Koobface is a worm-type infection that can be set to perform various actions like information stealing

Koobface is a relatively old cyber infection that targets Windows, Mac OS X, and Linux platforms.[1] Operating as a worm, this malware is capable of intercepting traffic,[2] inducing ads, stealing sensitive information, downloading secondary payloads, and many other malicious activities.
The virus is also a worm that is capable of spreading via social media and email networks, in particular, Facebook, Twitter, Skype, Gmail Yahoo Mail, and others. As soon as the infection is populated, it checks if there are cookies of social networks[3]. If it locates them, it infects the victim’s profile[4].
If the virus can’t find evidence of social networking websites, it merely erases itself and then loads pop-ups that look like MS Windows error messages. The pop-ups contain the following details: “Error installing Codec. Please contact support.” The threat is flagged by different vendors as Gen:Variant.Koobface.4, Trojan/Win32.Agent, Boface, and many more.

Additionally, the name of this computer worm is often used by technical support scams and other phishing attempts, such as Windows Detected Koobface Infection, Your System is infected with 3 viruses, and others. If you noticed notifications that note the infection of this virus on Google Chrome or another browser, make sure you scan your device with security software as all these claims are most likely fake. Nevertheless, you will have to remove the threat as soon as possible if the infection is real – check the bottom section to find out how.
| Name | Koobface |
| Type | Worm, Trojan |
| Platforms | Windows, Mac OS X, and Linux |
| Infiltration | Networking websites and services, such as Skype, Facebook, Twitter, etc. Pay-per-click ads to generate revenue while directing traffic to spoofed websites |
| Capabilities | Installing additional payloads, stealing confidential data, injecting advertisements into browsers, redirects, blocking access to certain sites, stealing license keys, modifying system files, intercepting internet traffic, etc. |
| Also known as | Associated malicious files include Fbtre6.exe, Mstre6.exe, Freddy35.exe, Websrvx.exe, Captcha6.exe, Bolivar28.exe, Ld05.exe, Ld11.exe, and Ld12.exe. Aliases: Dursg, VBInject, Usuge, VBKrypt, Koobfa, Autorun |
| Termination | Use powerful anti-malware software |
| Recovery | To restore system files to normal, scan your device with FortectIntego |
If a computer user actively uses social media networks, the threat detects particular cookies and collects the victim's login information of all social media websites that he or she visits. Then it sends messages to people on the victim's friend list, asking to view a video.
This message includes a malicious hyperlink. If people click on this hyperlink, they are going to be redirected to a harmful website, which states that an update of Flash is required in order to review the content. The download links include flash_player.exe file. If the person allows installing the update, he/she gives access to an installer of this worm. It means that this .exe file is going to silently download and install infection files.
Koobface hacking worm[5] allows the cyber-criminals to track and record sensitive data about the victim, for example, it can see what passwords do you enter on particular websites, what are your logins and it can even find out credit card info and banking information!
Be aware because it can lead to a financial loss. In addition to that, this malicious worm can display vague ads convincing you to install fake anti-virus programs. Do not install any software promoted by a virus hoax – most likely you will infect your computer even more.

For removal, you should employ reputable security software and terminate all the malicious files from your computer. Additionally, to recover from virus damage, make sure you scan your computer with FortectIntego – it can fix all the infected system files and make the machine operate normally again.
Beware of tech support scammers who claim that your computer has been infected with KoobFace malware. Technical support scammers make victims install a malicious program that displays pop-up messages via the user's default web browser, stating that the system has been compromised.
Such malicious programs can display a lock screen and prevent the user from accessing the PC or pose as a phony Windows Update. All of these deceptive programs are designed to showcase the technical support number that the user supposedly needs to call in order to get help from “certified technicians.”
If your computer is telling you that the system is infected with Koobface, and urges you to contact the tech support team, better scan the system for malware. We also strongly recommend reading this article – Tech Support Scam virus.
A worm usually spread via social media messages
Koobface is usually spread via social engineering. It means that it is spread via social media messages. If your friend has sent you a link that looks suspicious (looks unfamiliar and contains a lot of random symbols), you should double-ask your friend if he/she really sent that. Such spam usually includes such and similar lines:
- “I saw your silly face in that movie, check it!”;
- “Why do you look so stupid? xD See yourself”;
- “You look just awesome in this new movie”;
- “My friend caught you on hidden cam.”
If you can remember clicking any of these messages, make sure that you double-check your computer for malware. Also, you should scan your computer with the powerful anti-spyware if you have been tricked into downloading a fake version of Flash Player, which was disguised as “flash_player.exe”.

