Malware

Win32:Gardih removal guide

Malware Removal

The Win32:Gardih is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Gardih virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ylsn.site

How to determine Win32:Gardih?


File Info:

crc32: 40388E9F
md5: 034b939250cee2873d0174a18113de1b
name: s.exe
sha1: b531601de939be24a556e60404f5c7867a6e1740
sha256: b45ca2cfbf87509f2add1de6f797d6bbbe2cf630599d3eb19407cea6f0d8ea96
sha512: b54e9947b11ddf1ec285fbfd8adaf89af6552123ce49dcfd28ba5e2c97aca4b3766d9818a66a8f078ab0ede563d10e454263eb28a186fff88f80718f24415ef0
ssdeep: 12288:ha2e2tgegXna8Q6Ujr4IFpvBqJi5TqVeZ6HnzkgE1:ha2eaCKb68rzpvBqJ++VU6H7O
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2002
InternalName: GetFileAttr
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: GetFileAttr x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: GetFileAttr Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: GetFileAttr.EXE
Translation: 0x0804 0x04b0

Win32:Gardih also known as:

BkavW32.KillJeefo
MicroWorld-eScanWin32.Jeefo.B
FireEyeGeneric.mg.034b939250cee287
CAT-QuickHealW32.Jeefo.A
Qihoo-360Virus.Win32.Jeefo.A
McAfeeW32/Jeefo.e
CylanceUnsafe
VIPREVirus.Win32.Jeefo.a (v)
AegisLabVirus.Win32.Hidrag.tn6g
SangforMalware
K7AntiVirusVirus ( 00001b701 )
BitDefenderWin32.Jeefo.B
K7GWVirus ( 00001b701 )
Cybereasonmalicious.250cee
Invinceaheuristic
BitDefenderThetaAI:FileInfector.7B5783490D
F-ProtW32/Jeefo.A
SymantecW32.Jeefo
TotalDefenseWin32/Jeefo.A
BaiduWin32.Virus.Hidrag.a
APEXMalicious
AvastWin32:Gardih
ClamAVWin.Trojan.Jeefo-3
GDataWin32.Virus.Hidrag.A
KasperskyVirus.Win32.Hidrag.a
AlibabaVirus:Win32/Jeefo.7e3347c9
NANO-AntivirusTrojan.Win32.Jeefo.gjxzsw
ViRobotWin32.Hidrag
TencentVirus.Win32.Jeefo.b
Endgamemalicious (high confidence)
TACHYONVirus/W32.Hidrag
SophosW32/Jeefo-A
ComodoWin32.Jeefo.A@1fda
F-SecureMalware.W32/Jeefo.A
DrWebWin32.HLLP.Jeefo.36352
ZillyaVirus.Jeefo.Win32.1
TrendMicroPE_JEEFO.E
Trapminemalicious.high.ml.score
EmsisoftWin32.Jeefo.B (B)
SentinelOneDFI – Malicious PE
CyrenW32/Jeefo.OYRV-0749
JiangminWin32/Jeefo
AviraW32/Jeefo.A
Antiy-AVLVirus/Win32.Hidrag.a
KingsoftWin32.HiDrag.a.363008
MicrosoftVirus:Win32/Jeefo.A
ArcabitWin32.Jeefo.B
ZoneAlarmVirus.Win32.Hidrag.a
CynetMalicious (score: 100)
AhnLab-V3Win32/Hidrag
Acronissuspicious
VBA32Virus.Jeefo
ALYacWin32.Jeefo.B
MAXmalware (ai score=88)
Ad-AwareWin32.Jeefo.B
MalwarebytesVirus.Jeefo
PandaGeneric Malware
ZonerVirus.Win32.403
ESET-NOD32Win32/Jeefo.A
TrendMicro-HouseCallPE_JEEFO.E
RisingWin32.HiDrag.a (CLASSIC)
YandexWin32.Hidrag
IkarusVirus.Win32.Hidrag
eGambitUnsafe.AI_Score_100%
FortinetW32/Jeefo.A
AVGWin32:Gardih
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureVirus.W32.HIDRAG.A

How to remove Win32:Gardih?

Win32:Gardih removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment