W32/Koobfa-Gen is a family of worms for the Windows platform that target social networking sites including Facebook, MySpace, hi5, Bebo, Friendster, myYearbook, Tagged, Netlog and fubar.
The worms attempt to send messages to users of the social networking site pointing to a copy of themselves.
When first run, members of W32/Koobfa-Gen often display an error message saying:
Error installing Codec. Please contact support.
Members of W32/Koobfa-Gen often create a clean .dat data file called in the Windows folder, for example <Windows>\fmark2.dat.
Members of W32/Koobfa-Gen may create registry entries similar to the folowing:
HKLM\SYSTEM\ControlSet001\Control\Session manager\PendingFileRenameOperations
<blank>
\??\<path to worm>\??\<path to another executable>
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations
<blank>
\??\<path to worm>\??\<path to another executable>