Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | January 2007 (4.13) |
| Protection available since | 24 November 2006 12:25:05 (GMT) |
| Last updated | 28 November 2006 20:06:15 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/SillyFDC-E is a worm for the Windows platform.
When run W32/SillyFDC-E copies itself to <System>\OfcpfwSv.exe.
The following registry entries are set to run OfcpfwSv.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
OfcpfwSv.exe
<System>\OfcpfwSv.exe
W32/SillyFDC-E attempts to periodically copy itself to removeable drives, including floppy drives and USB keys. The worm will attempt to create the hidden file Autorun.inf on the removeable drive and copy itself to the file \RECYCLER\RECYCLER\autorun.exe on the same drive. The file Autorun.inf is designed to start the worm once the removeable drive is connected to an uninfected computer.
W32/SillyFDC-E may create the file kas.exe. This file is detected as Troj/PcClien-WI.
