Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 21 May 2008 17:47:57 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/VKon-A spreads using the social networking site Vkontakte.ru.
W32/VKon-A executes its payload after 10am on the 25th day of the month. At this time it deletes files from the C: drive.
When run W32/VKon-A copies itself to <Application Data>\Vkontakte\svc.exe.
W32/VKon-A creates a registry entry at the following location so that it runs automatically at startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DurovVkon
<Application Data>\Vkontakte\svc.exe
