Sophos

W32/SillyFDC-M

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 22 January 2007 04:52:11 (GMT)
Last updated 23 January 2007 04:19:37 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

W32/SillyFDC-M is a worm for the Windows platform.

W32/SillyFDC-M also creates the following files on the infected computer;

<Windows>\cmd.com
<Windows>\svchost.com
<System>\driver.exe
<Windows>\wuaucll.exe

W32/SillyFDC-M attempts to periodically copy itself to removeable drives, including floppy drives and USB keys. The worm will attempt to create a hidden file Autorun.inf on the removeable drive and copy itself to the same location as the filename music.exe

The file Autorun.inf is designed to start the worm once the removeable drive is connected to a uninfected computer.

The following registry entry is changed to run wuaucll.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe wuaucll.exe

The following registry entry is set or modified, so that wuaucll.exe is run when files with extensions of EXE are opened/launched:

HKCR\exefile\shell\open\command
(default)
wuaucll.exe "%1" %*

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
3030

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer