This article has been created in order to help you to learn what is the FacexWorm remote access Trojan and how to remove this malware completely from your computer plus protect your PC against future infections as well.
The FacexWorm virus is a newly discovered computer threat that bears an advanced infection engine. It targets computer users using redirects and browser hijackers and has the potential to hijack their cryptocurrency assets and spy on them in real time. Read our complete analysis to find out more about it. Our in-depth removal instructions for FacexWorm virus can help victims get rid of the active infections.
|Type||Remote Access Trojan (RAT), Cryptocurrency miner, Trojan|
|Short Description||The FacexWorm virus is a dangerous worm that can hijack sensitive data, including cryptocurrency assets.|
|Symptoms||The users may notice that their browser settings are changed and that interaction with certain sites may lead to unexpected behavior.|
|Distribution Method||Mainly via browser redirects and social engineering scams.|
|Detection Tool|| See If Your System Has Been Affected by malware |
Malware Removal Tool
|User Experience||Join Our Forum to Discuss FacexWorm.|
FacexWorm – Distribution Methods
The FacexWorm virus is a dangerous worm that has recently been discovered by Trend Labs experts in a worldwide attack against computer users. Instead of the usual email delivery tactics it uses alternative methods that have a high infection ratio. The analysts have observed that the actual mechanism is a fairy complex one.
It involves the setup of fake profiles on Facebook. They are programmed via bots to send out links to the intended victims. The links lead to redirects that open a notification prompt asking the users to install a malware browser hijacker. Thеy represent dangerous browser plugins that have the ability to change the default settings to redirect the victims to a hacker-controlled page. Example system changes include the default home page, new tabs page and the search engine. The developers behind these malware extensions usually make it compatible with the most popular applications: Mozilla Firefox, Google Chrome, Opera, Microsoft Edge, Safari and Internet Explorer. As soon as the threat has been delivered to the target computers the built-in scripts will be initiated.
So far this has been the main method. We envision that the criminals will also set up alternative channels of distribution that can propagate the FacexWowrm virus. A related mechanism is the use of bundle software installers. The hacker operators behind the threat may embed the code into installers of popular applications. Examples include system utilities, computer games or creativity suites. In most cases the virus delivery can happen without the user noticing. Only in certain cases the victims may be presented with the option of disallowing the installation.
Another mechanism is its inclusion into web scripts that can also affect legitimate sites through affiliate and ad networks. Examples include all kinds of banners, pop-ups and redirects.
The hackers behind the FacexWorm virus have been found to operate a multitude of domains and C&C servers.
FacexWorm – Purpose and Activity
Once the FacexWorm virus has infiltrated the victim machine it will automatically start itself. In certain cases the threat can install itself as a persistent threat. This means that it will change various system settings in order to automatically start every time the computer is booted.
When the malware plugin is started it will start to spy on the users activity and particularly their web browser habits. As soon as Facebook or another social network is opened by the users a connection with hacker-controlled servers is started. The hackers can then automatically obtain the OAuth token and therefore gain access to their accounts.
One of the first actions is to harvest the affected victims friends list and use it to send fake YouTube videos to the contacts that are either online or idle. This is done to spread malware or advertisement to the users for scam purposes. The security analysts have detected that when the relevant links are opened in a web browser other than Google Chrome (its desktop variant), the link will be changed to lead to a random advertisement. This will generate income for the operators.
The standard behavior is to execute the code the delivered code. Some of the built-in functions of the captured samples include the following commands:
- Steal Account Credentials — When a compatible service’s login page is open a stealer function will be injected to the web browsers. It is inteded to steal the account credentials of the following sites: Google, MyMonero and Coinhive. It is expected that this list will grow further.
- Cryptocurrency Scams — When the FacexWorm virus detects that the users is accessing cryptocurrency trading platforms or exchanges it will automatically redirect them to a scam site. The currently captured strains have been found to feature a built-in list of 52 sites and a lot of keywords. The scams themselves coerce the victims into sending 0.5 to 10 ETH to the hacker’s wallet address for “verification purposes”.
