Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Protection available since | 30 October 2008 06:28:24 (GMT) |
| Last updated | 3 July 2009 00:09:12 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Koobfa-Gen is a family of worms for the Windows platform that target social networking sites including Facebook, MySpace, hi5, Bebo, Friendster, myYearbook, Tagged, Netlog and fubar.
The worms attempt to send messages to users of the social networking site pointing to a copy of themselves.
When first run, members of W32/Koobfa-Gen often display an error message saying:
Error installing Codec. Please contact support.
Members of W32/Koobfa-Gen often create a clean .dat data file called in the Windows folder, for example <Windows>\fmark2.dat.
Members of W32/Koobfa-Gen may create registry entries similar to the folowing:
HKLM\SYSTEM\ControlSet001\Control\Session manager\PendingFileRenameOperations
<blank>
\??\<path to worm>\??\<path to another executable>
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations
<blank>
\??\<path to worm>\??\<path to another executable>

