Malware

How to remove “Koobface.1 (B)”?

Malware Removal

The Koobface.1 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Koobface.1 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Catalan
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Ramnit malware family
  • Creates a copy of itself

How to determine Koobface.1 (B)?


File Info:

name: F44DE51501AB6D29180F.mlw
path: /opt/CAPEv2/storage/binaries/e89d9d1162cf42462b697c90b4fce19e18afbc16561cfa6ea98cc63d3289c572
crc32: 500A75AB
md5: f44de51501ab6d29180f40240f25c9b8
sha1: 35d8a582d0e8a1c78ca9a8d8d77d350836733404
sha256: e89d9d1162cf42462b697c90b4fce19e18afbc16561cfa6ea98cc63d3289c572
sha512: 6682f76b115fecaeb4c2f7a01c16135de2b5b2f36bb553b13a65a310db3dfc65bcfcb0c68336459ad0fc11fae3342986a8892e8bb132af9d3dc01855c17a35b2
ssdeep: 768:/06R0UKzOgnKqGR7//GPc0LOBhvBrHks3IiyhDYQbGmxlNaM+WGa1wuxnzgOYw9B:lR0vxn3Pc0LCH9MtbvabUDzJYWu3Bc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119E3248FE4A8518DE5F7E73E4036FFC2053E78B585AA8067322891ED55B684DC78C13A
sha3_384: 356d2c703566398ffff9d9e721ebf4f7b17a1c44270109fdb984ef5cd579ad32b88db02602fd28d4cf26b29c410bd33d
ep_bytes: 558bec83ec2c8165ec000000008d5b56
timestamp: 2003-03-23 13:28:50

Version Info:

CompanyName: Macromedia, Inc.
FileDescription: Macromedia Flash Player 7.0 r19
FileVersion: 7,0,19,0
InternalName: Macromedia Flash Player 7.0
LegalCopyright: Copyright © 1996-2003 Macromedia, Inc.
LegalTrademarks: Macromedia Flash Player
OriginalFilename: SAFlashPlayer.exe
ProductName: Shockwave Flash
ProductVersion: 7,0,19,0
Translation: 0x0409 0x04b0

Koobface.1 (B) also known as:

BkavW32.FamVT.DisbukCI.Trojan
MicroWorld-eScanGen:Variant.Koobface.1
FireEyeGeneric.mg.f44de51501ab6d29
CAT-QuickHealTrojan.Ramnit.A
ALYacGen:Variant.Koobface.1
CylanceUnsafe
VIPREGen:Variant.Koobface.1
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Koobface.1
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34646.jy0@a858cumH
VirITTrojan.Win32.Generic.SUG
CyrenW32/Virut.C.gen!Eldorado
SymantecPacked.Protexor!gen1
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Ramnit.AU.Gen
BaiduWin32.Trojan.Nimnul.a
APEXMalicious
ClamAVWin.Virus.Virut-6804273-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Ramnit.bbgdmp
CynetMalicious (score: 100)
ViRobotWorm.Win32.A.Net-Koobface.126464
RisingWin32.Ramnit.m (CLASSIC)
Ad-AwareGen:Variant.Koobface.1
SophosML/PE-A + Mal/Ramnit-ZZ
ComodoTrojWare.Win32.Kryptik.ILZ@39m3x2
DrWebTrojan.Siggen2.9448
TrendMicroWORM_PALEVO.SMGD
McAfee-GW-EditionBehavesLike.Win32.Dropper.cm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Koobface.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/Virut.bv
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Ramnit
SUPERAntiSpywareTrojan.Agent/Gen-Ramnit
GDataGen:Variant.Koobface.1
GoogleDetected
AhnLab-V3Trojan/Win32.Krap.R20076
McAfeePWS-Zbot.gen.di
TACHYONWorm/W32.Qvod.154112.B
VBA32Malware-Cryptor.Win32.General.4
MalwarebytesNimnul.Virus.FileInfector.DDS
PandaTrj/Pck_Pretorx.A
TrendMicro-HouseCallWORM_PALEVO.SMGD
TencentTrojan.Win32.Koobface.udb
YandexTrojan.GenAsa!MLownxgq9A8
IkarusVirus.Win32.Ramnit
FortinetW32/CoinMiner.F
AVGWin32:Crypto-V [Trj]
Cybereasonmalicious.501ab6
AvastWin32:Crypto-V [Trj]

How to remove Koobface.1 (B)?

Koobface.1 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment