Antivirus and Security Software from Sophos

Sophos blogs

W32/SillyFDC-EI

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Protection available since 30 November 2009 10:27:17 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/SillyFDC-EI is a worm for the Windows platform.

W32/SillyFDC-EI includes functionality to:

 - run automatically
 - access the internet and communicate with a remote server via HTTP

W32/SillyFDC-EI communicates via HTTP with the following locations:

   filmbebas . com
   bok3p . com
   17tahun1 . com
   downloadbokep . net
   toketgadis . com
   17tahun . us
   syok3gp . net
   cewekina . net
   bokeps . com
   duniasex . com
   susuaku . us

When W32/SillyFDC-EI is installed the following files are created:

<Root>\Documents and Settings.lnk
<Root>\gnu.lnk
<Root>\INSTALLERS.lnk
<Root>\logs.lnk
<Root>\Perl.lnk
<Program Files>.lnk
<Root>\temp.lnk
<Windows>.lnk
<Root>\Autorun.inf

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
EnableLUA
0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DefaultValue
0x00000001

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
0x00000001

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0x00000000

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\Security Center\Svc
HKLM\SOFTWARE\Microsoft\Security Center

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer