W32/Koobfa-Gen

Category: Viruses and Spyware Protection available since:02 Jul 2009 21:15:48 (GMT)
Type: Win32 worm Last Updated:02 Jul 2009 21:15:48 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Koobfa-Gen is a family of worms for the Windows platform that target social networking sites including Facebook, MySpace, hi5, Bebo, Friendster, myYearbook, Tagged, Netlog and fubar.

The worms attempt to send messages to users of the social networking site pointing to a copy of themselves.

When first run, members of W32/Koobfa-Gen often display an error message saying:

  Error installing Codec. Please contact support.

Members of W32/Koobfa-Gen often create a clean .dat data file called in the Windows folder, for example <Windows>\fmark2.dat.

Members of W32/Koobfa-Gen may create registry entries similar to the folowing:

HKLM\SYSTEM\ControlSet001\Control\Session manager\PendingFileRenameOperations
<blank>
\??\<path to worm>\??\<path to another executable>

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations
<blank>
\??\<path to worm>\??\<path to another executable>

download Try Sophos products for free
Download now