Can't login to Facebook malware on computer

John Connor

Lifer
Nov 30, 2012
22,757
618
121
So I admin my parent's computer and network. I run a pretty damn tight ship. My parent's computer is protected with Bitdefender Free, VooDoo Shield and the browser runs in Sandboxie. Also, the browser has Noscript and uBlock installed. uBlock prevents ADs which could be laced with malware and uses the malware domain list. I also scan the crap out of the computer with Malwarebytes, Super Anti Spyware, ADwCleaner, Junkware Removal Tool, TDSSKiller, GMER, Rougekiller, Hijackthis, and I even run some live CDs on the computer in a non-boot environment as an extra precaution. Nothing found at all. Despite this, my mom goes to log into Facebook and sees this and can't login.

Qr4Qo6h.jpg




I was so PISSED! to say the least. Because I know damn well there is no malware on the damn computer. What's more is that on this computer I was able to log into my Facebook account with no issue. I even tried another browser and Facebook would not allow my mom to log in. So you know what Facebook wanted me to do? Run their Trend micro scanner. I was like 'the hell I'm running some crap program on a clean machine'! Especially from privacy invading Facebook! But after all my resources were exhausted I ran the damn Trend micro scanner anyway. It said it found four BS items all of the same name of which I can't remember now. I call them BS because I Googled this name and found nothing except other people reporting the same crap on the Internet. But doing this and satisfying Facebook my mom was then able to log into her account.

What I find so disturbing is that it's almost as if they are advertising Trend micro. God only knows what the scanner was doing. Probably uploaded a list of stuff on the computer to Facebook and/or Trend micro. But what was I gonna do? I'll talk about that latter on in section (B) below.

So after this Trend micro BS scan. I dug into the computer for any changes and new registry entries that may have been placed there. I found no new registry entries. I did find a lot of Trend micro crap under AppData\Local\Temp\. The most notable were the following places:

C:\Users\"USER_NAME"\AppData\Local\Temp\HC_1E69.tmp\Updater\AUCache\AU_Cache

C:\Users\"USER_NAME"\AppData\Local\Temp\HC_D411.tmp\Updater\AUCache\AU_Cache

C:\Windows\Prefetch\TRENDMICRO.EXE-C03BA22E.pf

C:\Windows\Prefetch\TRENDMICRO.EXE-FADF8549.pf

C:\Windows\Prefetch\TRENDMICRO_T1314239605261586T-0CB3DBA8.pf

C:\Windows\Prefetch\TRENDMICRO_T1314239605261586T-B2FA11AA.pf

But here's the most interesting. I ran Rougekiller after the Trend micro scan and Rougekiller found an entry from Trend micro that seemed like it could have been attached to svchost.exe. I promptly removed it and ran Rougekiller again and found nothing.

===Section B===

So you know what I'll will do if I see this crap pop up on my Facebook account? Since you have no choice in the matter to run the damn Trend micro scanner to satisfy Facecrooked, I'll just have it run in a virtual machine. The hell I'm going to let their scanner touch my computer! Especially since I FDE all my machines!

Just in case if you were wondering if this was a Facebook malware pop up or some crap. Yes, I thought that when I seen it and when I dug around it's real from Facecrook.

https://www.facebook.com/notes/facebook-security/malware-checkpoint-for-facebook/10150902333195766/

https://www.facebook.com/help/community/question/?id=747730905321731

Now I've read on another social networking site by a person who posted about this very thing. Interesting enough a Facebook engineer posted that he helped design this asinine crap and he says it's more of an art and not a science. So it looks like my mom triggered their BS algorithm thinking my mom was spreading malware or spam or some damn thing. Who knows, but this is absolute BS! Any platform that uses some asinine algorithm as an art rather than a science is a HUGE disparage for their users. Does Reddit, Twitter or other social networking sites even have such garbage?
 

1sikbITCH

Diamond Member
Jan 3, 2001
4,194
574
126
When you have ruled out everything else you are left with the truth.

Mom's a scammer! Sorry got nuthin.
 

balloonshark

Diamond Member
Jun 5, 2008
7,017
3,510
136
I wonder if something in the security setup triggered the warning. Sometimes I have to reload a site many times finding the correct things to allow in noscript.

You could also trying using a light virtualization app to install or run TM. Or you could have imaged, installed and scanned then re-imaged which is the best uninstaller. I would have marked that image as possibly infected though in case you would need it in the future and forget about why it was created.

I'm finding Ublock Origin blocks many things that breaks sites. Ad-block Plus may be more friendly plus I think it also has an optional malware domain list if I remember correctly.
 

John Connor

Lifer
Nov 30, 2012
22,757
618
121
No, this was just a PSA that Facebook's algorithm on detecting so-called "malware" is BS.

It might have been due to my mom clicking on those "suggested pages" and triggering the malware algorithm. I had a look at the Apps she has in her FB account and there's nothing that raises a concern. She only has 5 and are legit. Like Pinterest, Ancestry.com, etc.
 

Ketchup

Elite Member
Sep 1, 2002
14,559
248
106
So, since you didn't find it, but TM did, it must be BS. Sounds about right.

Reminds me of times I would scan computers with Kaspersky, and it wouldn't find anything, then would scan it with AVG and bam! there it was. Just because I program is generally rated higher on detection every so often doesn't mean that it's going going to have better detection every single day, IME.
 

Elixer

Lifer
May 7, 2002
10,371
762
126
The obvious thing to look at is, if there was spam being sent through that account. Don't they have a history of what is going on? (Never used facebook, never plan to either.)

Ketchup makes a good point, it could have been a 0 day exploit, and the other malware / AV programs just didn't have time to update yet...
 

John Connor

Lifer
Nov 30, 2012
22,757
618
121
I did look at the log of posts and fond nothing that wasn't my mom's. VooDoo Shield is there to make sure there aren't any zero days.
 

nerp

Diamond Member
Dec 31, 2005
9,865
105
106
Recently, Avast's root certificates were hijacked. This allowed people to hijack other people's Facebook accounts to send spam. Avast is a steaming pile of crap so this is not surprising.

I wouldn't be surprised if your Trend Micro crap also has been compromised.

Antivirus software only creates new attack vectors for exploits. They don't protect jack. If you disagree, go back to your mom's computer.

Format, reinstall and stop using third party security suites.
 

John Connor

Lifer
Nov 30, 2012
22,757
618
121
No, this isn't an anti-virus issue. It's Facebook algorithm crap I'll assure you. Especially since I can access my Facebook account using the same software, i.e. Bitdefender Free and VooDoo Shield.
 

nerp

Diamond Member
Dec 31, 2005
9,865
105
106
Take a look at your root certificates. Look at the certificates for Facebook. What are that?
 

John Connor

Lifer
Nov 30, 2012
22,757
618
121
What root Certs? Like I said, I use the same software as what's on my mom's computer and I have no issue.