March MSRT Kills Koobface

March 11, 2009 – 3:01 PM

Win32/Koobface is a worm that may spread when a user logs into their profile account on the Internet social network sites MySpace, Facebook and others.  The following system changes may indicate the presence of this malware:

Addition of the following files:

  • %windir%\bolivar19.exe
  • %windir%\bolivar31.exe
  • %windir%\bolivar30.exe
  • %windir%\ld01.exe
  • %windir%\che08.exe
  • %windir%\freddy35.exe

And/or the getting the following message box:

koobface1

March’s edition of the Malicious Software Removal Tool now looks for this infection and attempts to remove it.

koobface2

koobface3

(How to run the GUI for an on-demand scan)

You must be logged in to post a comment.