Malware

W32/SillyFD-W (file analysis)

Malware Removal

The W32/SillyFD-W is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/SillyFD-W virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine W32/SillyFD-W?


File Info:

name: 15E8144878F75F829BC8.mlw
path: /opt/CAPEv2/storage/binaries/66ed1e744ed5671758e295833782338f867857f4e3a01b5967449530deae2fc4
crc32: 9F0EE240
md5: 15e8144878f75f829bc8fce7840e13eb
sha1: 077433068e6d3bc04853bbed39d9abf861c8fb46
sha256: 66ed1e744ed5671758e295833782338f867857f4e3a01b5967449530deae2fc4
sha512: e78a496a9b59b07bfca014e5b652f9be0857fd987991d6b91c64934645cc390df139b0babfd681b2621b0b01270fa7d1d622ab88357511b13c34de71de3a13f4
ssdeep: 6144:4mU3PFKs7aFwKWwalhrEqxF6snji81RUinKZHg/YS6:4mOPhAmZIH+YH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E34B7677F64A948F53A15F458F3C3F21292E84CCA47420B5B743A2A3EEBE461D24673
sha3_384: 8df59fd8dfbd51cd9d4b1279f75ab1a9167c5579371c7b4d11afe28ea4fe99065f5634ad4fe170016080fbe29aec8ed7
ep_bytes: 68a0124000e8f0ffffff000000000000
timestamp: 2012-05-03 05:51:34

Version Info:

0: [No Data]

W32/SillyFD-W also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.15339
MicroWorld-eScanTrojan.GenericKDZ.95863
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dt
McAfeeVBObfus.dv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.878f75
BitDefenderThetaAI:Packer.6DF855361E
VirITTrojan.Win32.VBCrypt.EVL
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AVM
APEXMalicious
TrendMicro-HouseCallTSPY_VOBFUS_BK08038F.TOMC
ClamAVWin.Malware.Vobfus-9940378-0
KasperskyWorm.Win32.Vobfus.dgsd
BitDefenderTrojan.GenericKDZ.95863
NANO-AntivirusTrojan.Win32.VB.rilqk
AvastWin32:VB-ACQT [Trj]
EmsisoftTrojan.GenericKDZ.95863 (B)
F-SecureTrojan.TR/Barys.992.JH.2
BaiduWin32.Worm.VB.aq
VIPRETrojan.GenericKDZ.95863
TrendMicroTSPY_VOBFUS_BK08038F.TOMC
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.15e8144878f75f82
SophosW32/SillyFD-W
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
JiangminTrojan/Generic.atfxu
GoogleDetected
AviraTR/Barys.992.JH.2
VaristW32/Vobfus.O.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.998
MicrosoftWorm:Win32/Vobfus.EV
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D17677
ViRobotTrojan.Win32.A.VB.233472.CB
ZoneAlarmWorm.Win32.Vobfus.dgsd
GDataTrojan.GenericKDZ.95863
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R26181
Acronissuspicious
VBA32SScope.Malware-Cryptor.VBCR.3042
TACHYONWorm/W32.Vobfus.233472.E
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingTrojan.FakeIcon!1.64A2 (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACQT [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Symmi.f0d2dd7c

How to remove W32/SillyFD-W?

W32/SillyFD-W removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment