Home Malware Programs Worms Net.Worm.Koobface.ld

Net.Worm.Koobface.ld

Posted: July 2, 2009

Threat Metric

Threat Level: 9/10
Infected PCs: 9
First Seen: July 24, 2009
OS(es) Affected: Windows

Net.Worm.Koobface.ld is a worm that typically targets people using social networking websites, such as Facebook and MySpace. Net.Worm.Koobface.ld spreads by sending Facebook messages to people that are considered friends of yours. The messages contain harmless subject matter, but upon receipt, the message will redirect the individual to a third-party website, unaffiliated with the social networking site, where they are then prompted to download what is said to be an update to Adobe Flash player. Should the unsuspecting person choose to download this file, they will actually be inviting the Net.Worm.Koobface.ld worm into their computer. Once active, Net.Worm.Koobface.ld gathers sensitive information from your PC, such as credit card numbers, personal identity information, and more.

Aliases

PAK_Generic.001 [TrendMicro]Suspicious.MH690.A [Symantec]Mal/Generic-A [Sophos]a variant of Win32/Koobface.NBG [NOD32]Artemis!0ED3D94AF344 [McAfee+Artemis]Net-Worm.Win32.Koobface.ld [Kaspersky]Suspicious File [eSafe]Worm.Koobface-20 [ClamAV]Worm.Win32.Koobface!IK [a-squared]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



freddy44.exe File name: freddy44.exe
Size: 44.03 KB (44032 bytes)
MD5: 0ed3d94af344ebf0b30e2240a0f3f198
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
Loading...