Malware

W32/SillyFDC-HZ (file analysis)

Malware Removal

The W32/SillyFDC-HZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/SillyFDC-HZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine W32/SillyFDC-HZ?


File Info:

name: D08E204BA7E9F95C6E08.mlw
path: /opt/CAPEv2/storage/binaries/73396d30ca59d5f0a3e38dd2fb3fd274890cfab74003dc12f88fc2c4698803db
crc32: 063E0F5E
md5: d08e204ba7e9f95c6e0808580d0c40e3
sha1: 8ba86bacb99b58d5ff270ace9ccf02e7e2565b70
sha256: 73396d30ca59d5f0a3e38dd2fb3fd274890cfab74003dc12f88fc2c4698803db
sha512: 5124cf3cc28f3a4d2be6709ebf4664ef3f9846e4ee75d1e24c745fdc2b5242622d992146307a277578f5089a5c37e0428b3bd954407fb296c1f18dcb20ec6ef2
ssdeep: 1536:q0xPseTIqXFixXVG4e2JLBJ3Ue05znybzPe9j5wo7JaSi:nseTI2FixFG4e1ybGVwQU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183D34F7F3F0600A5E4741578D2E3E7D22BE5784A5E17E1AAB72063681CEBE251C2CB53
sha3_384: a08af4613046e23bc0f4e3903dd0b10038d0479f07f940a2cb6953f0e456b98c964d55066c88f0d00ea32c3d1bfeb8f3
ep_bytes: 6898124000e8f0ffffff000000000000
timestamp: 2012-04-14 15:28:30

Version Info:

0: [No Data]

W32/SillyFDC-HZ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94628
FireEyeGeneric.mg.d08e204ba7e9f95c
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.ct
McAfeeVBObfus.dv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36802.imW@a4O!f@pi
VirITTrojan.Win32.VBCrypt.EVI
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.BWI
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SM41
ClamAVWin.Trojan.Vobfus-51
KasperskyTrojan.Win32.Vobfus.rds
BitDefenderTrojan.GenericKDZ.94628
NANO-AntivirusTrojan.Win32.Vobfus.dxrptx
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:GenMalicious-FAD [Trj]
TencentWorm.Win32.Vobfus.h
TACHYONTrojan/W32.Vobfus.135168
EmsisoftTrojan.GenericKDZ.94628 (B)
BaiduWin32.Worm.Autorun.v
F-SecureTrojan.TR/Barys.629.jh.2
DrWebWin32.HLLW.Autoruner2.25006
VIPRETrojan.GenericKDZ.94628
TrendMicroWORM_VOBFUS.SM41
Trapminemalicious.high.ml.score
SophosW32/SillyFDC-HZ
IkarusWorm.Win32.Vobfus
GoogleDetected
AviraTR/Barys.629.jh.2
VaristW32/Vobfus.AO.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Generic.D171A4
ZoneAlarmTrojan.Win32.Vobfus.rds
GDataTrojan.GenericKDZ.94628
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R23689
Acronissuspicious
VBA32SScope.Malware-Cryptor.VBCR.1641
MAXmalware (ai score=87)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99E1 (CLASSIC)
YandexTrojan.GenAsa!AWN33uNqfj8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:GenMalicious-FAD [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.f0a27513

How to remove W32/SillyFDC-HZ?

W32/SillyFDC-HZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment