NANO Antivirus / About / News / Trojan targeting social network users

24 July 2009
Trojan targeting social network users

 
NANO Antivirus analysts have discovered a new variant of a Trojan targeting users of the social networks "Odnoklassniki" and "VKontakte", as well as users of the "Yandex Mail" service.

This malware sample has been named VkHost.af (according to our classification). Infection occurs when other malware already present on the computer downloads the Trojan without the user's knowledge. When visiting the resources listed above from an infected computer, messages appear demanding that the user send a supposedly free SMS to a specified number to activate the account:
 
 



 

 

Traditionally, malware authors are not known for literacy, and the abundance of errors in these supposedly service messages can give the scam away. The fraudsters' goal is to force the user to send an expensive SMS to a premium-rate number.

To regain access to the blocked resources, do not send the "free" SMS to the number provided. First use NANO Antivirus to remove the Trojan from the infected computer. Then replace the hosts file in the system directory %sysdir%\drivers\etc\hosts with the hosts1 file in the same directory (for example, if you are running Windows XP, the required file will be at the following path: windows\system32\drivers\etc\hosts).