Remove FacexWorm Virus From Your PC

Remove FacexWorm Virus From Your PC

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)

This article has been created in order to help you to learn what is the FacexWorm remote access Trojan and how to remove this malware completely from your computer plus protect your PC against future infections as well.

The FacexWorm virus is a newly discovered computer threat that bears an advanced infection engine. It targets computer users using redirects and browser hijackers and has the potential to hijack their cryptocurrency assets and spy on them in real time. Read our complete analysis to find out more about it. Our in-depth removal instructions for FacexWorm virus can help victims get rid of the active infections.

Threat Summary

TypeRemote Access Trojan (RAT), Cryptocurrency miner, Trojan
Short DescriptionThe FacexWorm virus is a dangerous worm that can hijack sensitive data, including cryptocurrency assets.
SymptomsThe users may notice that their browser settings are changed and that interaction with certain sites may lead to unexpected behavior.
Distribution MethodMainly via browser redirects and social engineering scams.
Detection Tool See If Your System Has Been Affected by FacexWorm


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss FacexWorm.

FacexWorm – Distribution Methods

The FacexWorm virus is a dangerous worm that has recently been discovered by Trend Labs experts in a worldwide attack against computer users. Instead of the usual email delivery tactics it uses alternative methods that have a high infection ratio. The analysts have observed that the actual mechanism is a fairy complex one.

It involves the setup of fake profiles on Facebook. They are programmed via bots to send out links to the intended victims. The links lead to redirects that open a notification prompt asking the users to install a malware browser hijacker. Thеy represent dangerous browser plugins that have the ability to change the default settings to redirect the victims to a hacker-controlled page. Example system changes include the default home page, new tabs page and the search engine. The developers behind these malware extensions usually make it compatible with the most popular applications: Mozilla Firefox, Google Chrome, Opera, Microsoft Edge, Safari and Internet Explorer. As soon as the threat has been delivered to the target computers the built-in scripts will be initiated.

So far this has been the main method. We envision that the criminals will also set up alternative channels of distribution that can propagate the FacexWowrm virus. A related mechanism is the use of bundle software installers. The hacker operators behind the threat may embed the code into installers of popular applications. Examples include system utilities, computer games or creativity suites. In most cases the virus delivery can happen without the user noticing. Only in certain cases the victims may be presented with the option of disallowing the installation.

Another mechanism is its inclusion into web scripts that can also affect legitimate sites through affiliate and ad networks. Examples include all kinds of banners, pop-ups and redirects.

The hackers behind the FacexWorm virus have been found to operate a multitude of domains and C&C servers.

FacexWorm – Purpose and Activity

Once the FacexWorm virus has infiltrated the victim machine it will automatically start itself. In certain cases the threat can install itself as a persistent threat. This means that it will change various system settings in order to automatically start every time the computer is booted.

When the malware plugin is started it will start to spy on the users activity and particularly their web browser habits. As soon as Facebook or another social network is opened by the users a connection with hacker-controlled servers is started. The hackers can then automatically obtain the OAuth token and therefore gain access to their accounts.

One of the first actions is to harvest the affected victims friends list and use it to send fake YouTube videos to the contacts that are either online or idle. This is done to spread malware or advertisement to the users for scam purposes. The security analysts have detected that when the relevant links are opened in a web browser other than Google Chrome (its desktop variant), the link will be changed to lead to a random advertisement. This will generate income for the operators.

The standard behavior is to execute the code the delivered code. Some of the built-in functions of the captured samples include the following commands:

  • Steal Account Credentials — When a compatible service’s login page is open a stealer function will be injected to the web browsers. It is inteded to steal the account credentials of the following sites: Google, MyMonero and Coinhive. It is expected that this list will grow further.
  • Cryptocurrency Scams — When the FacexWorm virus detects that the users is accessing cryptocurrency trading platforms or exchanges it will automatically redirect them to a scam site. The currently captured strains have been found to feature a built-in list of 52 sites and a lot of keywords. The scams themselves coerce the victims into sending 0.5 to 10 ETH to the hacker’s wallet address for “verification purposes”.
  • Cryptocurrency Mining — The virus is capable of injecting JavaScript code that can lead to a cryptocurrency miner instance. Some of the captured strains of FacexWorm have instituted a CoinHive script. The downloaded versions are customized to use only 20% of the available system CPU for each thread, four threads are to be opened for mining on web pages. This setup does not impact overall system performance that much and can remain undetected in longer periods of time.
  • Transactions Hijack — Once a cryptocurrency transaction page is opened a on a cryptocurrency-relted site the virus will located the entered recipient address and replace it with the hacker’s own. At the moment the following platforms are implemented: HitBTC, Bitfinex, Ethfinex and Binance. A wallet application is targeted as well ( The following digital assets are targeted at the moment: Bitcoin (BTC), Bitcoin Gold (BTG), Bitcoin Cash (BCH), Dash (DASH), ETH, Ethereum Classic (ETC), Ripple (XRP), Litecoin (LTC), Zcash (ZEC), and Monero (XMR).
  • Referral Programs Infection — Certain web sites can lead to a specific referral link. This means that purchases or certain interactions can lead to direct income being generated for the hackers. At the moment the following sites are targeted: Binance, DigitalOcean,,, and HashFlare.

One of the integral features of the worm is the persistence protection component. It detects when the victims attempt to remove the malware extension by automatically closing the Chrome extensions management page.

Remove FacexWorm from Your Computer

In order to make sure that this nefarious software is completely gone from your computer, security researchers strongly advise following the manual or automatic removal instructions underneath. They are created in order to assist you based on how much experience you have in malware removal. If you lack such experience, be advised that security analysts strongly advise to download an advanced anti-malware software and remove FacexWorm automatically by scanning for all of it’s objects and changed settings and reverting them back to normal. Such tool has the capability to not only fully secure your PC after removing FacexWorm, but also make sure it’s operating system remains protected against future intrusions that might take place.


Martin Beltov

Martin graduated with a degree in Publishing from Sofia University. As a cyber security enthusiast he enjoys writing about the latest threats and mechanisms of intrusion.

More Posts - Website

Follow Me:
TwitterGoogle Plus

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share