Otherwise, Koobface can try to overtake your HTTP traffic, steal your personal information and infect your PC system with additional malware. If you think that you are infected, please, scan your computer with FortectIntego. You can find more about removal below.
The gang behind malware shows off their earnings online
While the majority of cyber criminals tend to stay underground and not brag about the money[6] they earn in illegal ways, criminals behind viruses behave in an entirely different way. According to research, cyber criminals who have created Koobface project have earned thousands of US dollars daily – up to $10,000 a day.
These criminals were so proud of themselves and loved money so much so that they all have set their phones to deliver a message telling how much money has been earned in the previous 24 hours every morning. Bad actors have also been spotted swaggering on social media and posting pictures next to money piles and Porsches.
Do not let scammers take advantage of you and protect your computer in advance to avoid malware attack. Please, do not click on suspicious-looking links while browsing social media websites, and do not open links sent by your friends that point to a video that has nothing to do with you.
Koobface prevention tips:
- Do not browse unreliable websites. If you have opened a website that asks to update your Flash Player, and you know that it was possible to open other videos before, you should know that the site is suspicious. Close it immediately.
- If you have at least the smallest suspicion that your friend did not send the suspicious message with a hyperlink, ask him or her twice.
- Keep an anti-malware program on your computer to prevent infectious computer threats; we recommend FortectIntego.
Manual removal of a computer worm is not recommended
You can check if you have this infection by opening the Task Manager and looking for such processes: freddy79.exe, fbtre6.exe, mstre6.exe, ld08.exe, Ld12.exe. You must remove this malicious threat from your computer and stop the spread of it. You can perform removal manually, and we have provided the instructions on how to do it below this article. This worm has a lot of background processes, manual removal of the Koobface computer worm is not recommended as it may lead to a system crash.
Nonetheless, we strongly advise you to remove Koobface worm automatically by employing a reputable security tool, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. After termination, perform a scan with FortectIntego to fix virus damage and change your social media/banking passwords to ensure that the cyber-criminals will not use them again.
Did this guide help?
27 comments
Guest
I also had to remove a file "freddy51" from the C drive as well.
rodi
Thanks, although this file has other anmes as well. Previously it was freddy46, freddy49. Now, it's freddy51. Later it could be freddy52, freddy53 and etc.
Guest
Removed Koobface using AVG, but still can Not connect to the Net using Internet Explorer even after changing the LAN Settings to automaic detect settings from Use a Proxy server. Please help
Guest
yah it's freddy64 now
Guest
it's freddy79. i was able to manually stop the processes, found the registry entries and deleted them but "freddy79" remains in C:Windows. If anyone has suggestions on getting it deleted, please post. It will no longer let you delete the file.
rodi
Thank you, we added freddy79 to the list too. Just download an automatic removal tool and run a system scan. I'm afraid that manual removal won't work for you.
Guest
i hate this stupid virus
Guest
I just cleaned this from a friend's laptop last night. It was up to freddy81.
Guest
im finding bills now, is that bad?
Guest
I don't find the fbtre6.exe, I find fbtre19.exe. Should I remove it?
Guest
Found it on mine as bill104.exe? Or is that another one?
Guest
Found as bill 106.exe
Guest
Koobface is nasty. It blocked me from many Internet sites by preventing DNS translation. I couldn't update my antivirus program (Avast). Ultimately I was able to rid myself of this beastie by running Microsoft's Malicious Software Removal tool (MRT.exe).
Guest
dies this affect mac users also? if so, how do i manually remove it on a mac? thanks
callum-MS-FB
ok just get avg or norton or a good anti virus and it will detect it and remove it
Guest
Avira (free) gets rid of Koobface
Guest
uhh, i found a bill something, but deleted it as soon as i found it (i run in safemode so i know what processz arnt suppose to be there) but i cant find it anywhere on my laptop, any help on where bill105 would be in the registry?
Akio
hey guys after i infected with koobface my Google Chrome cant login facebook and any google related sites. Is it also koobfaces effect??
Saleem
Avira gets rid of koobface.
boka choda
koob face amar computer chude deache
alicia
SpyHunter worked very well, thank you!!!!! This malicious threat is gone for good, god damn it! need to change my passwords now
counterstrike
Yeah it can! Try to retrieve your account by answering the security questions or send the password reset link to your e-mail. BUT FIRSTLY REMOVE KOOBFACE!!! otherwise this worm will see your new passowrds as well
RoyBiggie
manual removal instructions aint gonna work that well, it is better to remove it automatically ;] you should get anti-malware app, dude
George Kinal
Great. Article says koobface can infect Macs BUT it says bloody well NOTHING at all about how to do so.
Freddie
What about other computers on the same network
Freddie
What about other computers on the same network
Allison
Free scan yes, remove the virus, need to pay, I cant afford it. So unless you can afford to buy something, i wouldnt get this.