Sophos

W32/SillyFDC-N

Aliases
  • WORM_AGENT.EUJ
  • WORM_AGENT.FZW
  • Worm.Win32.Agent.o
  • W32/USBAgent.dll
  • virus
  • W32.SillyFDC
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 23 January 2007 02:44:07 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/SillyFDC-N is a multicomponent worm for the Windows platform.

W32/SillyFDC-N spreads through removeable storage devices, including floppy drives and USB keys. The worm attempts to create a hidden file Autorun.inf on the removeable drive and copy itself to the removeable drive with the filename autorun.exe

The file Autorun.inf is designed to start the worm once the removable drive is connected to an uninfected computer.

When first run W32/SillyFDC-N copies itself to:

<Windows>\java\classes\java.dll
<System>\kernel32.sys
<System>\mfc48.dll

The following registry entry is set to run the file kernel32.sys on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
kernel32.sys

The worm also sets the following registry entries:

HKCR\CLSID\{Random CLSID}\InprocServer32
@
<Windows>\java\classes\java.dll

HKCR\CLSID\\InprocServer32
@
<Windows>\java\classes\java.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\<CLSID>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer