Title: Koobface
Type: Worms
Also known as: W32/Koobface,W32.Koobface,W32/Koobface.AZ,Boface

Remove Koobface
Removal instructions

 
Severity scale:Koobface severity is 72  (72 / 100)
 
Koobface worm is distributed on social networks, usually on MySpace and Facebook. It embeds itself on victim’s profile and displays links to malicious websites. The websites promote video codec which is actually the Koobface worm. Those sources might also install the worm without notifying visitors.

Koobface is also known as W32/Koobface, W32/Koobface.AZ, W32.Koobface and Boface. Once it gets on a machine, it checks if there are cookies of social networks. If it finds the cookies, it infects victim’s profile. If Koobface worm can’t find evidence of social networking websites, it simply erases itself.

Koobface also loads pop-ups that look like MS Windows error messages. The pop-up contains the following text: "Error installing Codec. Please contact support."

Related files: fmark2.dat

Koobface properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Koobface removal:

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use.
By downloading any of provided Anti-spyware software to remove Koobface you agree with our Privacy Policy and Agreement of Use.
SpyHunter is recommended remover to uninstall Koobface. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

If you failed to remove Koobface using SpyHunter, submit question to our support team and provide as much details as possible.
dot
STOPzilla
download
manual required
We are testing STOPzilla's efficiency at removing Koobface (2012-02-09 15:36:40)
dot
Malwarebytes Anti Malware
download
manual required
We are testing Malwarebytes Anti Malware's efficiency at removing Koobface (2012-02-09 15:36:40)
dot
XoftSpySE Anti Spyware
download
manual required
We are testing XoftSpySE Anti Spyware's efficiency at removing Koobface (2012-02-09 15:36:40)
dot
Defender Pro Ultimate
download
manual required
We are testing Defender Pro Ultimate's efficiency at removing Koobface (2012-02-09 15:36:40)

what to do if you failed to remove the infection?
Virus Removal
Phone Support
Help Line to remove Koobface
Koobface snapshot:

Koobface manual removal:

Kill processes:
freddy79
fbtre6.exe
mstre6.exe
ld08.exe
Ld12.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\"systray" = "c:\windows\mstre6.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\"systray" = "C:\Windows\fbtre6.exe"
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating
Delete files:
freddy79
fbtre6.exe
fmark2.dat
ld08.exe
Ld12.exe

Geolocation of Koobface:

This map reveals the prevalence of Koobface. Countries and regions that have been affected the most are: United States, Canada, United Kingdom, Italy and Germany.

QR code for Koobface removal instructions:

Koobface qrcode
QR is short for Quick Response. They can be read quickly by the mobile phones. QR codes can store more data than standard barcodes, including url links, geo coordinates, and text.

The reason we add QR code to the website is that parasites like Koobface are really hard to remove on infected computer. you can quicly scan the QR code with your mobile device and have manual removal instructions to uninstall Koobface right in your pocket.

Simply use the QR scanner and read removal instructions from mobile device.
Information added: 2008-11-24 03:25:53
Information updated: 2012-02-09 12:59:25

Additional resources:

Attention: If you know know a reputable website reated to security threats, please add a link here: add url

2
0
<Guest>
I also had to remove a file "freddy51" from the C drive as well.
0
0
rodi
Thanks, although this file has other anmes as well. Previously it was freddy46, freddy49. Now, it's freddy51. Later it could be freddy52, freddy53 and etc.
1
0
<Guest>
Removed Koobface using AVG, but still can Not connect to the Net using Internet Explorer even after changing the LAN Settings to automaic detect settings from Use a Proxy server. Please help
0
0
<Guest>
yah it's freddy64 now
0
0
<Guest>
it's freddy79. i was able to manually stop the processes, found the registry entries and deleted them but "freddy79" remains in C:Windows. If anyone has suggestions on getting it deleted, please post. It will no longer let you delete the file.
0
0
rodi
Thank you, we added freddy79 to the list too. Just download an automatic removal tool and run a system scan. I'm afraid that manual removal won't work for you.
0
0
<Guest>
i hate this stupid virus
0
0
<Guest>
I just cleaned this from a friend's laptop last night. It was up to freddy81.
0
0
<Guest>
im finding bills now, is that bad?
0
0
<Guest>
I don't find the fbtre6.exe, I find fbtre19.exe. Should I remove it?
0
0
<Guest>
Found it on mine as bill104.exe? Or is that another one?
0
0
<Guest>
Found as bill 106.exe
0
0
<Guest>
Koobface is nasty. It blocked me from many Internet sites by preventing DNS translation. I couldn't update my antivirus program (Avast). Ultimately I was able to rid myself of this beastie by running Microsoft's Malicious Software Removal tool (MRT.exe).
0
0
<Guest>
dies this affect mac users also? if so, how do i manually remove it on a mac? thanks
0
0
<Guest>
MUCH THANKS
0
0
hey
dident work :(
0
2
callum-MS-FB
ok just get avg or norton or a good anti virus and it will detect it and remove it
0
0
<Guest>
Avira (free) gets rid of Koobface
0
0
<Guest>
uhh, i found a bill something, but deleted it as soon as i found it (i run in safemode so i know what processz arnt suppose to be there) but i cant find it anywhere on my laptop, any help on where bill105 would be in the registry?
0
1
Akio
hey guys after i infected with koobface my Google Chrome cant login facebook and any google related sites. Is it also koobfaces effect??
0
1
Saleem
Avira gets rid of koobface.
0
1
nazi
ya
1
0
boka choda
koob face amar computer chude deache

Post Comment:

Attention: Use this form only if you have additional information about Koobface parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Like us on Facebook
Latest spyware news:
Subscribe to spyware news
Please enter your e-mail address:
If you do not want to receive our spyware
newsletter please unsubscribe here
48602 Subscribers
Ask us
I failed to remove Koobface using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight against computer parasites on the Internet alone. If you have a website, we would be more than happy if you would like to cooperate and help us spread the information about latest threats. Remember, knowledge is the most powerful weapon. Help your visitors protect their computers!
add text box
rss feed
help other