Malware

Should I remove “W32/SillyFDC-GW”?

Malware Removal

The W32/SillyFDC-GW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/SillyFDC-GW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine W32/SillyFDC-GW?


File Info:

name: 327FF925C9993A3845E7.mlw
path: /opt/CAPEv2/storage/binaries/fe75881d58f773f5321dcb64d32493f769d61d41046cf961090dae1e7a4b73a0
crc32: 1E8ED463
md5: 327ff925c9993a3845e7db808cd4c921
sha1: d0c16e6d785f7f6a10c06d0597bdba2b3fe2a1eb
sha256: fe75881d58f773f5321dcb64d32493f769d61d41046cf961090dae1e7a4b73a0
sha512: 46d5c930ef2e7547ccea80886899f6b872e480f30e1bc6c1a8452fbe0ac4886f1672e7cd8a4729adcb2650c3827ad1f4c5adfe10bc95890f5348080ee58dda1c
ssdeep: 3072:Oge7ei5UYJVFV5eDQHsuvNA05Vqtto24VmcZMUuXi46qndrAxIbYps+:QN3JrLeDQHr+uV0to24VmlUuSvqdS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A33462197280F73ED524CAF47D4A4390683EAC7224A1A807F7D25F2A77B1D5BE221763
sha3_384: 52f8ab8a47772e4697501102a8f48ee1210b42d571a0632fb475bdd8cc4ba9e14386e82b68e2e2cb2d774674c52790c6
ep_bytes: 68e8434000e8f0ffffff000000000000
timestamp: 2012-01-19 06:47:10

Version Info:

Translation: 0x0409 0x04b0
ProductName: XNlMkPyO
FileVersion: 1.00
ProductVersion: 1.00
InternalName: BRxavZXMJb
OriginalFilename: BRxavZXMJb.exe

W32/SillyFDC-GW also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-COM [Trj]
tehtrisGeneric.Malware
DrWebWorm.Siggen.11130
MicroWorld-eScanGen:Variant.Chinky.7
FireEyeGeneric.mg.327ff925c9993a38
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eq
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Chinky.7
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.36802.om0@ae!@@chi
VirITTrojan.Win32.Diple.EMQE
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.AC
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:AutoRun-COM [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dfgw
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.Barys.fdudjv
EmsisoftGen:Variant.Chinky.7 (B)
F-SecureTrojan.TR/Dldr.Agent.22354
BaiduWin32.Trojan.Inject.n
TrendMicroWORM_VOBFUS.SMKA
Trapminemalicious.high.ml.score
SophosW32/SillyFDC-GW
SentinelOneStatic AI – Malicious PE
JiangminWorm.Vobfus.kuhl
GoogleDetected
AviraTR/Dldr.Agent.22354
MAXmalware (ai score=85)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Chinky.7
ViRobotTrojan.Win32.A.Diple.233472.J
ZoneAlarmWorm.Win32.Vobfus.dfgw
GDataGen:Variant.Chinky.7
VaristW32/Vobfus.AI.gen!Eldorado
AhnLab-V3Trojan/Win32.Diple.R20591
Acronissuspicious
ALYacGen:Variant.Chinky.7
TACHYONWorm/W32.Vobfus.233472
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SMKA
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!bbDJSc+Zc84
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Jorik_Vobfus.FELF!tr
ZonerTrojan.Win32.86803
Cybereasonmalicious.5c9993
DeepInstinctMALICIOUS

How to remove W32/SillyFDC-GW?

W32/SillyFDC-GW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment