Analysis by: Erika Bianca Mendoza

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Adware

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

Cookies may also be used by malware to gather information related to site preferences, sessions or other computer activities. For example, WORM_KOOBFACE makes use of cookies related to social networking sites, such as Facebook and Twitter, to allow the malware to post malicious links using the affected user's account credentials.

  TECHNICAL DETAILS

File Size: Varies
Memory Resident: No
Initial Samples Received Date: 30 Mar 2011

NOTES:

This tracking cookie is installed on a system when an affected user visits the websites, http://www.{BLOCKED}click.com.

Tracking cookies (also known as data miners) are cookies that are used by two or more websites to track an affected user's Web browsing habits and display advertisement or other material the users might be interested in.Similar to adware, tracking cookies collect user information for third party recipients.

Cookies may also be used by malware to gather information related to site preferences, sessions or other computer activities. For example, WORM_KOOBFACE makes use of cookies related to social networking sites, such as Facebook and Twitter, to allow the malware to post malicious links using the affected user's account credentials.

  SOLUTION

Minimum Scan Engine: 8.900

Step 1

Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.

Step 2

Scan your computer with your Trend Micro product to delete files detected as COOKIE_DOUBLECLICK If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:


Did this description help? Tell us how we did.