Beware of Koobface the social worm

Beware of Koobface the social worm

Postby Stephen Withers » Thu Dec 04, 2008 1:15 pm

No, it's not the villain in the latest slasher movie - Koobface is a social networking worm affecting MySpace and Facebook. But like Jason and Freddie, Koobface refuses to die.

PC Tools' ThreatFire research operation is reporting fresh infections of the Koobface worm.

Originally discovered in mid-2008, members of the Koobface family spread through social networking sites.

They work by sending bogus messages or comments to the infected user's friends.

These texts include links to malicious sites that purport to offer video clips. If visitors follow the link, they are told that they need to install a new version of Flash and are offered an 'updater' which is actually installs malware.

The installer loads backdoors onto the system, which in turn download additional malware. Koobface also modifies the local hosts file to prevent the system accessing major security providers including Trend, Symantec and Sophos.

One of the main clues that the so-called updater was actually Koobface is a dialog that says "Error installing Codec. Please contact support." or "Error installing Flash Update. Please contact support."

Although Koobface was detected by Kaspersky back in late July, it is still active according to ThreatFire.

According to a ThreatFire blog entry, the latest Koobface infections are installing and running a file named bolivar28.exe or similar, and the name of the 'updater' has changed from codecsetup.exe to flash_update.exe.

So be warned: if a site prompts you to install a codec or Flash update, don't take whatever is offered. Go directly to a recognised vendor's site (eg www.adobe.com for Flash) to make sure you get the real deal.


Article Link at http://www.itwire.com/content/view/22086/53/
Stephen Withers
 
Posts: 1991
Joined: Tue May 27, 2008 10:39 am

Re: Beware of Koobface the social worm

Postby Guest » Thu Dec 04, 2008 1:35 pm

Any ideas how to remove it ?
User avatar
Guest
 

Re: Beware of Koobface the social worm

Postby Guest » Thu Dec 04, 2008 3:15 pm

Guest wrote:Any ideas how to remove it ?


I just rana malwarebytes scan and it removed it. Still had to go into the settings for each browser and correct the proxy settings which the worm had reset. You can get details on that here....

http://miekiemoes.blogspot.com/2008/10/ ... usion.html
User avatar
Guest
 

Re: Beware of Koobface the social worm

Postby Mark » Fri Dec 05, 2008 5:02 am

Any ideas on how to remove this?
User avatar
Mark
 

Re: Beware of Koobface the social worm

Postby Maybe_Factor » Fri Dec 05, 2008 12:00 pm

If it's so hard to get rid of then prevention is probably a good option. My advice is to use your head, get updates directly from the original authors instead of downloading and running exe files from MySpace(obviously not a good idea). Going to the original author of the software ensures(in most cases) you actually end up with the updates instead of viruses.
User avatar
Maybe_Factor
 


Return to Information technology news

Who is online

Users browsing this forum: No registered users and 3 guests