Koobface Removal Guide

May 24, 2019

What is Koobface

Koobface is a worm that can inject ads into all users’ browsers and redirect to malicious sites, as well as steal personal information

Koobface is a relatively old cyber infection that targets Windows, Mac OS X, and Linux platforms. Operating as a work, this malware is capable of intercepting traffic, inducing ads, stealing sensitive information, downloading secondary payloads, and many other malicious activities.

Koobface is also a worm that is capable of spreading via social media and email networks, in particular, Facebook, Twitter, Skype, Gmail Yahoo Mail, and others. As soon as the infection is populated, it checks if there are cookies of social networks. If it locates them, it infects the victim’s profile.

If Koobface virus can’t find evidence of social networking websites, it merely erases itself and then loads pop-ups that look like MS Windows error messages. The pop-ups contain the following text: “Error installing Codec. Please contact support.” The threat is flagged by different vendors as W32/Koobface, W32/Koobface.AZ, W32.Koobface and Boface.

How does Koobface works

Additionally, the name of this computer worm is often used by technical support scams and other phishing attempts, such as Windows Detected Koobface Infection, Your System is infected with 3 viruses, and others. If you noticed notifications that note the infection of this virus on Google Chrome or another browser, make sure you scan your device with security software as all these claims are most likely fake. Nevertheless, you will have to remove Koobface as soon as possible if the infection is real – check the bottom section to find out how.

If computer user actively uses social media networks, Koobface detects particular cookies and collects victim’S login information of all social media websites that he or she visits. Then it sends messages to people on the victim’S friend list, asking to view a video.

This message includes a malicious hyperlink. If people click on this hyperlink, they are going to be redirected to a harmful website, which states that an update of Flash is required in order to review the content. The download links include flash_player.exe file. If the person allows installing the update, he/she gives access for an installer of Koobface. It means that this .Exe file is going to silently download and install Koobface infection files.

Koobface hacking worm allows the cyber-criminals to track and record sensitive data about the victim, for example, it can see what passwords do you enter on particular websites, what are your logins and it can even find out credit card info and banking information! Be aware because it can lead to a financial loss. In addition to that, this malicious worm can display vague ads convincing you to install fake anti-virus programs. Do not install any software promoted by Koobface virus hoax – most likely you will infect your computer even more.

For Koobface removal, you should employ reputable security software and terminate all the malicious files from your computer. Additionally, to recover from virus damage, make sure you scan your computer with – it can fix all the infected system files and make the machine operate normally again.

Beware of tech support scammers who claim that your computer has been infected with Koobface malware. Technical support scammers make victims install a malicious program that displays pop-up messages via the user’S default web browser, stating that the system has been compromised.

Such malicious programs can display a lock screen and prevent the user from accessing the PC or pose as a phony Windows Update. All of these deceptive programs are designed to showcase the technical support number that the user supposedly needs to call in order to get help from “certified technicians.†If your computer is telling you that the system is infected with Koobface, and urges you to contact the tech support team, better scan the system for malware. We also strongly recommend reading this article – Tech Support Scam virus.

How to delete Koobface

Koobface is usually spread via social engineering. It means that it is spread via social media messages. If your friend has sent you a link that looks suspicious (looks unfamiliar and contains a lot of random symbols), you should double-ask your friend if he/she really sent that. Such spam usually includes such and similar lines:

“I saw your silly face in that movie, check it!â€; “Why do you look so stupid? XD See yourselfâ€; “You look just awesome in this new movieâ€; “My friend caught you on hidden cam.â€

If you can remember clicking any of these messages, make sure that you double check your computer for Koobface malware. Also, you should scan your computer with the powerful anti-spyware if you have been tricked into downloading a fake version of Flash Player, which was disguised as “flash_player.exeâ€.

Crooks are often using Koorface’s name in order scam users and make them install bogus software or pay for fake tech support services

Otherwise, Koobface can try to overtake your HTTP traffic, steal your personal information and infect your PC system with additional malware. If you think that you are infected, please, scan your computer with . You can find more about removal below.

While the majority of cyber criminals tend to stay underground and not brag about the money they earn in illegal ways, criminals behind virus behave in an entirely different way. According to research, cyber criminals who have created Koobface project have earned thousands of US dollars daily – up to $10,000 a day.

These criminals were so proud of themselves and loved money so much so that they all have set their phones to deliver a message telling how much money has been earned in the previous 24 hours every morning. Bad actors have also been spotted swaggering on social media and posting pictures next to money piles and Porsches.

Do not let scammers take advantage of you and protect your computer in advance to avoid malware attack. Please, do not click on suspicious-looking links while browsing social media websites and do not open links sent by your friends that point to a video that has nothing to do with you.

