Sophos

W32/SillyFDC-K

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Removable storage devices
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2008 (4.36)
Protection available since 11 January 2007 07:00:45 (GMT)
Last updated 13 October 2008 15:03:38 (GMT)
Detected by All Sophos products

Action

More Information

W32/SillyFDC-K is a worm for the Windows platform.

When run W32/SillyFDC-K copies itself to

C:\music.exe

The following registry entries are set to run W32/SillyFDC-K on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
music
<path to worm executable>

W32/SillyFDC-K also creates the following files on the infected computer

<Windows>\backup.reg - sets the above registry entry
<Windows>\runreg.bat - runs backup.reg
/Autorun.inf - automatically executes C:\music.exe

W32/SillyFDC-K attempts to periodically copy itself to removeable drives, including floppy drives and USB keys. The worm will attempt to create a hidden file Autorun.inf on the removeable drive and copy itself to the same location as the filename music.exe

The file Autorun.inf is designed to start the worm once the removeable drive is connected to a uninfected computer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer