Technology news and Jobs arrow Information Technology News arrow Beware of Koobface the social worm
Beware of Koobface the social worm E-mail
by Stephen Withers   
Thursday, 04 December 2008
No, it's not the villain in the latest slasher movie - Koobface is a social networking worm affecting MySpace and Facebook. But like Jason and Freddie, Koobface refuses to die.

Register now to win a Canon EOS 500D Cannon EOS 500D Digiral SLR

PC Tools' ThreatFire research operation is reporting fresh infections of the Koobface worm.

Originally discovered in mid-2008, members of the Koobface family spread through social networking sites.

They work by sending bogus messages or comments to the infected user's friends.

These texts include links to malicious sites that purport to offer video clips. If visitors follow the link, they are told that they need to install a new version of Flash and are offered an 'updater' which is actually installs malware.

The installer loads backdoors onto the system, which in turn download additional malware. Koobface also modifies the local hosts file to prevent the system accessing major security providers including Trend, Symantec and Sophos.

One of the main clues that the so-called updater was actually Koobface is a dialog that says "Error installing Codec. Please contact support." or "Error installing Flash Update. Please contact support."

Although Koobface was detected by Kaspersky back in late July, it is still active according to ThreatFire.

According to a ThreatFire blog entry, the latest Koobface infections are installing and running a file named bolivar28.exe or similar, and the name of the 'updater' has changed from codecsetup.exe to flash_update.exe.

So be warned: if a site prompts you to install a codec or Flash update, don't take whatever is offered. Go directly to a recognised vendor's site (eg www.adobe.com for Flash) to make sure you get the real deal.

Please enable JavaScript in your browser to post your comment!

Tags See All Tags Add New Tag...

Please Enter New Tags Separated By Comma's
  Or Close

Facebook  Flash  Internet  Malware  MySpace  Social networks  Stephen Withers  Web  Web 2.0  Windows  Worm  Worms 
Powered By Joomla Tags

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
665,005
Subscribers 14,517
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter