Koobface

Koobface Description

Koobface is a worm that infects computers by using the messaging system of social networks like Facebook and MySpace. Other Koobface known variants are Boface, W32.Koobface, Net-Worm.Win32.Koobface.b, and W32/Koobface. The Koobface worm attacks profiles by sending an email to a user's Facebook inbox with subjects like "You look just awesome in this new movie" or "You look funny in this new video" and the email message provides a link to a malicious video website. The malicious video website will prompt the user to download the fake video codec file flash_player.exe under the assumption that the user needs to update the Flash program to view a video. The flash_player.exe is really a doorway meant to let Koobface infect your computer.

Once installed, Koobface downloads a program called tinyproxy.exe. Tinyproxy.exe loads a proxy server called Security Accounts Manager which Koobface uses to monitor traffic on TCP port 9090 and proxies all outgoing HTTP traffic. Koobface hijacks search results from search engines like Google, Yahoo, and MSN and replaces the results with links of malicious websites.

Koobface may redirect you to malicous websites that sell rogue security tools. Koobface has the ability to recreate itself after reboot. It is strongly recommended to remove Koobface from your system upon detection.

Aliases


Worm.Win32.Koobface.bnWin-Trojan/Injecter.17920.ES [AhnLab-V3]Trojan.Win32.Downloader.17920.GQTrojanDownloader.Injecter.abxTrojan.Dropper.Koobface.AEJ [McAfee-GW-Edition]DR/Koobface.AEJ [AntiVir]Trojan.DownLoad.40118 [DrWeb]TrojWare.Win32.TrojanDownloader.Injecter.ddn0 [Comodo]Worm.Koobface-125 [ClamAV]W32/Downldr2.FZRM [F-Prot]Trojan.DL.Injecter.BRLTrojan/Downloader.Injecter.ddnTrojanDownloader.Injecter.ddn [CAT-QuickHeal]Trojan-Downloader/W32.Injecter.17920.WArtemis!10377EFE296F [McAfee+Artemis]
More aliases (3069)

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Koobface may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner

Note: SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware tool to remove the malware threats. Learn more on SpyHunter. If you would like to uninstall SpyHunter for any reason, please follow these uninstall instructions. To learn more about our policies and practices, visit our EULA, Privacy Policy and Threat Assessment Criteria.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\swe.dll File name: swe.dll
Size: 64.51 KB (64512 bytes)
MD5: b008856fa107fb14dbfb01ac4bc7ff0a
Detection count: 1,426
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32\
Group: Malware file
Last Updated: November 8, 2010
%WINDIR%\system32\drivers\PDRV.sys File name: PDRV.sys
Size: 39.29 KB (39296 bytes)
MD5: 07e86b47b742f78855ea14b68f4b6fea
Detection count: 1,183
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\drivers\
Group: Malware file
Last Updated: September 7, 2010
%WINDIR%\system32\mas.dll File name: mas.dll
Size: 49.15 KB (49152 bytes)
MD5: 0ca69d528f881daf9553dd969b16a276
Detection count: 1,091
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32\
Group: Malware file
Last Updated: November 9, 2010
%WINDIR%\system32\drivers\mas.sys File name: mas.sys
Size: 28.03 KB (28032 bytes)
MD5: 2428166634a56621d224f2f8883ebb0d
Detection count: 1,031
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\drivers\
Group: Malware file
Last Updated: November 9, 2010
%windir%\system32\fio32.dll File name: fio32.dll
Size: 50.68 KB (50688 bytes)
MD5: c1448afa4012e692b85c2755a112c33c
Detection count: 90
File type: Dynamic link library
Mime Type: unknown/dll
Path: %windir%\system32\
Group: Malware file
Last Updated: September 15, 2010
mrxoko.sys File name: mrxoko.sys
Size: 32.76 KB (32768 bytes)
MD5: c52a4b688b5ba67181cd809c5204a18c
Detection count: 86
File type: System file
Mime Type: unknown/sys
Group: Malware file
Last Updated: April 1, 2010
bill110.exe File name: bill110.exe
Size: 77.31 KB (77312 bytes)
MD5: 4fb5e6eea077e43c95c65f072c608c91
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 18, 2010
bill109.exe File name: bill109.exe
Size: 74.75 KB (74752 bytes)
MD5: 7e35f37167c894c5b4a9c29a1648dcf2
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 18, 2010
o6ko.sys File name: o6ko.sys
Size: 32.76 KB (32768 bytes)
MD5: 97422c4896c4ce5cf4ff38500918c069
Detection count: 76
File type: System file
Mime Type: unknown/sys
Group: Malware file
Last Updated: March 19, 2010
bill105.exe File name: bill105.exe
Size: 62.97 KB (62976 bytes)
MD5: f5927d6e2879c1ac0dddfe8876fadd99
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 25, 2010
kenny17.exe File name: kenny17.exe
Size: 19.45 KB (19456 bytes)
MD5: a5581a695cc8c52157aa9d413032bbb8
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 19, 2010
fbtre6.exe File name: fbtre6.exe
Size: 17.4 KB (17408 bytes)
MD5: 1fa5b4771e4d4e9f6dff52521b2d9bfd
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 23, 2010
kenny14.exe File name: kenny14.exe
Size: 21.5 KB (21504 bytes)
MD5: 6a4f4328cd6168a8cb20b9c473fb2607
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 19, 2010
che6.exe File name: che6.exe
Size: 21.5 KB (21504 bytes)
MD5: 8ea9e442bf3a56a171086a58d23a3aa3
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 23, 2010
bolivar27.exe File name: bolivar27.exe
Size: 29.69 KB (29696 bytes)
MD5: cbd1298e9c3a9d62e0404c18593479b3
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 23, 2010
bill106.exe File name: bill106.exe
Size: 51.71 KB (51712 bytes)
MD5: eb5b7849efbe793e13ebf102eecd77b9
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 30, 2010
dl1.exe File name: dl1.exe
Size: 324.09 KB (324096 bytes)
MD5: e9d1edceed62b10b8324d2ae46f8bc6f
Detection count: 51
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 30, 2010
%WINDIR%\system32\certoko.dll File name: certoko.dll
Size: 128 KB (128000 bytes)
MD5: 9392b9eaab4b07b1b1696f350caf7397
Detection count: 42
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32\
Group: Malware file
Last Updated: October 28, 2010
%WINDIR%\system\svchost.exe File name: svchost.exe
Size: 40.44 KB (40448 bytes)
MD5: 55d39b196e1ac496a355e9bc16de3ba1
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system\
Group: Malware file
Last Updated: November 2, 2010
ndisoko.sys File name: ndisoko.sys
Size: 32.76 KB (32768 bytes)
MD5: 7597e155a66a2ab97e2195255757e1a4
Detection count: 13
File type: System file
Mime Type: unknown/sys
Group: Malware file
Last Updated: April 8, 2010

More files

Registry Modifications


The following newly produced Registry Values are:

File name without pathld14.exeRun keysCaptcha7

Related Posts

Posted: December 5, 2008
Threat Metric
Threat Level: 5/10
Infected PCs 6,389

4 Comments

Leave a Reply

Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter. If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.