Flag This Hub

Get Rid Of Koobface - Get Removal Tool

By


Who are you Mr. Koobface?

It is known by different names:

Net-Worm.Win32.Koobface.b, W32/Koobface.worm, W32/Koobface.worm.gen.e, Boface.A, W32/Koobface.AA.worm, W32/Koobface.A.gen!Eldorado, Win32.HLLW.Facebook.24, Worm.Koobface-15, W32/Koobfa-Gen, W32.Koobface.A, Worm/Generic.VYK, WORM_KOOBFACE.AZ

In common it is social network worm spreading from user to user by sending special links forwarding to third party websites.

A typical Koobface attack – like the one that surfaced on Twitter some time ago – comes via a link that purports to be an interesting video (i.e. – someone tweets “my home video” with a link to what looks like a YouTube page. Those videos then tell that you have old version of player - nothing weird at first sight - many legitimate videos often do the same. Upon so called “upgrading” the user download the virus that infiltrates system.

In this Hub we will talk about Koobface removal.

Already Infected With Koobface?

1) Use automatic Koobface removal tool that will scan your processes, files and registry entries and remove infected ones. In case you will have any problems with it - 24/7 support is ready to help you. Here is how it is look like:

 

Manual Solution

Remove following files - for example using Unlocker tool:

freddy79

fbtre6.exe

mstre6.exe

ld08.exe

Ld12.exe 

• [%WINDOWS%]\ro122739.dat
• [%WINDOWS%]\sber18.exe
• [%WINDOWS%]\sonce122712.dat
• [%WINDOWS%]\sonce122739.dat
• [%WINDOWS%]\sonce123198.dat
• [%WINDOWS%]\sto453165.dat
• [%WINDOWS%]\sto453190.dat
• [%WINDOWS%]\sto453192.dat
• [%WINDOWS%]\st_1241203961.exe
• [%WINDOWS%]\st_1241222389.exe
• [%WINDOWS%]\st_1243005929.exe
• [%WINDOWS%]\t55ft2667f44.dat
• [%WINDOWS%]\t55ft2668f44.dat
• [%WINDOWS%]\t55ft2695f44.dat
• [%WINDOWS%]\tag14.exe
• [%WINDOWS%]\tgm2.dat
• [%WINDOWS%]\tw23567.dat
• [%WINDOWS%]\twitty07.exe

Remove following registry entries:

• Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\"systray" = "c:\windows\mstre6.exe"
• Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\"systray" = "C:\Windows\fbtre6.exe"
• Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: sysberay2
• Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: sysfbtray
• Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: sysberay2
• Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: systgray2
• Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  Value: pp
 

Comments

No comments yet.

Submit a Comment
Members and Guests

Sign in or sign up and post using a hubpages account.



    Like this Hub?
    Please wait working