Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Protection available since | 30 November 2009 10:27:17 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/SillyFDC-EI is a worm for the Windows platform.
W32/SillyFDC-EI includes functionality to:
- run automatically
- access the internet and communicate with a remote server via HTTP
W32/SillyFDC-EI communicates via HTTP with the following locations:
filmbebas . com
bok3p . com
17tahun1 . com
downloadbokep . net
toketgadis . com
17tahun . us
syok3gp . net
cewekina . net
bokeps . com
duniasex . com
susuaku . us
When W32/SillyFDC-EI is installed the following files are created:
<Root>\Documents and Settings.lnk
<Root>\gnu.lnk
<Root>\INSTALLERS.lnk
<Root>\logs.lnk
<Root>\Perl.lnk
<Program Files>.lnk
<Root>\temp.lnk
<Windows>.lnk
<Root>\Autorun.inf
Registry entries are set as follows:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
EnableLUA
0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DefaultValue
0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt
0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0x00000000
Registry entries are created under:
HKLM\SOFTWARE\Microsoft\Security Center\Svc
HKLM\SOFTWARE\Microsoft\Security Center

