support.com tech support community
Facebook Virus / Koobface Removal

Koobface (a play on the word Facebook), is a virus distributed via Facebook messaging, the Facebook Wall and other Facebook communication tools. The Facebook (Koobface) virus can turn your computer into a zombie and hijack your web browser.  Koobface attempts to automatically send Facebook messages to your Facebook friends list in an attempt to infect more computers.  Koobface has spread quickly to hundreds of thousands of computers because consumers are (not surprisingly) more likely to trust messages from friends.

There are two variants: Net-Worm.Win32.Koobface.a which is the Facebook variant, and Net-Worm.Win32.Koobface.b which is the MySpace variant.

As it happens I recently received a message from a Facebook friend that turned out to be a hook for the Koobface virus.  Here is the message I received in my Facebook inbox (as well as a similar message posted to my Facebook Wall):

What happens next falls into the "don't try this at home" category.  While I could tell from the message posting that it was a virus (telltale signs: an odd URL and a generic "Amazing Video" message that didn't sound like it came from the person sending the message),  I clicked on the link to document the experience and was taken to the following web page:

At this point you are still safe but red flags should be going off in your mind if you were tricked into click the Facebook link.  The red flags are things like this - the URL (web address) being an IP address (75.253...) vs. a website domain (like www.support.com).  The request immediately upon visiting the webpage to download a file (note the security warning from IE "To help protect your security").  The Adobe Flash Player upgrade request is completely bogus - and is the trick to get consumers to take the next step... which I did (don't do this at home!):

After allowing the download to proceed I am now one click away from infecting my computer.  The application "setup.exe" is the Koobface virus... not the Adobe Flash Player.  Windows gives you one more warning:

Note another red flag - the "Unknown Publisher".  Would the Adobe Flash Player really come from an Unknown Publisher?

If you were unfortunately tricked by the hackers you are among the thousands of consumers tricked everyday.  Some of the traps are more obvious than others - and hackers are looking for more insidious and clever ways to trick consumers.

The methods for virus removal are as diverse as the viruses themselves, and our Solutions Engineers are working every day to stay one step ahead of the hacker hordes.  If you believe Koobface has infected your computer call us at 1-800-PCSUPPORT.


Posted Sep 11 2009, 02:29 PM by jamesm@support.com

Comments

support.com Blog wrote Avoiding Cyber Security – and other Tricky Rogue Anti-Spyware
on 8 Oct 2009 4:53 AM

Rogue anti-spyware software is a class of bogus software that uses clever techniques to trick consumers

uberVU - social comments wrote Social comments and analytics for this post
on 9 Nov 2009 3:09 AM

This post was mentioned on Twitter by twitrvenky: http://bit.ly/1WMVqR | gud blog on nt 2 gt duped #virus