Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | September 2007 (4.21) |
| Protection available since | 31 July 2007 07:36:29 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/SillyFDC-AO is a worm for the Windows platform that spreads via removable shared drives.
W32/SillyFDC-AO is a worm for the Windows platform that spreads via removable shared drives.When run W32/SillyFDC-AO sets the following registry entries to run itself on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
Asynchronous
1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
DLLName
<path to Worm DLL>
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
Impersonate
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
Shutdown
DoShutdown
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
Startup
DoStartup
W32/SillyFDC-AO also attempts to spread via removable shared drives by creating the file <Root>\Autorun.inf and creating the following file in the hidden folder <Root>\RECYCLER\RECYCLER:
desktop.ini - can be safely removed
