Sophos

W32/SillyFDC-AT

Aliases
  • Worm.Win32.Agent.o
  • W32/USBAgent.dll
  • WORM_AGENT.LOL
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2007 (4.22)
Protection available since 31 August 2007 06:04:52 (GMT)
Last updated 31 August 2007 06:31:00 (GMT)
Detected by All Sophos products

Action

More Information

W32/SillyFDC-AT is a multi-component worm for the Windows platform.

W32/SillyFDC-AT spreads through removable storage devices, including floppy drives and USB keys. The worm attempts to create a hidden file Autorun.inf on the removable drive and copy itself to the removable drive with the filename autorun.exe

The file Autorun.inf is designed to start the worm once the removable drive is connected to an uninfected computer.

When first run W32/SillyFDC-AT copies itself to:

<Windows>\java\classes\java.dll
<System>\kernel32.sys
<System>\mfc48.dll

The following registry entry is set to run the file kernel32.sys on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
kernel32.sys

The worm also sets the following registry entries:

HKCR\CLSID\{Random CLSID}\InprocServer32
<Windows>\java\classes\java.dll

HKCR\CLSID\\InprocServer32
<Windows>\java\classes\java.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer