Malicious code via 'You look funny in this video' message hits Facebook
While Orkut was blocked at workplaces and schools, Facebook was the new kid on the block for Indian users. However, a new worm identified as Koobface sends a malicious code via a message to the Facebook users. To remove the infection, follow these instructions.
McAfee Avert Labs' threat researcher, Craig Schmugar, confirmed on CNet news that the Net-Worm.Win32.Koobface.a worm affects only social networking sites. When a user clicks on the incoming message 'You look funny in this video,' Flash player update is requested and the user is redirected to a site with a Flash video player. When the user clicks on the link to update, Koobface downloads a malicious file 'tinyproxy.exe' onto the user's system, which loads a proxy server Security Accounts Manager that listens to the traffic on the TCP port 9090, and the entire outgoing HTTP traffic gets proxied.
Facebook representative Barry Schnitt said that this worm is the same as the one reported back in August, but this might be a variant. Unfortunately, there isn't any online scanner to remove Koobface from Facebook.