Koobface Still Causing Problems for Facebook Users

by Albin on August 19th, 2009 in Security Alert.

The KoobFace worm is still causing troubles in the wild. The picture below shows a malicious link which spreads through popular social networks. The link is sent from a trustworthy source (friends) inside the social network. A majority of users will most likely check it out.

If users choose to click the link, they'll be redirected to a malicious download site.

This site is constructed in a “phishing manner”. The malware authors use a reliable Facebook interface to entice users to download an upgrade of flash player in order to watch a non-existant video, as the picture above shows.

The next step in the social engineering chain is the download of a file called setup.exe. This is the “parent file” for the Koobface infection.  The worm will download and install additional malicious files without the user's consent. After a few minutes, unexpected browser windows will be opened.  The malware authors want to bring in money by pushing the user to install and purchase a fake anti-virus solution.

The KoobFace infection also drops a file called DDnsFilter.dll which redirects and controls the traffic. It lets users surf on google.com but blocks access to security sites like lavasoft.com and kaspersky.com, as the picture below shows. This functionality is built-in to actively prevent users from being able to clean the infection.

The bottom line: don’t trust links on social networks, even if they're sent by your best friend. Be especially cautious if the link leads to download a file with a .exe extension, which is considered suspicious behavior. Lavasoft Malware Labs detects this worm under the name Win32.Worm.KoobFace.

Albin

Lavasoft Malware Labs

Adaware was able to zap the

User offline. Last seen 2 years 25 weeks ago.arletta_shenfeld
Joined: 2009-08-26
Posts: 0

Adaware was able to zap the Trojan that left the problems - but my computer will not allow me to delete the DDNS.DLL file. (And as a result I can't access any websites and can't get virus/spyware updates!). How can I delete this file, other than going into DOS mode and deleting the file the old fashioned way.


I have just contributed to the MyLavasoft community.

Hi arletta ! Which version of

User offline. Last seen 1 year 30 weeks ago.Albin
Beta tester
Joined: 2008-12-02
Posts: 0

Hi arletta !


Which version of Ad-Aware do you run? DDNS.DLL should be able to remove with Ad-Aware's "bootscan" . You may have to restart your system to remove the malicous file.


Thanks


Albin


Lavasoft Malware Labs


Blog
Ad-Aware 10 Early Preview
February 20th - Jerome
Ad-Aware 10 – beta version available
February 14th - hyu.kim
Don't Let Cupid Lead You To Trouble.
January 31st - News Editor
February Spam Warning: Valentine’s Day Security
January 31st - News Editor
Twitter
Lavasoft: Want your computer to run smoothly? It’s easy, just verify that your browser is the most updated version. Here’s why: http://t.co/ij6HuAcx
February 21st
Lavasoft: Check out the beta version of Lavasoft’s soon to be released Ad-Aware 10: http://t.co/lepXU5Ve #adaware
February 15th
About Lavasoft

Lavasoft is the maker of Ad-Aware, the world's most popular anti-malware software with over 350 million downloads.

Subscribe to
our Newsletter
E-mail: