Koobface Removal Instructions (Koobface Facebook Virus)
December 3rd, 2008 | by Alex |Koobface Virus Descriptions:
Koobface is a new virus that spreads through social networking sites in recent days – Facebook or MySpace in particular. Koobface is a nasty virus. It takes control of your computer by sending fake messages to your social network sites’ inbox. By opening the fake yet malicious emails, you would get prompted to install video codec or other malicious ActiveX plugins to view the attachments. As a result of this, Koobface virus will be installed onto your computer aggressively. It does not stop from here. Koobface virus will then hijack your browsers and display annoying fake system alerts. Not only does Koobface dramatically degrade the performance of your computer, it would also put your privacy at risk.
Just follow the removal instructions carefully to remove Koobface. As always, please make a backup of the data before proceeding. Good luck!
Download SpyHunter* Spyware Detection Utility
Manual Koobface Virus Removal Instructions:
Stop Koobface Virus Processes:
(Learn how to do this)
fbtre6.exe
che07.exe
bolivar28.exe
ekrn.exe
ecls.exe
ncsjapi32.exe
Find and Delete Koobface Virus Files:
(Learn how to do this)
fbtre6.exe
che07.exe
bolivar28.exe
ekrn.exe
ecls.exe
ncsjapi32.exe
ekrnEmon.dll
ekrnScan.dll
ekrnEpfw.dll
ekrnAmon.dll
lmfunit32.dll
mcaserv32.dll
kbdsapi.dll
Remove Koobface Virus Registry Values:
(Learn how to do this)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Intelli Mouse Pro Version 2.0B\StubPath: “%WinDir% \System32\splm\ncsjapi32.exe”
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: “%WinDir% \System32\splm\ncsjapi32.exe”
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Intelli Mouse Pro Version 2.0B: “%WinDir% \System32\splm\ncsjapi32.exe”
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden: “2″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*Intelli Mouse Pro Version 2.0B*: “%WinDir% \System32\splm\ncsjapi32.exe”
HKEY_USERS\Software\Microsoft\Windows\nScan32\ExecuteDate: “14\8\2008″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “c:\windows\mstre6.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “C:\Windows\fbtre6.exe”
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating















