Trojan

Trojan:Win32/Koobface.K information

Malware Removal

The Trojan:Win32/Koobface.K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Koobface.K virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Koobface.K?


File Info:

name: 18812D503DEE9ACC26BA.mlw
path: /opt/CAPEv2/storage/binaries/032a8e35be5406d2b61287ad40a91eb5aa6178f36da9a432ee2a3528fd953e7d
crc32: B8A5E954
md5: 18812d503dee9acc26baf353d58a5462
sha1: e33364c1200b8cc79a7a68b819000b51e5d83669
sha256: 032a8e35be5406d2b61287ad40a91eb5aa6178f36da9a432ee2a3528fd953e7d
sha512: fe1885eb7b060e90b8d6b6c7f2ed95272e2f8125ef9e8b0553d9df858ff57dfc1dce2f0a9a8d2bebc3af38f63c229955384058c60430bc3d1738b90182e23e4c
ssdeep: 1536:YoYHOJZGCzsDor44jCojxkwaknRFHQAAD8lco+T1ikF0kBpUx:Yoj3z44jC4xkhkRFwP4lL+T1ikvpUx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B643F215EEA9481FF19B5EB200DB4FD3307B718EDF5A0BA80E4A902639748CC25D6D79
sha3_384: dfa61816b4cf918d5f23201b2c628b1b0a6ad9d20fab59d0348bb500a6dce48e2ac3b4179026a702f309cb950e560ed6
ep_bytes: 60be006041008dbe00b0feff57eb0b90
timestamp: 2011-04-28 12:59:11

Version Info:

CompanyName: Windows Service
FileDescription: Windows Service
FileVersion: 1.0.0.1
InternalName: Notify
LegalCopyright: Copyright (C) 2011
ProductName: Windows Service
ProductVersion: 1.0.0.1
Translation: 0x0419 0x04b0

Trojan:Win32/Koobface.K also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Koobface.p!c
MicroWorld-eScanGen:Variant.Ransom.Nemty.17
FireEyeGeneric.mg.18812d503dee9acc
SkyhighGenericRXKI-GC!68AD72DFBF91
ALYacGen:Variant.Ransom.Nemty.17
Cylanceunsafe
ZillyaWorm.Koobface.Win32.6766
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaWorm:Win32/Koobface.ae347505
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.03dee9
BitDefenderThetaAI:Packer.DB2C6E951F
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Spammer.Agent.J
APEXMalicious
TrendMicro-HouseCallTROJ_KOOBFACE_000000c.TOMA
ClamAVWin.Worm.Koobface-365
KasperskyNet-Worm.Win32.Koobface.babd
BitDefenderGen:Variant.Ransom.Nemty.17
NANO-AntivirusTrojan.Win32.Koobface.kxzvx
AvastWin32:Downloader-GQF [Trj]
TencentMalware.Win32.Gencirc.13c1b5fd
EmsisoftGen:Variant.Ransom.Nemty.17 (B)
F-SecureTrojan.TR/Spy.Gen
DrWebWin32.HLLW.Facebook.989
VIPREGen:Variant.Ransom.Nemty.17
TrendMicroTROJ_KOOBFACE_000000c.TOMA
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminWorm/Koobface.bof
GoogleDetected
AviraTR/Spy.Gen
VaristW32/Koobface.R.gen!Eldorado
Antiy-AVLWorm[Net]/Win32.Koobface
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/Koobface.K
XcitiumTrojWare.Win32.Agent.tmbl@3z144o
ArcabitTrojan.Ransom.Nemty.17
ViRobotWorm.Win32.A.Net-Koobface.57864.A[UPX]
ZoneAlarmNet-Worm.Win32.Koobface.babd
GDataGen:Variant.Ransom.Nemty.17
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R4582
McAfeeArtemis!18812D503DEE
MAXmalware (ai score=100)
VBA32BScope.Worm.Koobface
PandaTrj/Genetic.gen
RisingTrojan.Koobface!8.CD6 (TFE:5:1oO4FbbcIeP)
YandexWorm.Koobface!uqicOsPUL/c
IkarusTrojan.Win32.Jorik
MaxSecureTrojan.Malware.2076871.susgen
FortinetW32/KoobFace.IED!tr
AVGWin32:Downloader-GQF [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm[net]:Win/Koobface.babd

How to remove Trojan:Win32/Koobface.K?

Trojan:Win32/Koobface.K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment