Selected viruses, spyware, and other threats: sorted alphabetically
Short description
Win32/Koobface.NBH is a worm that is spread via links in social networking sites. Installation
When executed, the worm copies itself into the following location: - %windir%\pp12.exe
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run]
"pp" = "%windir%\pp12.exe"
- [HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\
Navigating]
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\
PhishingFilter]
"EnabledV8" = 0 - [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\
PhishingFilter]
"ShownServiceDownBalloon" = 0
Other information
The worm checks for Internet connectivity by trying to connect to the following servers: - www.google.com
- anlaegkp.dk
- aricosenza.it
- captchastop.com
- capthcabreak.com
- mymegadomain03072009.com
- http://promservice.sky.ru/.sys/%removed%
- http://trinityonline.biz/.sys/%removed%
The "Windows Web Security" displays warnings about possible problems detected on the compromised computer that need to be fixed.
Some examples follow.
(1.) (2.) (3.)
The problems/threats are fake.
The worm creates the following files:
- %windir%\fdgg34353edfgdfdf
- dxxdv34567.bat



