Home Malware Programs Worms W32.SillyFDC.BAZ

W32.SillyFDC.BAZ

Posted: November 26, 2009

W32.SillyFDC.BAZ is a malicious network-aware Worm from the W32.Silly family of viruses which spread via removable media. W32.SillyFDC.BAZ can download other malicious applications referenced in autorun.inf files that may be located on removable drives or network drives. W32.SillyFDC.BAZ will try to spread to other computers and should be removed from the infected computer upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\system\ming9b090423.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run]
Loading...