LCI Learning

Share on Facebook

Share on Twitter

Share on LinkedIn

Share on Email

Share More

kartikeya (lawyer/cyber law consultant/cyber crime investigator)     03 March 2010

koobface - beware of this worm

 

Koobface, an anagram of Facebook, is a computer worm that targets the users of the social networking websites Facebook, MySpace, hi5, Bebo, Friendster and Twitter. Koobface ultimately attempts, upon successful infection, to gather sensitive information from the victims such as credit card numbers. It was first detected in December 2008 and a more potent version appeared in March 2009.

Koobface spreads by delivering Facebook messages to people who are 'friends' of a Facebook user whose computer has already been infected. Upon receipt, the message directs the recipients to a third-party website, where they are prompted to download what is purported to be an update of the Adobe Flash player. If they download and execute the file, Koobface is able to infect their system. It can then commandeer the computer's search engine use and direct it to contaminated websites.

Among the components downloaded by Koobface are a DNS filter program that blocks access to well known security websites and a proxy tool that enables the attackers to abuse the infected PC.

Several variants of the worm have been identified:

Net-Worm.Win32.Koobface.a, which attacks MySpace

Net-Worm.Win32.Koobface.b, which attacks Facebook.

WORM_KOOBFACE.DC, which attacks Twitter.

W32/Koobfa-Gen, which attacks Facebook, MySpace, hi5, Bebo, Friendster, myYearbook, Tagged, Netlog, Badoo and fubar.

The Windows operating system is currently the only operating system affected by this worm. Microsoft's Malicious Software Removal Tool, an antivirus program released to Windows Update twice a month, removes Koobface and other viruses/spyware, and cleaned over 800,000 computers of Koobface and similar threats



Learning

 2 Replies

Daksh (Student)     03 March 2010

Dear Friend Kartikeya,

Thanks a tonne for such relevant, timely, well compressed and informative post.

Please tell us more whether apart from virus scanning anything else is required or resorting to Microsoft's Malicious Software Removal Tool, an antivirus program released to Windows Update is a must.

God bless

Best Regards

Daksh

kartikeya (lawyer/cyber law consultant/cyber crime investigator)     03 March 2010

koobface sneaks into your computer and replicates itself throughout the PC. Koobface is a worm and attacks a computer by downloading some .exe files into your computer.

Basically if you are using facebook you should watch for automated email messages that display either insulting message or some thing very tempting about you. Messages like, "you look funny in this video" or "you look so stupid in this pic" can be used to persuade somone to click on the link attached. Once the user clicks on them it takes you to a video which doesn't play and they ask you to download certain codecs which can be a 'flassh_player.exe' file.

If the file is downloaded your computer becomes open to Koobface malware. It downloads a file 'tinyproxy.exe' which hijacks your PC. It can even alter search results from google,yahoo etc and redirect you to websites selling malicious softwares.

get a good malware remover which can automatically detect and remove it and keep changing ur password frequently and ur password should be strong.


Leave a reply

Your are not logged in . Please login to post replies

Click here to Login / Register