Sophos

Sophos blogs

W32/SillyFDC-AP

Aliases
  • Win32/Autoit.AC
  • worm
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 7 September 2007 07:39:10 (GMT)
Last updated 12 February 2009 11:45:37 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/SillyFDC-AP is an autorun worm for the Windows platform.

When run the worm will first attempt to terminate msconfig.exe, rstrui.exe, regedit.exe and taskmgr.exe as well as anti-virus software before copying itself to <System>\msmsgs.exe, <System>\system.exe and \ESET\nod32.exe.

W32/SillyFDC-AP will also create the following registry entry to auto-start:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Msmsgs
<System>\msmsgs.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SYS1
<System>\system.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SYS2
<System>\bad1.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SYS3
<System>\bad2.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SYS4
<System>\bad3.exe

The worm will then attempt to copy itself to removable media as well as download components from the web to <System>\bad1.exe <System>\bad2.exe <System>\bad3.exe.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer