Threat Database Worms W32.SillyFDC.BCT

W32.SillyFDC.BCT

By SpideyMan in Worms

W32.SillyFDC.BCT is a computer worm that propagates by infecting removable storage devices and file-sharing networks, infecting other computers when the storage device is connected to them. W32.SillyFDC.BCT may also create a registry entry so that the worm begins running every time Windows starts up.

File System Details

W32.SillyFDC.BCT may create the following file(s):
# File Name Detections
1. %Temp%\cvasds0.dll
2. %Temp%\herss.exe
3. %System%\drivers\cdaudio.sys
4. %SystemDrive%\xs6kpr0.exe
5. %System%\dllcache\cdaudio.sys

Registry Details

W32.SillyFDC.BCT may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVPsys\"ErrorControl" = "1"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVPsys\"Type" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"ShowSuperHidden" = "1"
HKEY_CLASSES_ROOT\CLSID\MADOWN\"urlinfo" = "[MM-DD HH:MM:SS]] From:[IP ADDRESS]:http:\\gir88e. [REMOVED] Port 80\0a\0aSERVER_SOFTWARE=Apache\2.2.0 (Fedora)\0aSERVER_NAME=gir88e"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVPsys\"DisplayName" = "AVPsys"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVPsys\"Start" = "3"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\"Hidden" = "2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\"NoDriveTypeAutoRun" = "181"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"cdoosoft" = "%Temp%\herss.exe"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVPsys\"ImagePath" = "%System%\drivers\cdaudio.sys"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVPsys\Security\"Security" = "[BINARY DATA]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\"CheckedValue" = "1"

Trending

Most Viewed

Loading...