Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | October 2007 (4.22) |
| Protection available since | 31 August 2007 06:04:52 (GMT) |
| Last updated | 31 August 2007 06:31:00 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/SillyFDC-AT is a multi-component worm for the Windows platform.
W32/SillyFDC-AT spreads through removable storage devices, including floppy drives and USB keys. The worm attempts to create a hidden file Autorun.inf on the removable drive and copy itself to the removable drive with the filename autorun.exe
The file Autorun.inf is designed to start the worm once the removable drive is connected to an uninfected computer.
When first run W32/SillyFDC-AT copies itself to:
<Windows>\java\classes\java.dll
<System>\kernel32.sys
<System>\mfc48.dll
The following registry entry is set to run the file kernel32.sys on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
kernel32.sys
The worm also sets the following registry entries:
HKCR\CLSID\{Random CLSID}\InprocServer32
<Windows>\java\classes\java.dll
HKCR\CLSID\\InprocServer32
<Windows>\java\classes\java.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\
