Sophos

W32/SillyFDC-AO

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2007 (4.21)
Protection available since 31 July 2007 07:36:29 (GMT)
Detected by All Sophos products

Action

More Information

W32/SillyFDC-AO is a worm for the Windows platform that spreads via removable shared drives.

W32/SillyFDC-AO is a worm for the Windows platform that spreads via removable shared drives.

When run W32/SillyFDC-AO sets the following registry entries to run itself on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
Asynchronous
1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
DLLName
<path to Worm DLL>

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
Impersonate
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
Shutdown
DoShutdown

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
Startup
DoStartup

W32/SillyFDC-AO also attempts to spread via removable shared drives by creating the file <Root>\Autorun.inf and creating the following file in the hidden folder <Root>\RECYCLER\RECYCLER:

desktop.ini - can be safely removed

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer