{"id":10,"date":"2009-12-08T09:45:36","date_gmt":"2009-12-08T14:45:36","guid":{"rendered":"http:\/\/williamscomputers.com\/?p=10"},"modified":"2009-12-08T11:51:00","modified_gmt":"2009-12-08T16:51:00","slug":"koobface-gq","status":"publish","type":"post","link":"https:\/\/williamscomputers.com\/?p=10","title":{"rendered":"Virus Koobface.GQ"},"content":{"rendered":"<table id=\"enciclo_tabla\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\">\n<tbody>\n<tr>\n<td style=\"height: 10px;\" colspan=\"2\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.pandasecurity.com\/img\/trans.gif\" alt=\"\" width=\"1\" height=\"1\" \/><\/td>\n<\/tr>\n<tr id=\"row_NombreComun\">\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#NCOMUN\" target=\"glossary\">Common name<\/a>:<\/td>\n<td>Koobface.GQ<\/td>\n<\/tr>\n<tr id=\"row_NombreTecnico\">\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#NTECNICO\" target=\"glossary\">Technical name<\/a>:<\/td>\n<td>W32\/Koobface.GQ.worm<\/td>\n<\/tr>\n<tr id=\"row_Peligrosidad\">\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#PELIGROSIDAD\" target=\"glossary\">Threat level<\/a>:<\/td>\n<td>Medium<\/td>\n<\/tr>\n<tr id=\"row_Tipo\">\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#TIPO\" target=\"glosario\">Type<\/a>:<\/td>\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#Worm\" target=\"glosario\">Worm<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#SINTOMAS\" target=\"glossary\">Effects<\/a>:<a name=\"EFECTOSTABLA\"> <\/a><\/td>\n<td><a id=\"EFECTOSTABLA\" name=\"EFECTOSTABLA\"><\/a>Its main aim is to spread itself via the\u00a0social network Facebook\u00a0and affect as many computers as possible. It\u00a0displays a message on screen requiring users to enter some characters on the screen in order to avoid the computer restart.<\/td>\n<\/tr>\n<tr id=\"row_Plataformas\">\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#PLATAFORMA\" target=\"glosario\">Affected platforms<\/a>:<\/td>\n<td><span lang=\"EN-US\">Windows 2003\/XP\/2000\/NT\/ME\/98\/95<\/span><\/td>\n<\/tr>\n<tr id=\"row_FechaDeteccion\">\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#FECHADETEC\" target=\"glossary\">First detected on<\/a>:<\/td>\n<td><em>Dec. <\/em>3, 2009<\/td>\n<\/tr>\n<tr id=\"row_FechaModificacion\">\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#FECHAMODIF\" target=\"glossary\">Detection updated on<\/a>:<\/td>\n<td><em>Dec. <\/em>4, 2009<\/td>\n<\/tr>\n<tr id=\"row_EnCirculacion\">\n<td><a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/#ESTADISTICAS\" target=\"glossary\">Statistics<\/a><\/td>\n<td>No<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table id=\"table_DescripcionBreve\" border=\"0\">\n<tbody>\n<tr>\n<td>\n<h2>Brief Description<a name=\"BREVE\"> <\/a><\/h2>\n<\/td>\n<td width=\"1%\" align=\"right\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\"><a id=\"BREVE\" name=\"BREVE\"><\/a><em>Koobface.GQ<\/em> is a <a href=\"http:\/\/www.pandasecurity.com\/homeusers\/security-info\/glossary\/glossary.aspx#GUSANO\" target=\"_blank\">worm<\/a> whose main aim is to spread itself via the\u00a0social network Facebook\u00a0and affect as many computers as possible.Additionally, it\u00a0connects to a certain website in order to download malicious files, which belong to other variants of\u00a0<em>Koobface<\/em> in order to extend its spread.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table id=\"table_SintomasVisibles\" border=\"0\">\n<tbody>\n<tr>\n<td>\n<h2>Visible Symptoms<a name=\"VISIBLES\"> <\/a><\/h2>\n<\/td>\n<td width=\"1%\" align=\"right\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\"><a id=\"VISIBLES\" name=\"VISIBLES\"><\/a><em>Koobface.GQ<\/em> is\u00a0easy to recognize, as it shows the following symptoms:<\/p>\n<ul>\n<li>It publishes a link to a video in the affected user&#8221;&#8221;&#8221;&#8221;&#8221;&#8221;&#8221;&#8221;s Facebook main site, which will be shared to all their contacts. If the link is followed, a website similar to YouTube&#8221;&#8221;&#8221;&#8221;&#8221;&#8221;&#8221;&#8221;s (actually YuoTube) is displayed:<img decoding=\"async\" src=\"http:\/\/www.pandasecurity.com\/img\/enc\/W32KoobfaceGQworm_img1.jpg\" border=\"0\" alt=\"\" \/><\/li>\n<li>When it is run, it displays a message like the following on the screen:<img decoding=\"async\" src=\"http:\/\/www.pandasecurity.com\/img\/enc\/W32KoobfaceGQworm_img3.jpg\" border=\"0\" alt=\"\" \/><br \/>\nThis message informs users that they have to enter some characters and if they don&#8221;&#8221;&#8221;&#8221;&#8221;&#8221;&#8221;&#8221;t, the computer will be restarted in 3 minutes.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Common name: Koobface.GQ Technical name: W32\/Koobface.GQ.worm Threat level: Medium Type: Worm Effects: Its main aim is to spread itself via the\u00a0social network Facebook\u00a0and affect as many computers as possible. It\u00a0displays a message on screen requiring users to enter some characters on the screen in order to avoid the computer restart. Affected platforms: Windows 2003\/XP\/2000\/NT\/ME\/98\/95 First [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-10","post","type-post","status-publish","format-standard","hentry","category-virusalerts"],"_links":{"self":[{"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/posts\/10","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10"}],"version-history":[{"count":3,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/posts\/10\/revisions"}],"predecessor-version":[{"id":14,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=\/wp\/v2\/posts\/10\/revisions\/14"}],"wp:attachment":[{"href":"https:\/\/williamscomputers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/williamscomputers.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}