Malware

ML/PE-A + W32/SillyFDC-IE removal tips

Malware Removal

The ML/PE-A + W32/SillyFDC-IE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + W32/SillyFDC-IE virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.musiczipz.com
ns1.musicmixa.net
ns1.musicmixa.org
ns1.musicmixb.co
ns1.musicmixc.com
edgedl.gvt1.com
update.googleapis.com

How to determine ML/PE-A + W32/SillyFDC-IE?


File Info:

crc32: 1F6C79BC
md5: edd55b96ffa1b39c90ee3a178d042354
name: EDD55B96FFA1B39C90EE3A178D042354.mlw
sha1: a3c4f76a0f6822bc7da2c1a6a5c2c40121944349
sha256: 99c02563a311b413c7f4569c67c56897853faf2fa232f913efe395f95d2e6029
sha512: a31759389ed1633394fd2d4fe1379d23daa7e0507d4774c55fab8f41c9c0da26bc9072da3a842649826d7fbb1c7619b7fc4ff1c70493e14afd2177c33744e356
ssdeep: 6144:8so87vTlIpr1f+XqO5pOmS3FON9zdLPmUngF:Q8rTlIB1f+5517lPmUgF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 7.08.0002
InternalName: gbjpsjzcoqdw
FileVersion: 7.08.0002
OriginalFilename: gbjpsjzcoqdw.exe
ProductName: kokmwfbqe

ML/PE-A + W32/SillyFDC-IE also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.2424
FireEyeGeneric.mg.edd55b96ffa1b39c
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Barys.2424
CylanceUnsafe
VIPRELooksLike.Win32.Beebone.gen (v)
AegisLabTrojan.Win32.Jorik.lwz0
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Barys.2424
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.34804.tm0@a4majdoi
CyrenW32/Vobfus.O.gen!Eldorado
SymantecW32.Changeup!gen20
ESET-NOD32a variant of Win32/Kryptik.AFGN
BaiduWin32.Worm.VB.av
APEXMalicious
AvastWin32:VB-ADDH [Trj]
ClamAVWin.Trojan.Vobfus-64
KasperskyWorm.Win32.WBNA.ipa
AlibabaWorm:Win32/VBInject.76074bc6
NANO-AntivirusTrojan.Win32.Vobfus.coonoo
RisingWorm.VobfusEx!1.99DC (CLASSIC)
Ad-AwareGen:Variant.Barys.2424
EmsisoftGen:Variant.Barys.2424 (B)
ComodoWorm.Win32.Pronny.AK@4ogvoo
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.15668
TrendMicroWORM_VOBFUS.SM00
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fh
SophosML/PE-A + W32/SillyFDC-IE
SentinelOneStatic AI – Malicious PE – Worm
JiangminTrojan/Vbobf.b
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftVirTool:Win32/VBInject.WX
ArcabitTrojan.Barys.D978
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AhnLab-V3Trojan/Win32.Jorik.R25213
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.Barys.2424
CynetMalicious (score: 100)
TotalDefenseWin32/Vobfus.AMD
McAfeeW32/Autorun.worm.aaeh
TACHYONTrojan/W32.Vobfus.319488
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Trojan.Dropper.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM00
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!Mw+z8LTh1EQ
IkarusVirus.Win32.Cryptor
MaxSecureTrojan.Vobfus.toz
FortinetW32/Jorik.EGLG!tr
AVGWin32:VB-ADDH [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Worm.3d4

How to remove ML/PE-A + W32/SillyFDC-IE?

ML/PE-A + W32/SillyFDC-IE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment