Monday, September 7, 2009

Facebook, Koobface, the other side

"Kaspersky Lab, a leading developer of secure content management systems, has detected two variants of a new worm, Net-Worm.Win32.Koobface.a. and Net-Worm.Win32.Koobface.b, which attack MySpace and Facebook respectively. As part of their malicious payload, the worms transform victim machines into zombie computers to form botnets.

Even though the worms are currently only infecting MySpace and Facebook users, Kaspersky Lab analysts are warning users that the worms are designed to upload additional malicious modules with other functionality via the Internet. It is highly probable that victim machines will not only be used for spreading links via these social networking sites, but the botnets will also be used for other malicious purposes."

This is the same as an infamous attack of last year. If anything, some blogs say they are rumors, others say they are fact.

This blog from mashable.com claims is it is a two part way of having you go to a site which loads malware by luring you with this scare. Some might call it social scareware at this point, as far as eggBrain is concerned.

Associatedcontent.com's post states: "Facebook users who added the Fan Check application may find themselves especially vulnerable. The Fan Check application tells you which of your friends are your biggest fans. It compiles data by accessing your wall and your news feed (already a bit creepy from a privacy standpoint, but Facebook users are aware of this when they add the application)."

Again, if you are a facebook user and you have this app, please try to remove it promptly. In addition, there are signatures written for the Koobface virus by various antivirus companies, such as Kapersky and Norton/Symantec. (This link contains information about the virus and it's latest certification as late as Sept 4, 2009.

All in all, in eggBrain's honest AND professional opinion, UPDATE your antivirus, DISCONNECT your machine from the internet, and SCAN your computer with a Full detailed scan. The software that we recommend, AVG Antivirus, does have a signature written for it so you SHOULD be protected.

Reconnect after you are SURE any and all malware has been removed.

If you STILL have the virus and any other malware that may have come along because of it, you may need to have an expert, such as eggBrain, to take a look at your machine.

Feel free to post your progress here or e-mail eggBrain.

Regards,
eggBrain

No comments: