
SymantecTrojan.Patchep!inf
APEXMalicious
AvastWin32:Trojan-gen
AlibabaExploit:Win32/Pidief.70bafef7
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
Ad-AwareTrojan.Generic.1870643
EmsisoftTrojan.Generic.1870643 (B)
ComodoMalware@#317c2uobcu5rl
F-SecureExploit.EXP/Pidief.nvufh
TrendMicroCryp_Xed-15
McAfee-GW-EditionBehavesLike.Win32.Virut.pm
FireEyeTrojan.Generic.1870643
SophosMal/Generic-S
IkarusTrojan.Win32.Patched
WebrootW32.Malware.Gen
AviraEXP/Pidief.nvufh
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftExploit:Win32/Pidief.C
ArcabitTrojan.Generic.D1C8B33
GDataTrojan.Generic.1870643
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZexaF.34804.cm0@aiBQyPgi
ALYacTrojan.Generic.1870643
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Spy
MalwarebytesMalware.Heuristic.1004
PandaGeneric Suspicious
ESET-NOD32a variant of Generik.JAAYWFX
TrendMicro-HouseCallCryp_Xed-15
TencentWin32.Trojan.Xed.Lsca
YandexTrojanSpy.Agent!4RoBsQj6J48
eGambitGeneric.Malware
FortinetW32/Tefo.A
AVGWin32:Trojan-gen
Cybereasonmalicious.9ffb91

How to remove Exploit:Win32/Pidief.C?

Exploit:Win32/Pidief.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment