W32.SillyDC

W32.SillyDC Description


W32.SillyDC is a malicious network-aware Worm that detects variants of the W32.Silly family of viruses which spreads via removable media. Malware.SillyDC can download other malicious applications referenced in autorun.inf files that may be located on removable drives or network drives. W32.SillyDC will try to spread to other computers and should be removed from the infected computer upon detection.

Aliases

Worm.Win32.AutoRun.afcb (Kaspersky Lab)
Downloader-AZN.dr (McAfee)
Mal/Autorun-C (Sophos)
Trojan.Win32.Glox (Ikarus)
Packed/Upack (AhnLab)
packed with PE_Patch (Kaspersky Lab)

DOWNLOAD NOW

» Learn more about SpyHunter's Spyware Detection Tool
and steps to uninstall SpyHunter.


W32.SillyDC Automatic Detection Tool (Recommended)


Is your PC infected with W32.SillyDC? To safely & quickly detect W32.SillyDC we highly recommend you run the malware scanner listed below.



File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AllUsersProfile%\ming9df16.ini
    2 %System%\drivers\etc\hosts
    3 %Windir%\system\ming9b090423.exe
    4 %Windir%\system\nb9ming32c090423.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run]
Posted: November 17, 2009 | By
Share:
Rate this article:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Threat Metric
Threat Level: 5/10

Leave a Reply

What is 6 + 4 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)