Worm.Koobface.AW
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Threat Level: | 50 % (Medium) |
| Infected Computers: | 57 |
| First Seen: | November 1, 2011 |
| Last Seen: | October 8, 2019 |
| OS(es) Affected: | Windows |
The detection of Worm.Koobface.AW on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the worm, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.
Table of Contents
What Is Worm.Koobface.AW?
Worm.Koobface.AW is a type of malware that can spread from system to system without the need for user interaction. The name itself suggests it is a worm, a category of malware known for its ability to replicate and spread independently. Understanding the nature of this threat is crucial in taking appropriate measures to protect your system and data.
How Worm.Koobface.AW Operates
Malware like Worm.Koobface.AW typically operates by exploiting vulnerabilities in software or manipulating users into executing malicious files. Once inside a system, it can perform a variety of harmful actions, including data theft, unauthorized changes to system settings, and facilitating further malware infections. The specifics of how Worm.Koobface.AW operates can depend on its design and the intentions of its creators, but the general principle involves compromising system security and using the infected machine for malicious purposes.
Symptoms of Infection
Symptoms of a Worm.Koobface.AW infection can vary but may include unexpected changes to your system, such as new programs or toolbars appearing, changes in your web browser's homepage or search engine, and overall system slowdown. You might also notice increased network activity, even when you're not using your internet connection. These signs indicate that your system is under the control of malicious software, and taking immediate action is necessary to prevent further damage.
- Unexplained system crashes or freezes
- New, unfamiliar programs or icons on your desktop
- Pop-ups and unwanted advertisements appearing on your screen
- Difficulty in accessing certain system files or folders
How to Remove Worm.Koobface.AW
- Boot your system into Safe Mode with Networking. This will limit the worm's ability to operate and make it easier to remove.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to increase the chances of detecting and removing the worm.
- Uninstall any suspicious programs that you do not recognize or that were installed without your consent. Be cautious and only remove programs you are certain are malicious or unnecessary.
- Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the worm.
- After completing the above steps, reboot your system and perform another full scan to ensure the worm has been completely removed. Repeat the scanning process until no more threats are detected.
Conclusion
Removing Worm.Koobface.AW from your system requires careful and methodical steps to ensure complete eradication. It's also essential to adopt preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong, unique passwords, and being cautious with email attachments and links from unknown sources. By understanding the threat posed by Worm.Koobface.AW and taking proactive steps, you can protect your system and personal data from harm.
Aliases
15 security vendors flagged this file as malicious.
| Antivirus Vendor | Detection |
|---|---|
| BitDefender | Trojan.Generic.7085756 |
| BitDefender | Trojan.Generic.7082907 |
| Ikarus | Trojan.Win32.Patched |
| Antiy-AVL | Trojan/Win32.Patched.gen |
| Sophos | W32/Footle-A |
| BitDefender | Trojan.Generic.7083678 |
| Kaspersky | Trojan.Win32.Patched.nn |
| Avast | Win32:Patched-ADQ [Trj] |
| Fortinet | W32/FakeAV.OZ!tr |
| Sophos | Mal/FakeAV-OZ |
| Kaspersky | Trojan-FakeAV.Win32.SystemRestore.d |
| NOD32 | a variant of Win32/Kryptik.UVJ |
| McAfee | Generic FakeAlert.fc |
| AhnLab-V3 | Trojan/Win32.Agent |
| Kaspersky | Trojan.Win32.Agent.pymt |
File System Details
| # | File Name | MD5 |
Detections
Detections: The number of confirmed and suspected cases of a particular threat detected on
infected computers as reported by SpyHunter.
|
|---|---|---|---|
| 1. | vmusbw32.dll | fc9ef34a204535d1c40dbebeafaefb1a | 10 |
| 2. | aadrive32.exe | ab3cb543390d53531a866fb9a6c74866 | 9 |
| 3. | questscan143.exe | 89101d4bc36616171c67e56c5906c272 | 8 |
| 4. | 6DSS92c31Apgjk.exe | bf47034c58f0c268037af2588d5be73f | 8 |
| 5. | Photoshop.exe | b24f090f200f720a4a2c2abc3a08603e | 4 |
| 6. | svchost.exe | 4db29f34dc18cfedc6da2431928ab2ee | 4 |
| 7. | winlogon.exe | f1b853e906761fe4ee4356ad61cf5057 | 2 |
| 8. | rundll32.exe | 52c1b257f9e6f29f834d6729063f2d86 | 2 |
| 9. | MgKPyEORiQUvGj.exe | 81be2832d96176835fae74530d6d0d5d | 2 |
| 10. | explorer.exe | 25c62889f7db0c400dee08bf65e2f809 | 2 |
| 11. | ftppost2.exe | 5a964755038c5c0a9008177967f1a730 | 1 |
| 12. | netiepad.dll | adaa4a0d2f7309bd69769af09a669a01 | 1 |
| 13. | nnBOhWioHpG62R.exe | 1cefd69ad65710d7441f18802513c290 | 1 |