Selected viruses, spyware, and other threats: sorted alphabetically
Short description
The worm sends links to VKontakte.ru users. If the link is clicked a copy of the worm is retrieved from the Internet. Installation
When executed, the worm copies itself in the %appdata%\Vkontakte\ folder using the following name: - svc.exe
- deti.jpg
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run]
"DurovVkon" = "%filepath%" - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run]
"DurovVkon" = "%filepath%"
- Durov VKontakte Service
Spreading
The worm sends links to VKontakte.ru users. If the link is clicked a copy of the worm is retrieved from the Internet. Other information
The worm may display the following file: deti.jpg The worm opens the file using the default image viewer. If the current system date and time matches certain conditions, the worm attempts to delete all files and folders stored on available drives.
It avoids those with any of the following strings in their names:
- ntldr
- bootmgr
The worm displays a window titled
- Павел Дуров
- Работая с "ВКонтакте.РУ" Вы ни разу не повышали свой рейтинг и поэтому мы не получили от Вас прибыли. За это Ваш компьютер будет уничтожен!
- Если обратитесь в милицию, то сильно пожалеете об этом!
- С уважением, Павел Дуров.