Do not browse unreliable websites. If you have opened a website which asks to update your Flash Player, and you know that it was possible to open other videos before, you should know that the site is suspicious. Close it immediately. If you have at least the smallest suspicion that your friend did not send the suspicious message with a hyperlink, ask him or her twice. Keep an anti-malware program on your computer to prevent infectious computer threats; We recommend .

You can check if you have this infection by opening the Task Manager and looking for such processes: freddy79.exe, fbtre6.exe, mstre6.exe, ld08.exe, Ld12.exe. You must remove this malicious threat from your computer and stop the spread of it. You can perform Koobface removal manually, and we have provided the instructions on how to do it below this article.

Nonetheless, we strongly advise you to remove Koobface worm automatically by employing a reputable security tool, such as Combo Cleaner or Anti-Malware . After termination, perform a scan with to fix virus damage and change your social media/banking passwords to ensure that the cyber-criminals will not use them again.

Stage 1: Delete Browser Extension

First of all, we would recommend that you check your browser extensions and remove any that are linked to Koobface. A lot of adware and other unwanted programs use browser extensions in order to hijacker internet applications.

Remove Koobface Extension from Google Chrome

  1. Launch Google Chrome.
  2. In the address bar, type: chrome://extensions/ and press Enter.
  3. Look for Koobface or anything related to it, and once you find it, press ‘Remove’.

Uninstall Koobface Extension from Firefox

  1. Launch Mozilla Firefox.
  2. In the address bar, type: about:addons and press Enter.
  3. From the menu on the left, choose Extensions.
  4. Look for Koobface or anything related to it, and once you find it, press ‘Remove’.

Delete Koobface Extension from Safari

  1. Launch Safari.
  2. Press on the Safari Settings icon, which you can find in the upper-right corner.
  3. Select Preferences from the list.
  4. Choose the Extensions tab.
  5. Look for Koobface or anything related to it, and once you find it, press ‘Uninstall’.
  6. Additionally, open Safari Settings again and choose Downloads.
  7. If Koobface.safariextz appears on the list, select it and press ‘Clear’.

Remove Koobface Add-ons from Internet Explorer

  1. Launch Internet Explorer.
  2. From the menu at the top, select Tools and then press Manage add-ons.
  3. Look for Koobface or anything related to it, and once you find it, press ‘Remove’.
  4. Reopen Internet Explorer.In the unlikely scenario that Koobface is still on your browser, follow the additional instructions below.
  5. Press Windows Key + R, type appwiz.cpl and press Enter
  6. The Program and Features window will open where you should be able to find the Koobface program.
  7. Select Koobface or any other recently installed unwanted entry and press ‘Uninstall/Change’.

Alternative method to clear the browser from Koobface

There may be cases when adware or PUPs cannot be removed by simply deleting extensions or codes. In those situations, it is necessary to reset the browser to default configuration. In you notice that even after getting rid of weird extensions the infection is still present, follow the below instructions.

Use Chrome Clean Up Tool to Delete Koobface

  1. Launch Google Chrome.
  2. In the address box, type: chrome://settings/ and press Enter.
  3. Expand Advanced settings, which you can find by scrolling down.
  4. Scroll down until you see Reset and Cleanup.
  5. Press on Clean up computer. Then press Find.

This Google Chrome feature is supposed to clear the computer of any harmful software. If it does not detect Koobface, go back to the Clean up computer and reset settings.

Reset Mozilla Firefox to Default

If you still find Koobface in your Mozilla Firefox browser, you should be able to get rid of it by restoring your Firefox settings to default. While extensions and plug-ins will be deleted, this will not touch your browser history, bookmarks, saved passwords or Internet cookies.

  1. Launch Mozilla Firefox
  2. Into the address box, type: about:support and press Enter.
  3. You will be redirected to a Troubleshooting Information page.
  4. From the menu on the right side, select Refresh Firefox.
  5. Confirm your choice by clicking Refresh Firefox in the new window.
  6. Your browser will close automatically in order to successfully restore the settings.
  7. Press Finish.

Reset Safari Browser to Normal Settings

  1. Launch Safari.
  2. Press on the Safari Settings icon, which you can find in the upper-right corner.
  3. Press Reset Safari.
  4. A new window will appear. Select the boxes of what you want to reset or use the screenshot below to guide you. Once you have selected everything, press ‘Reset’.
  5. Restart Safari.

Restore Internet Explorer to Default Settings

  1. Launch Internet Explorer.
  2. From the top menu, press on Tools and then Internet Options.
  3. In the new window that opens, choose the Advanced tab.
  4. At the bottom of the window, below Reset Internet settings, there will be a ‘Reset’ button. Press that.

While extensions and plug-ins will be deleted, this will not touch your browser history, bookmarks, saved passwords or Internet cookies.

