Home » Technology

Koobface worm hits Facebook

5 December 2008 10 Comments

Posted by Sherwin

koobface attacks facebook

A new variant of KoobFace, a dangerous kind of worm, has been attacking Facebook users this week. The virus can spread rapidly because they move through messages which appear to come from your pals.

So don’t be enticed by those sweet messages.

Those “friends” you have on Facebook might not actually be your friends. In fact, some of them might be scammers trying to infect your computer with this virus.

Even before the first virus struck, Kaspersky Lab the one who discovered the virus, had forecast that there would be a proliferation of these problems.

According to them, messages and comments on MySpace and Facebook include links to http://youtube.[skip].pl. If the user clicks on this link, s/he is redirected to http://youtube.[skip].ru, a site which purportedly contains a video clip. If the user tries to watch it, a message appears saying that s/he needs the latest version of Flash Player in order to watch the clip. However, instead of the latest version of Flash Player, a file called codecsetup.exe is downloaded to the victim machine; this file is also a network worm. The result is that users who have come to the site via Facebook will have the MySpace worm downloaded to their machines, and vice versa.

This attack on the world’s most popular social networking site and its 120 million users comes just weeks after Facebook won an $873 million lawsuit against several people accused of hacking user accounts and spreading spam.

Blog Widget by LinkWithin


  • http://www.spitrekop.com kuru

    my whole office got infected by this, and then some colleagues were fired because they were slacking too much

  • http://towelwavers.blogspot.com Hal

    too much social networking can cause harm to your PC.

  • http://top-rated-pc-security.com Terry Jackson

    Makes you scared to even login to your facebook account.. I hope facebook gets the problem fixed soon.

  • http://www.righteoushack.net/ Himuraken

    This has seriously impacted a clients network that I maintain. An unsuspecting user clicked on some FaceBook message garbage and managed to infect most of his friends/co-workers. Love it!

  • http://www.righteoushack.net/ Himuraken

    This has seriously impacted a clients network that I maintain. An unsuspecting user clicked on some FaceBook message garbage and managed to infect most of his friends/co-workers. Love it!

  • 03zx6r

    FB has not cleaned this up yet. It just infected a friend's facebook account and he has friend's replying to the “youtube” link indicating it's a virus, but he can no longer log in to do anything about it. And the fb admins have been notified but they haven't removed it yet…that's been two days ago.

  • 03zx6r

    FB has not cleaned this up yet. It just infected a friend's facebook account and he has friend's replying to the “youtube” link indicating it's a virus, but he can no longer log in to do anything about it. And the fb admins have been notified but they haven't removed it yet…that's been two days ago.

  • Pingback: The Value of Separate User Accounts « PowerUp! Blog

  • lynseysteward

    i just got infected with this virus yesterday…..'malwarebytes' got rid of the Koobface worm, and 'GooredFix' got rid of the file/service 'fioo32' which is a trojan dropper.

    i, amongst many others, where sent a link to our inbox from a facebook friend, and i stupidly clicked on it. i didnt click on the 'install latest flash player' though, as i found it a bit suspicious…..

    the message said something along the lines of;

    “Where you reallly in thiiiis videeo??” with a video link directly after it.

  • lynseysteward

    i just got infected with this virus yesterday…..'malwarebytes' got rid of the Koobface worm, and 'GooredFix' got rid of the file/service 'fioo32' which is a trojan dropper.

    i, amongst many others, where sent a link to our inbox from a facebook friend, and i stupidly clicked on it. i didnt click on the 'install latest flash player' though, as i found it a bit suspicious…..

    the message said something along the lines of;

    “Where you reallly in thiiiis videeo??” with a video link directly after it.