Webware

Read all 'Koobface' posts in Webware
April 2, 2009 10:33 AM PDT

Microsoft helps keep Koobface virus off Facebook

by Elinor Mills
  • 5 comments

Microsoft is working with Facebook to keep the persistent Koobface virus off the popular social-networking site, the companies said on Thursday.

"In working with Facebook, we were able to add detection of Koobface to our Malicious Software Removal Tool (MSRT), which checks computers running Windows software to detect and remove viruses," Jeff Williams, a principal group program manager for the MRST, wrote in a guest post on the Facebook Blog.

The MSRT has removed Koobface nearly 200,000 times from more than 133,600 computers around the world just in the past two weeks, he wrote.

Koobface is a mass-mailing virus that arrives in Facebook users' in-boxes announcing a message like "You look funny in this new video." Clicking on the link takes recipients to a Web site where they are prompted to download a Trojan masked as an Adobe Flash update. The Trojan could allow an attacker to remotely steal a victim's Facebook password and other information or even use the computer to launch attacks on other computers.

Koobface has been around since August mostly targeting social networks, and a variant that targets only Facebook users surfaced in December. Facebook has been hit by at least one other version since then.

Details on how to protect against Koobface are on Facebook's security page.

Originally posted at Security
December 4, 2008 4:36 PM PST

Koobface virus hits Facebook

by Robert Vamosi
  • 45 comments

This message could lead you to the Koobface virus, say security experts.

(Credit: McAfee Avert Labs)

A worm responsible for sending Facebook users malicious code appears to be limited in nature, although the social engineering attack may be used again, say experts.

Facebook representative Barry Schnitt said the worm isn't new; it dates back to August, although the variant that first appeared on Wednesday targets only Facebook users.

Craig Schmugar, threat researcher for McAfee Avert Labs, confirmed this in a call with CNET News and said that, in general, Koobface strikes only social-networking sites.

After receiving a message in their Facebook in-box announcing, "You look funny in this new video" or something similar, recipients are then invited to click on a provided link. Once on the video site, a message says an update of Flash is needed before the video can be displayed. The viewer is prompted to open a file called flash_player.exe.

A new mass-mailing virus targeting Facebook users directs victims to a site asking to download a Trojan masked as an Adobe Flash update.

(Credit: McAfee Avert Labs)

Schmugar said the prompt for a new player should be a warning. "The messages you tend to get from these sites don't look quite right." For instance, IE will tell you where the update is coming from, and usually it's not an Adobe site.

If the viewer approves the Flash installation, Koobface attempts to download a program called tinyproxy.exe. This loads a proxy server called Security Accounts Manager (SamSs) the next time the computer boots up. Koobface then listens to traffic on TCP port 9090 and proxies all outgoing HTTP traffic. For example, a search performed on Google, Yahoo, MSN, or Live.com may be hijacked to other, lesser-known search sites.

Schmugar said this version of Koobface includes a bot-like component that could install other malicious apps at a later time.

Facebook's Schnitt said, "Only a very small percentage of Facebook users have been affected and we're working quickly to update our security systems to minimize any further impact, including resetting passwords on infected accounts, removing the spam messages, and coordinating with third parties to remove redirects to malicious content elsewhere on the Web."

Facebook has posted instructions on how to remove the infection.

McAfee's Schmugar said this attack is similar to e-mail attacks 10 years ago in that Koobface is using infected friends lists, reminiscent of early mass-mailing worms. As was the recommendation then, he advises users not to open any unexpected e-mail attachments, even if they are from someone you know.

Originally posted at Security
  • prev
  • 1
  • next
advertisement

About Webware

Say No to boxed software! The future of applications is online delivery and access. Software is passé. Webware is the new way to get things done.

Add this feed to your online news reader

Webware topics

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

Most Discussed

Inside CNET News

Scroll Left Scroll Right