Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | December 2008 (4.36) |
| Protection available since | 11 January 2007 07:00:45 (GMT) |
| Last updated | 13 October 2008 15:03:38 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for disinfecting PE executables.
More Information
W32/SillyFDC-K is a worm for the Windows platform.
When run W32/SillyFDC-K copies itself to
C:\music.exe
The following registry entries are set to run W32/SillyFDC-K on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
music
<path to worm executable>
W32/SillyFDC-K also creates the following files on the infected computer
<Windows>\backup.reg - sets the above registry entry
<Windows>\runreg.bat - runs backup.reg
/Autorun.inf - automatically executes C:\music.exe
W32/SillyFDC-K attempts to periodically copy itself to removeable drives, including floppy drives and USB keys. The worm will attempt to create a hidden file Autorun.inf on the removeable drive and copy itself to the same location as the filename music.exe
The file Autorun.inf is designed to start the worm once the removeable drive is connected to a uninfected computer.
