Facebook worm still spreading

By Tim Conneally | Published August 25, 2008, 1:17 PM

Early in August, security firms noticed a worm spreading on Facebook through wall posts, claiming to contain a video requiring a new codec to be installed. Variants of this worm are now being spotted on a weekly basis.

The virus appears to be a slightly modified version of what Kaspersky Labs called Koobface; a worm elaborate in its design, but crude in execution.

Utilizing the same poorly worded social engineering tricks, the worm sends messages in Facebook with subject lines like "Hi My Friend," or "Hej!" and contains a verbose link to a video that claims to feature the recipient in some way. Instead of loading a video, it says the user's version of Flash is out of date and needs a new codec. Attempting to click on any part of the video player, including the sender's profile information, the fake comments, or settings, results in a forced download.

Koobface virus package contents


Up to this point where the user downloads the file entitled "codecsetup.exe", the worm's methods are exactly the same. Once the "codec" file is opened, it creates a file called "fbtre9.exe", different from the Koobface.A profile, which created a file called "mstre6.exe." This appears to be the sole difference between the two, and the twelfth time the virus has mutated in such a way (there are currently 27 different Koobface infections). When the file is run for the first time, it generates an error message and begins looking for Facebook user ID cookies. If found, the results are intended to be reproduced every time the user turns on his computer.

During the inital spread of "Koobface," Facebook's head of security Max Kelly wrote in the official blog that "Less than .002 percent of people on Facebook have been affected, all of whom we notified and suggested steps to remove the malware."

At least for BetaNews, which purposefully installed the koobface virus on a virtual machine, this statement is untrue; we were neither notified nor were we informed on corrective measures. However, the message which carried the virus disappeared promptly after obtaining the necessary files. Some have attributed this to either Facebook's diligent users or staff, but this is yet unconfirmed.

Koobface worm installed

Comments

View comments by with a score of at least

foxfire stole my planned one word post! ****.

Score: 0

|

Damn... same here. LOL

Score: 0

|

Good.

Score: 0

|

AND yet another reason to get a Mac, no worries of viruses taking over your computer. Wow, as I said that, I'm feeling very smug right now. :)

Score: 0

|

Not as smug as me. You couldn't fit in the same room with my ego. I bet you get in your s***box and drive to a soon-to-be-eliminated job every day like everybody else.

You are the type who would drive a seven year old Honda Civic but have an iPhone to appear successful.

_________________________________

Vista also won't let viruses install without warning you twice (unlike XP), and of course there is always Windows Restore for the morons.

Score: 0

|

*puts up two thumbs, squints eyes and says:*

GOOD FER YEWWWWWW!!!

AND yet another reason to dislike smug Apple-fanboy comments.

The real lesson here is that people need education on how to protect their computers by not falling for such stupidity.

I have no viruses.

I run NO antivirus software 24/7 (on occasion I do scan my systems).

I have a NAT router without any special software security suite on the client side.

I patch my OS regularly.

I don't open uninvited attachments without knowing who sent them and if they even sent the file in the first place, especially anything executable.

I don't surf pr0n spam mail links, random links sent to me in SPIM or SPAM, I don't use facebook or any "*book" or "*space" site.

I don't install every single program that pops up in my browser when I do go to a website outside the norm.

I use the proper CLOSE button on popups instead of cheesy deceptive graphics inside a popup HTML frame.

I don't download and use "adware".

I pay attention to what I have running at all times when I'm working on my PC.

I don't let anything autorun on start that doesn't absolutely need to be, unless it will not function without it, and even then it had better be essential to the operation of the program (rare gems like Daemon Tools and ANYDVD are examples)

Here's my version of a Mac vs. PC commercial:

I am a PC. And I'm educated about how a PC works. I know not to click on everything that pops up, and guess what, I don't have a problem with my Windows experience!

I am a Mac, and I don't want to know, nor care to know, I just want it to work. I don't have the time or brainpower to care.

Score: 0

|

"At least for BetaNews, which purposefully installed the koobface virus on a virtual machine,"

Hope you keep the host well protected with regards to this type of testing. A VM is no guarantee of a secure sandbox.

Score: 0

|

You think they'd do it on a box connected in anyway to their web host? I think they're smarter than that.

Score: 0

|

Microsoft denies latest 'Black Screen of Death' claims

After an anti-malware producer announced a fix to what it says is a swarm of recent KSoD problems, evidence of the swarm itself has yet to turn up.

Latest Firefox 3.6 beta fixes 133 bugs, promises faster page load times

A once-sluggish beta testing process has kicked into overdrive, with astonishing success at finding serious bugs. Will Mozilla be able to fix all the others in time?

Confirmed: Office 2010 to ship in June

Two weeks after Microsoft had been expected to draw a clearer roadmap for its principal applications suite, it's finally ready to commit to the end of H1.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

New EU antitrust commissioner will oversee Microsoft, Oracle+Sun, Intel issues

As one of Europe's most prominent politicians shifts positions in January, her replacement remains a question mark over technology's biggest issues.

Without its own 'iTablet' yet, is Apple missing the boat?

Steve Jobs is on record as dissing "single-purpose" devices like e-readers. But given their recent popularity, was that a mistake?

Not-so-mobile battery life: Time to force the issue

Carmi Levy | Wide Angle Zoom: If power efficiency is important when you buy a car or even a motorcycle, why shouldn't it matter for a smartphone?

Apple invokes DMCA, claims Psystar is 'trafficking in circumvention devices'

In trying to close the book on possibly the last attempt at a Mac clone, Apple cites from its own landmark case...but may actually be misinterpreting it.

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.