- Transactions Hijack — Once a cryptocurrency transaction page is opened a on a cryptocurrency-relted site the virus will located the entered recipient address and replace it with the hacker’s own. At the moment the following platforms are implemented: HitBTC, Bitfinex, Ethfinex and Binance. A wallet application is targeted as well (Blockchain.info). The following digital assets are targeted at the moment: Bitcoin (BTC), Bitcoin Gold (BTG), Bitcoin Cash (BCH), Dash (DASH), ETH, Ethereum Classic (ETC), Ripple (XRP), Litecoin (LTC), Zcash (ZEC), and Monero (XMR).
- Referral Programs Infection — Certain web sites can lead to a specific referral link. This means that purchases or certain interactions can lead to direct income being generated for the hackers. At the moment the following sites are targeted: Binance, DigitalOcean, FreeBitco.in, FreeDoge.co.in, and HashFlare.
One of the integral features of the worm is the persistence protection component. It detects when the victims attempt to remove the malware extension by automatically closing the Chrome extensions management page.
Remove FacexWorm from Your Computer
In order to make sure that this nefarious software is completely gone from your computer, security researchers strongly advise following the manual or automatic removal instructions underneath. They are created in order to assist you based on how much experience you have in malware removal. If you lack such experience, be advised that security analysts strongly advise to download an advanced anti-malware software and remove FacexWorm automatically by scanning for all of it’s objects and changed settings and reverting them back to normal. Such tool has the capability to not only fully secure your PC after removing FacexWorm, but also make sure it’s operating system remains protected against future intrusions that might take place.
- Guide 1: How to Remove FacexWorm from Windows.
- Guide 2: Get rid of FacexWorm from Mac OS X.
- Guide 3: Remove FacexWorm from Google Chrome.
- Guide 4: Erase FacexWorm from Mozilla Firefox.
- Guide 5: Uninstall FacexWorm from Microsoft Edge.
- Guide 6: Remove FacexWorm from Safari.
- Guide 7: Eliminate FacexWorm from Internet Explorer.
How to Remove FacexWorm from Windows.
Step 1: Boot Your PC In Safe Mode to isolate and remove FacexWorm
Step 2: Uninstall FacexWorm and related software from Windows
Step 3: Clean any registries, created by FacexWorm on your computer.
The usually targeted registries of Windows machines are the following:
You can access them by opening the Windows registry editor and deleting any values, created by FacexWorm there. This can happen by following the steps underneath:
Get rid of FacexWorm from Mac OS X.
Step 1: Uninstall FacexWorm and remove related files and objects
1. Hit the ⇧+⌘+U keys to open Utilities. Another way is to click on “Go” and then click “Utilities”, like the image below shows:
- Go to Finder.
- In the search bar type the name of the app that you want to remove.
- If all of the files are related, hold the ⌘+A buttons to select them and then drive them to “Trash”.
In case you cannot remove FacexWorm via Step 1 above:
You can repeat the same procedure with the following other Library directories:
Tip: ~ is there on purpose, because it leads to more LaunchAgents.
Step 2: Scan for and remove malware from your Mac
Remove FacexWorm from Google Chrome.
Step 1: Start Google Chrome and open the drop menu
Step 2: Move the cursor over "Tools" and then from the extended menu choose "Extensions"
Erase FacexWorm from Mozilla Firefox.
Step 1: Start Mozilla Firefox. Open the menu window
Step 2: Select the "Add-ons" icon from the menu.
Step 3: Select the unwanted extension and click "Remove"
Uninstall FacexWorm from Microsoft Edge.
Step 1: Start Edge browser.
Step 2: Open the drop menu by clicking on the icon at the top right corner.
Step 3: From the drop menu select "Extensions".
Step 4: Choose the suspected malicious extension you want to remove and then click on the gear icon.
Step 5: Remove the malicious extension by scrolling down and then clicking on Uninstall.
Remove FacexWorm from Safari.
Step 1: Start the Safari app.
Step 3: From the menu, click on "Preferences".
Step 4: After that, select the 'Extensions' Tab.
Step 5: Click once on the extension you want to remove.
Step 6: Click 'Uninstall'.
A pop-up window will appear asking for confirmation to uninstall the extension. Select 'Uninstall' again, and the FacexWorm will be removed.
Eliminate FacexWorm from Internet Explorer.
Step 1: Start Internet Explorer.
Step 2: Click on the gear icon labeled 'Tools' to open the drop menu and select 'Manage Add-ons'
Step 3: In the 'Manage Add-ons' window.