Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 19 November 2007 10:15:16 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/SillyFDC-BK is a worm for the Windows platform.
When run W32/SillyFDC-BK copies itself to <Windows>\krag.exe and sets the following registry entry to run itself on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
krag
<Windows>\krag.exe
W32/SillyFDC-BK spreads via removable shared drives by copying itself to <Root>\krage.exe and creating the file <Root>\autorun.inf (detected as W32/Agent-FOW). The file <Root>\autorun.inf is designed to run the worm when the removable drive is connected to an uninfected computer.
