How to delete the WORM_KOOBFACE.AZ Facebook worm


Description:

WORM_KOOBFACE.AZ is a worm that targets social media sites. It does this by monitoring the cookies on your computer that contain login information to various social sites.  When login information is found it will login to your account and start sending messages to your friends and contacts on the site.  For example, if you use Facebook, it will login to your account and send all your friends messages about a video they should see. These messages will contain links to the infection that will further infect the person who visits the link.

The social sites that this infection monitors are:

  • facebook.com
  • hi5.com
  • friendster.com
  • myyearbook.com
  • myspace.com
  • bebo.com
  • tagged.com
  • netlog.com
  • fubar.com
  • livejournal.com

Once infected, the worm will create the file C:\Windows\freddy35.exe.  This file is the main program that sends infected messages to your friends. It will then create the follow registry key to start itself automatically:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”sysftray2″ = “%WinDir%\freddy35.exe”

Manual Removal Instructions for WORM_KOOBFACE.AZ

End these processes if they exist:
Learn how to end processes

freddy35.exe


Delete these files if they exist:

Lean how to remove files

C:\Windows\freddy35.exe

Remove these Registry keys if they exist:
Learn how to remove Windows Registry entries

Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly.  Please edit the Registry only if you know what you are doing.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”sysftray2″

del.icio.us:How to delete the WORM_KOOBFACE.AZ Facebook worm  digg:How to delete the WORM_KOOBFACE.AZ Facebook worm  spurl:How to delete the WORM_KOOBFACE.AZ Facebook worm  wists:How to delete the WORM_KOOBFACE.AZ Facebook worm  simpy:How to delete the WORM_KOOBFACE.AZ Facebook worm  newsvine:How to delete the WORM_KOOBFACE.AZ Facebook worm  blinklist:How to delete the WORM_KOOBFACE.AZ Facebook worm  furl:How to delete the WORM_KOOBFACE.AZ Facebook worm  reddit:How to delete the WORM_KOOBFACE.AZ Facebook worm  fark:How to delete the WORM_KOOBFACE.AZ Facebook worm  blogmarks:How to delete the WORM_KOOBFACE.AZ Facebook worm  Y!:How to delete the WORM_KOOBFACE.AZ Facebook worm  smarking:How to delete the WORM_KOOBFACE.AZ Facebook worm  magnolia:How to delete the WORM_KOOBFACE.AZ Facebook worm  segnalo:How to delete the WORM_KOOBFACE.AZ Facebook worm  gifttagging:How to delete the WORM_KOOBFACE.AZ Facebook worm

Leave a Reply