W32.SillyFDC virus

jRand's picture

Background:
Currently running Symantec AV 10.1.5.5002
I need assistance with interpreting or coming to a conclusion of where certain  types of files are originating from.

We have workstations that are provided from a vendor with their custom WinXP w/SP3 image installed on the harddrive.   These workstations are on their own separate subnet.and internet access has been blocked.  After the machines are shipped to us we network them,  join the windows domain server, install symantec from the network, and then we perform a Full scan of the workstation harddrives and we find the files below.  The scan detects the W32.SillyFDC virus.  Once thing to note is that we only detect this type of virus on the workstations provided from the vendor.  The vendor has Symantec EP11 and they scan their image and nothing is flagged.  We are trying to determine if these files are false positives or if our SAV client settings are set  too agressively in detecting this particular virii.
Any information you provide would be greatly appreciated.

Virus Detected: w32.SillyFDC
Files Detected:
c:\windows\system32\odbcasvc.exe
c:\documents and settings\sbuser\local settings\temp\s.exe
c:\windows\system32\recycled\info.exe
d:\recycled\info.exe
c:\windows\uda.exe

Thanks in advance.

Filed under: ,
teiva-boy's picture

 The silly virus was known to

 The silly virus was known to spread through infected removable storage, aka thumb drives and the like.


There is an online portal, save yourself the long hold times. Create ticket online, then call in with ticket # in hand :-)
http://mysupport.symantec.com

"We backup data to restore, we don't backup data just to back it up."

jRand's picture

Is it possible to get this

Is it possible to get this type of virus through a network share?  Everyone claims no one  uses a USB stick drive when setting up these workstations.  Also, everyone's telling me that our virus detection level is too sensitive, and our heuristic scanning settings are set to use Bloodhound virus detection technology with default level of protection.   Any thoughts?

Thanks again.