Malware

Mal/SillyFDC-T malicious file

Malware Removal

The Mal/SillyFDC-T is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/SillyFDC-T virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/SillyFDC-T?


File Info:

name: A9499ABF33683B9DBB62.mlw
path: /opt/CAPEv2/storage/binaries/bb6887a84e8686785122f6e488b4b13d051a630dc9c2144335da36e84c96abf5
crc32: 1BF24B9E
md5: a9499abf33683b9dbb6211e69d99c147
sha1: 1a31f003e8c05d55f0719db985231a4d8c594354
sha256: bb6887a84e8686785122f6e488b4b13d051a630dc9c2144335da36e84c96abf5
sha512: 7410b8c4a2a0760a41e33b4307fc72556aa9b28ab1eecf20f3b65d2a92ec6de89f413bab4c37bdde7c864510a707015684ed75d857d8f3cea93deec7821edfea
ssdeep: 3072:7lfofGL02W2N0fAU9x5Ea3hN4oQZiEgCl:ZcGL012efAU9x5BxfWSI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ACE3A2297781F23ED425CAF4391982E0907DAC3521D6AC17FBC25B1AB3F1DAB9220757
sha3_384: a0a4215bc465f61b1710d4dfa270b3459a6238da9289b3096b0162f77f5efd909551d73d640e1dcebf63ad7e7ff1f783
ep_bytes: 68bc344000e8f0ffffff000000000000
timestamp: 2011-09-03 04:05:17

Version Info:

Translation: 0x0409 0x04b0
ProductName: lHILbZNLjaSfJz
FileVersion: 1.00
ProductVersion: 1.00
InternalName: CRVegtGCEW
OriginalFilename: CRVegtGCEW.exe

Mal/SillyFDC-T also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.luev
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.60
MicroWorld-eScanTrojan.GenericKDZ.83535
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.a9499abf33683b9d
CAT-QuickHealTrojan.Vobfus.gen
ALYacTrojan.GenericKDZ.83535
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/VBKrypt.5a6c
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.f33683
BitDefenderThetaAI:Packer.F977E3CC20
VirITWorm.Win32.Generic.AYMK
CyrenW32/Vobfus.V.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AKY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VBKrypt.gkqk
BitDefenderTrojan.GenericKDZ.83535
NANO-AntivirusTrojan.Win32.VBKrypt.etcoes
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Koobface.p
TACHYONWorm/W32.Vobfus.143360.C
EmsisoftTrojan.GenericKDZ.83535 (B)
F-SecureWorm.WORM/Vobus.N.1
BaiduWin32.Worm.Pronny.d
VIPRETrojan.GenericKDZ.83535
TrendMicroWORM_VOBFUS.SMHE
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10I69CR
AviraWORM/Vobus.N.1
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D1464F
ZoneAlarmTrojan.Win32.VBKrypt.gkqk
MicrosoftWorm:Win32/Vobfus.gen!N
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R13793
McAfeeVBObfus.at
MAXmalware (ai score=84)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.Vobfus!1.99C7 (CLASSIC)
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/SillyFDC-T?

Mal/SillyFDC-T removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment