Banner
Latest Tweets
Globodyne Business Card Design » Promotion on business card design.Pay one design and get 2 d...
Banner
Globodyne Ltd Why Us
Banner
Banner
Banner
Banner
Banner
Banner

 

Banner
Banner

Koobface remains active on Facebook

 Tweet

A new variant of Koobface (a worm that spreads over Social Networking sites) was recently making the rounds on Facebook. Users reported receiving spam messages, such as:

When a user follows the link, they’re redirected to one of many different compromised hosts, which displays a fake error message that the version of Flash is out of date. Next the user is prompted to download/open flash_player.exe, a new Koobface variant.

If the user choose to install the executable, a fake error message is displayed.

Facebook is already aware of this threat and is purging the spammed links from their system. But with dozens of Koobface variants known to exist, the situation is likely to get worse before it gets better. It’s important to note that spammed links leading to Koobface are likely to come from infected friends, reminiscent of early mass-mailing worms. The safe-computing practice created more than 10 years ago still applies today, which is not to open any unexpected email attachments, even if they are from someone you know. Only in this context, it must be expanded to the following:

Do not follow any unexpected hyperlinks you receive over the Web, Email, or IM, even if they are received from someone you know. It’s best to ask for confirmation from the sender; that they intentionally sent such a link.
 On the other end of hyperlinks, it’s best to install software and updates from the source (such as adobe.com in this case) rather than trusting the content from a third-party website.

The upcoming DAT release contains detection for the new Koobface variant, while users of McAfee Artemis Technology are already protected in real-time against this threat.

As for the motivations behind this Koobface variant, analysis shows that during infection a proxy server is installed to %ProgramFiles% inyproxy inyproxy.exe and a service named Security Accounts Manager (SamSs) is created to load the server at startup.  This component listens on TCP port 9090 and proxies all HTTP traffic, in particular looking for traffic to Google, Yahoo, MSN, and Live.com for the purpose of hijacking search results. Search terms are directed to find-www.net. This enables ad hijacking and click fraud.

Sources : blogs.mcafee.com

Our Vision & Mission

Globodyne Ltd is global level, Our Vision is offer top quality web solutions like Web Design, Web Development and IT Solutions,Web Hosting everything under one-roof.

Few important things that keep us moving towards achieving excellence in whatever we choose to do. We focus our goals on client’s business strategies and their work processes, and then, map them according to our work model.We have nurtured a dream to offer next generation and new technology driven web solutions to our clients that makes an ideal blend with their business processes.

Mission to continually come up with winning ideas in web designing and web development for our valuable customers, without any changes in technology.

Banner