Jack Yan
Global  |  Leadership  |  Experience  |  Media  |  Videos
Blog  |  Contact
  You can’t beat Wellington. Subscribe to my Facebook page Join my page on Facebook Follow me on Twitter Follow me on Drivetribe Follow me on Tumblr Follow me on Weibo Check out my Instagram account Follow me on Pinterest Subscribe to my blog’s RSS feed  


Share this page

Quick links

Surf to the online edition of Lucire

Add feeds

Get this blog via email
Enter your Email

Powered by FeedBlitz

Enter your email address:

Delivered by FeedBurner


The Persuader

My personal blog, started in 2006.

« | »


Facebook forced me to download their anti-malware, and my own antivirus gets knocked out

When Facebook says it cares about security, I laugh. Every day I see bots, spammers and click-farm workers plague the site, and despite reporting them, Facebook lets them stay. It will make a statement saying it would no longer kick off drag queens and kings, then proceed to kick off drag queens and kings. So when I was blocked last night from using Facebook on my Windows 10 computer, after using a website with a Facebook messaging plug-in, with the claim that there was malware on the system, I knew something was fishy.
   Like Google’s false malware accusationsso serious that people have lost websites over them—I knew to take this one with a massive grain of salt. However, I didn’t have a choice: in order to get in to the site, I had to download a Kaspersky malware program, and let it run. The program never appeared in my installed list in Windows. I let it run overnight, for seven hours, whereupon it was frozen at 62 per cent. Restarting the computer, I was back to square one.

Above: Doing things the Facebook way. Listening to them was bound to end in tears.

Above: There’s no sign of Kaspersky in Windows’ installed programs’ list.

   Here’s where things started getting very strange. Windows 10 began saying I had no antivirus, anti-malware, or firewall up. Normally I would use McAfee. However, no matter how many times I tried to choose it, the warnings kept coming, thick and fast. In one case, it chose Windows Defender for me—only because I decided to let it run—and would not permit me to change it back through the settings. The timing of these events was all too suspicious.
   There was a rumour, denied by Kaspersky, that it was creating malware to throw off its competitors. The jury’s still out, but it’s just odd that while Kaspersky is running its Facebook scan, of what I knew to be non-existent malware, that McAfee would be inaccessible. I went to the McAfee website to file this.

Above: While the Kaspersky scan proceeded, McAfee was knocked out and could not be switched on. Coincidence?

   Unlike most people, I have options open to me, so I began to go on to Facebook using several different methods. A VirtualBox containing XP on the same computer was fine, if incredibly slow while Kaspersky was doing its thing. (Think about Windows XP on a 386.) Lubuntu was fine as well, as was Mac OS X. I Tweeted the McAfee community link, and thought it odd that it did not appear in Facebook (I have my Twitter set up to post there). I then tried to paste the link into Facebook manually, whereupon, in Lubuntu and Mac OS, I was told that my computer was now infected with either a virus or malware. Unlike Windows, I had the option of telling them they were in error, and I was able to continue using the machines.
   This really sounds like Facebook and Kaspersky have it in for McAfee and, possibly, rival products, if the scan knocks out your choice of antivirus and anti-malware program, and if the mere mention of mcafee.com inside Facebook results in a warning box saying your computer is infected.

Above: On a Mac, I couldn’t even tell people about the post on mcafee.com. The second I did, Facebook said my computer was infected. The same thing happened on Lubuntu. Facebook accuses you of infection on the mere mention of mcafee.com.

   Eventually, the entire system froze, and while I could still move the mouse about, I couldn’t access the task bar or go to other programs.
   I was forced to do a hard reboot.
   But you’re asking now: was I ever infected? No. It’s Google all over again.
   Peter, the very knowledgeable McAfee support tech who came to my aid many years ago, was present again and put me on to two other programs after this restart. Getsusp analysed my system for malware, and, you guessed it, found nothing. Malware Bytes did the same, and found some PUPs (potentially unwanted programs), all of which I knew about, and I had intentionally installed. They’ve been present for years. In other words, two other malware scanners told me my system was clean. Malware Bytes did, however, restore McAfee as the correct antivirus program, exactly as Peter had predicted.
   He also suggested a system restore, which sadly failed, with Windows giving the reason that an antivirus program was running. Having restored this system once before (after some bad advice from Microsoft), I knew it couldn’t be McAfee. The only difference on this computer: I had had Kaspersky doing its Facebook scan. It appears that Facebook and Kaspersky don’t want you restoring your system.
   I had fixed the newer issues, but the original one remained: I couldn’t get on to Facebook. The Kaspersky scan never finishes, incidentally—you’re stuck on 62, 73 or 98 per cent—and while not having a personal Facebook is no great loss, I have businesses that have presences there.
   I stumbled across a Reddit thread where others had been forced to download antivirus programs by Facebook, and, fortunately, a woman there had found where hers resided. In my case, it was at C:\Users\USERNAME\AppData\Local\Temp\FBScanner_331840299. Deleting this, and all cookies mentioning Facebook and Kaspersky, restored my access.
   What to do if you ever come across this? My advice is to, first, run Malware Bytes, but ensure you run the free version, and do not opt for the trials. Once you’re satisfied your computer is clean, head into your cookies and delete all the Facebook ones, and any from the antivirus provider it recommends. This second Reddit thread may be helpful, too. I don’t know if this will work completely, but anything is preferable to following Facebook’s instructions and wasting your time. I really need to stop following instructions from these big firms—you’d think after all these years, I’d know better.

PS.: I found this video from last July which suggests the malware accusations have nothing to do with your computer set-up:

In addition, I cannot paste any links in Facebook. The situation began deteriorating after I regained access. Initially, I could paste and like a few things, but that facility eventually disappeared. Regardless of platform, I get the same error I did on the Mac yesterday (see screen shot above). Liking things results in the below error, and the wisdom there is to wait it out till Facebook staff get back to work on Monday.

P.PS.: Holly Jahangiri confronted the same issue as I did a few days later. She was smarter than me: she didn’t download the anti-malware malware. Have a read of her post here: other than that one difference, it’s almost play for play what happened to me for four days. She’s also rightly frustrated, as I am, by Facebook’s inaction when it’s legitimately needed.

P.P.PS.: Not only does Kaspersky delete your comment when you ask on its blog how to remove the malware scanner, they also clam up when you ask them on Twitter.

P.P.P.PS.: I’m beginning to hear that deleting cookies will not work (April 26). Facebook seems intent on having you download their suspicious junk. In those cases, people have switched to another browser.

P.P.P.P.PS.: Andrew McPherson was hit with this more recently, with Facebook blocking the cookie-deleting method in some cases, and advises, ‘If you get this, you will need to change your Facebook password to something very long (a phrase will do), delete and clear your browsers cache and history, then delete your browser, then renew your IP address to a different number and then reinstall your browsers.’ If you cannot change your IP address but are using a router, then he suggests refreshing the address on that. Basically, Facebook is making it harder and harder for us to work around their bug. Once again, if you sign on using a different account using the same “infected” computer, there are no problems—which means the finger of blame should remain squarely pointed at Facebook.

P.P.P.P.P.PS.: June 17: for those who might find Andrew’s method too technical, the current wisdom is to wait it out. It does appear to take days, however. Reminds me of the time Facebook stopped working for me for 69 hours in 2014.

P.P.P.P.P.P.PS.: January 28, 2017: David has come up with a great solution in the comments (no. 103). You can fool Facebook into thinking you are using a Mac by changing the user-agent. He suggests a Chrome Extension. I have Modify Headers for Firefox, which might work, too.

P.P.P.P.P.P.P.PS.: May 9: Stephan, on my other thread on this topic (comment no. 66), confirms that David’s solution worked and has posted a few more details, including extensions for Firefox, Safari and Chrome.

Related posts

Filed under: internet, technology, USA—Jack Yan @ 06.10

145 Responses to ‘Facebook forced me to download their anti-malware, and my own antivirus gets knocked out’

  1. Jack Yan says:

    You are right, Ann—I hope you have since been able to access your account.

  2. […] more than customers—its distributors surely will think twice. (I’m also looking at you, Kaspersky. Another firm to avoid.)    4. Advertising your website in large letters and have it not […]

  3. David says:

    I did this I found on the net, took 2 seconds –
    Re: Facebook F-Secure malware scanner

    1. Change your user agent with a browser addon – that way you ‘fool’ facebook you are on a Mac – it will prompt you to confirm with an OK that you do not have viruses, instead of forcing you to download the redundant and un-necesarry extra online scanner.
    2. Facebook will see the fake user agent and instead of offering you to download the windows based online scanner will simply present you with a menu – asking “Did you run antivirus for Mac?”
    And you can press “Yes i did” and it lets you in for good.

    3. Then revert back the user agent to its usual state
    4.[Optional] Change your password and run a rull AV scan with your own AV
    5. [Optional] Run an extra malware scan with malware bytes
    just my 2 cents

    Perfect, sod off Facebook. ME 1 – 0 Facebook. 100% works, you can do it manually or there is a Chrome Extension. I used the extension, turn to Sarfari, Loaded facebook, told them I did the scan, then clicked continue to Facebook. Then turn it back to Chrome, Close Chrome and reopened to check and I am in. Good luck, don’t download that software Facebook ask you to its a scam.

  4. Jack Yan says:

    An excellent idea, David! I use Modify Headers on Firefox, for those using Firefox. I will update the original post so people can see your idea. Thank you!

  5. @docgreen81 says:

    Same thing happened to me tonight in Google Chrome. One minute I’m surfing along reading comments, then I click a notification and *BAM*… Facebook logs me out and tells me that I have malware.

    Now, interesting side note… I’m an IT professional. Identifying and removing malware is one of my primary jobs. I have more than adequate malware protection on my computer, and can assure you that I do not, in fact, have malware on my PC.

    I also got a notification on my phone saying “You’re temporarily restricted from creating open graph actions” for 24 hrs.

    I had previously had issues pasting links into Facebook before this, but I had dismissed it as a problem with Chrome, and was always able to fix it by closing and re-opening the browser.

    Also, I had no problem at all logging into my Facebook account ON THE SAME DAMN COMPUTER using Internet Explorer.


  6. Jack Yan says:

    It’s great to get a few very learned opinions on this issue this week. Thank you, Docgreen81. As a professional, you’ll know this is Facebook itself playing silly buggers and nothing to do with someone masquerading as Facebook. There are some who theorize that the download is malware (someone inside Facebook enjoys irony). What we do know is that the Facebook malware warning is, for the most part, BS, since you can get in with IE. Word of this forced download is spreading, so I hope Facebook will eventually have to acknowledge that they have been spying on us.

  7. Erika says:

    David, how do I “1. Change your user agent with a browser addon – that way you ‘fool’ facebook you are on a Mac”? I am not very computer savy, please help.

  8. Jack Yan says:

    Hi Erika, I use a browser add-on to change the user-agent, but I’m on Firefox. Is this what you’re using?
       My Firefox one is called Modify Headers and it can be located here. If you are on Firefox, give that a go—if you’re not clear on how it works, I can try to walk you through it.

  9. Anastasia says:

    Thank you so much for this post. I just run into this problem after reinstalling my pc, full clean install with malwarebytes on. Cleaning cookies didnt help but changing agent to Safari did the trick!
    Glad I found your post :)

  10. Jack Yan says:

    My pleasure, Anastasia! I’m happy this post has helped so many.

  11. Their site is full of spam and malware, yet they have the audacity to enforce “real names” policy, and force us to send them scanned PERSONAL IDs? Are they f**king kidding me? If this is the kind of racket Facebook has decided to be involved in, I’d rather not use Facebook anymore. I don’t understand how the law has not got involved. This is in fact “ransomware.”

  12. Jack Yan says:

    The law, and the tech press (whom I have alerted, too, but no one seems to think this is a worthy story). It looks very damning to me, but maybe no one wants to upset rich people these days. There’s a good reason ‘Welcome to Facebook’ can be abbreviated as WTF.
       I had been progressively cutting down on Facebook anyway, and these forced downloads simply sped up my de-Facebooking. I still have the odd work page on there but as to personal updates, I can’t be bothered. Personal sharing was down 25 per cent in 2015, 29 per cent in 2016, so I imagine they’re desperate to get our data by whatever means possible. Hopefully as word spreads about Facebook’s conduct, more and more will actually leave the site, or at least ensure that sharing is so low Facebook might as well be Myspace.

  13. SandraL says:

    Tonight I was on facebook for at least a couple of hours. I read a post, then went to read an article, posted the article – which was about Venezuela giving Trump $500K for his inauguration…which it got from Russia…and then BOOM! I got that message saying my laptop was infected.

    Now, that seems to me that this has something to do with Russia…but, I did NOT download their antivirus because I already have one running on my system.

    What I did do is sign into FB with not just one, but TWO other FB accounts…on the same computer. No problem. Got in just fine. Then tried to sign in on another computer with my main FB account and boom! same message saying my device was infected. So I know it is account specific.

    I ran two antivirus scans on my computer, and nothing came up. Ran malwarebytes and nothing came up.

    Tried deleting cache and cookies, tried signing in with two different browsers on both computers, and same result. I can sign in with two different accounts but not with my main account.

    I am FUMING! Is Facebook in cahoot with a third company? OR has Facebook itself been hacked and thereby, all user accounts? Are we being monitored for what we upload? or what links we post? Or content?

    Because it seems very, very suspicious that as soon as I tried to post this article, which btw, did NOT post, as I can view what I post through my other accounts via “friends”…that suddenly I’m logged out and I get this notice from FB. Very VERY SUSPICIOUS.

  14. Miles says:

    Which Chrome extension should I use? There is no mention of the one to use?

  15. Jack Yan says:

    Hi Miles: on Firefox, it’s Modify Headers. Because Chrome is Google, I don’t use it, and I suspect David, whose suggestion it was, didn’t subscribe to the comments. I’m sure if you look up header modifications and user agent in wherever Chrome has its add-on library, you’ll find something to suit.

  16. […] have long maintained that Facebook’s databases are dying (hence their need to force people to download malware) and tonight’s discovery is a case of ‘What more proof do you need?’    Tonight, I […]

  17. Cee says:

    Just got that infamous message by facebook

    Let’s Check Your Device for Malicious Software
    Hi Cee, we’re continuously working to keep your account secure. We’ve noticed that this device may be infected with malicious software. To continue to use Facebook, you can either use other devices or clean this device by downloading the scanner provided by Facebook and Trend Micro.

    I tried cleaning the cookies there chrome://settings/cookies


    I tried logging in from explorer browser- same message by facebook.

    Anything I could try ? I am not an expert like you guys.. I have “Windows Defender” and it says it is all ok..

    Thanks for any input!

  18. Jack Yan says:

    Cee, if you scroll up you’ll see a comment by David, who suggests using an extension to modify your headers. There’s a separate comment on this blog (on another thread) which confirms that it works. They are slightly technical but in the second link, Stephan gives step-by-step instructions, and I would highly recommend what he says. I assume you’re using Chrome (because of the chrome://settings/cookies you mention)?

  19. Cee says:

    Thank you Jack Yan.. I read it but must sit with someone who understands the topic I am afraid..
    Apart from that FB ‘s last message was to block my account for 2 days and 22 hours… Wondering what will happen after that time !

  20. Jack Yan says:

    That’s really interesting, Cee. If Facebook has given a time, then it proves once and for all this has nothing to do with malware, and they are lying to you. There’s evidently something wrong with their databases and it’ll take then three days to fix. Others have reported that they were locked out for three days (up to a month in one case). I think in two days and nine hours (given I am replying to you much later), Facebook will just work as though nothing has happened.

  21. Cee says:

    It s really a big joke this FB thing… Wish I did not have to be part of it but my business page is there and until another option is worth it, I will remain there.
    I will report on friday and see if I am back in or not! :)
    Cheers Jack and everyone!

  22. Jack Yan says:

    Thank you, Cee! Like you, if I didn’t have work pages to manage, I’d happily abandon Facebook. I see very little point to it now in 2017.

  23. Suzie says:

    My problem is that I got this message on my employer computer and the last thing I need to do is call the help desk to clean it up. My office manager knows that all of us do this but none of the others have gotten this message. How can I get rid of it from a computer that belongs to the state?

  24. Jack Yan says:

    It might be an idea to contact the help desk because few people seem to believe this is happening. Demonstrate that any other account on your PC is fine, just not yours. Show them this post, and also refer them to my comment above. Hopefully the fix those two users posted still works.

  25. Tina Cosgrove says:

    I got this stupid message this morning using chrome! I refused to download Kaspersky. I did a full scan running my software and cleared my browser history and cache. Still couldnt get into facebook. Switched to firefox and got logged in with no problem!

    BTW i had searched facebook help and found a few people posting about this. I only ever found responses asking for screenshots but never an explanation of why it is happening.

  26. Jack Yan says:

    Great to know you got back in, Tina. Facebook (and Kaspersky, etc.) will never come clean about this—they haven’t to date and I doubt they ever will, probably because whatever they are planting on to our computers is dodgy.

  27. Cee says:

    it seems I forgot to check back with you guys…. sorry about that!
    So yep..the following Friday after that ban of 22hours or so, I was back in as if nothing happened and FB even had the nerve to inform me I had not posted anything those past days…
    Can someone please create something else –worthy– than this FB????

    Cheers everyone!

  28. JTLeung says:

    Hi Jack. It seems I’ve received the same issue as I am unable to access Facebook through Chrome and it wants me to install Kaspersky. I’ve already cleared my browsing cache, history, etc. but refuse to install Kaspersky. My antivirus McAfee and MalwareBytes both came up clean. I’m not sure what to do in order to regain access to Facebook via Chrome. Please advise. Thank you for your assistance. It is greatly appreciated!! Best regards – JTL

  29. Jack Yan says:

    JT, have you tried the idea above of spoofing your headers? It’s in one of the comments. So far that seems to be the best solution.

  30. JTLeung says:

    Hi Jack and thank you for the response. I’m not sure if I did this correctly. I followed the instructions of downloading the Chrome extension, then I went to (https://udger.com/resources/ua-list/browser-detail?browser=Safari) selected a string and pasted that into the Modify Headers for Google Chrome extension and got this:


    Then I went to try out the facebook page and received a different version of their message except this time they asked to scan with Eset instead of Kaspersky.


    I’m not sure if I did any of this correctly as I am not very good with computers. Please advise. Your help is much appreciated. Thank you and best regards :D! – JTL

  31. Jack Yan says:

    Hi JT, what you did looks right to me, but what I would try is a much later version of Safari. See if the one at the bottom of the page you cited works better:

    Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13) AppleWebKit/603.1.13 (KHTML, like Gecko) Version/10.1 Safari/603.1.13

    I don’t use Chrome myself so I am trying to work out the best solutions based on the comments posted. Hopefully the above will be more successful than the user-agent string you tried.

  32. JTLeung says:

    Hi Jack and thanks for the response. Unfortunately, it took me back to the original screen where they ask me to install the Kaspersky scanner. It seems Facebook might have learned about this spoof technique. Do you know anyone else who uses Chrome who is also facing a similar issue recently who also tried this technique? I’m wondering if it might be account based where they lock your account and not an actual Chrome issue.

    Please let me know what you think. Your help is much appreciated. Thank you and have a great week :D! – JTL

  33. […] This happened while Facebook was working fine in my Firefox browser. I found this very helpful hint here ( see comment # 3 in this lengthy article ) how to overcome this strange means and enable Facebook […]

  34. Jack Yan says:

    Hi JT, I’m afraid my sum knowledge of this is largely on this blog. I hear from a lot of people via Twitter but no one has gone into depth on what they have done (given Twitter’s character limits). But I can say with absolute certainty that it is your account they lock. Someone else can log in on your supposedly “infected” PC and have no problems with Facebook. The trick is fooling Facebook into thinking you are running a computer for which they have no fake malware scanner. I had hoped telling them that you were on a Mac would do it. But as I have noticed, Facebook does block techniques that people adopt in order to force them into installing their program. And no one will come clean on what that program does, not ESET, not Kaspersky, no one. If the program was innocent, then they have no reason to clam up.

  35. JTLeung says:

    This is really frustrating. Ongoing for over 10 days now. I think you are absoultely correct about the account being locked. I tried the user agent thing one more time but with a different string [Chose this one: Mozilla/5.0 (Windows; U; Windows NT 6.1; zh-HK) AppleWebKit/533.18.1 (KHTML, like Gecko) Version/5.0.2 Safari/533.18.5 ]

    After revisiting the facebook log in, instead of getting the Kaspersky scanner, I get this message instead “Account temporarily unavailable. Please log into http://www.facebook.com from your computer and follow the instructions you see there”.


    So it seems no matter what I try, it will probably prevent me from accessing my account via Chrome, IE, microsoft Edge, or Opera unless I install their scanner. At this point, not sure what else I can try. Hopefully someone has a new method some time in the near future as I have basically lost all contact and info with all the people I met on Facebook the past few years LOL…

    Thank you again for all the help! It is much appreciated! Best regards and have a great weekend – JTL

  36. LIRON says:

    Hi. The same happened to me… I uploaded Kaspersky and it wrote me that everything fine with my computer. I was sure I’m going to UNinstall Kaspersky but I couldn’t find it on my computer.
    what should I do?
    Thank you guys

  37. dee says:

    This has been happening to me every other DAY for about a month. But only when I use Google Chrome. Sometimes it’s Kaspersky that pops up, but today it was Eset. I had no choice but to uninstall Google Chrome. It got to be that I had to wait until it scans and only then could I get back onto Facebook. All my friends are insisting that I have some major virus, but everything comes up clean. So I wrote to Kaspersky yesterday and eset today to see if there is SOME way to deactive this nightmare.

  38. Jack Yan says:

    It’s discussed in the penultimate paragraph of the main post (there’s a link to Reddit as well).

  39. Jack Yan says:

    I’ve written to them both, and they both clam up. They initially engage with you when you don’t tell them what it’s about. The minute you do, and you say it’s the Facebook malware scanner, they run a mile. Your friends are all wrong, this is Facebook at its finest. Facebook has even bragged about offering it. This will keep spreading—then I’m sure they’ll believe you.

  40. Jack Yan says:

    Hi JT, the only remaining suggestion I have if you have gone through the header changes is to use a Mac or a Linux machine for real and see if that makes a difference. Back in 2016 when this hit me, I was able to get in via Mac and Ubuntu (but not post links).

  41. dee says:

    Yup..wrote to both and they both claimed innocence. That I should write to Facebook about it! LOL..yeah, good luck with that. I also found the FB_scanner file in my temp files, like you instructed. I click on them and it turns into a zip file. I click on THAT and it says “CHROME_EXT” As soon as I stopped using Chrome, I stopped being bothered by it. I also cannot delete those scanner files no matter what I do. Any suggestions on how to get rid of them? Thanks so much for this blog.

  42. Jack Yan says:

    Hi Dee, I’m not sure how to get rid of those scanner files. When I got this, I could just delete that FB_scanner folder. I imagine they must have changed their program since to prevent people from deleting it. You could give Ccleaner a try—I’ve found it pretty good when it comes to removing useless files. I just don’t know if it’s designed to pick up the Facebook “scanner”.

  43. dee says:

    Thanks! Will give it a try…they are insidious and evil!

  44. […] in 2017, giving fewer clues about how candidates are thinking, and I hardly look at my Facebook (for obvious reasons). I have spied some of the TVCs, where Labour has done an excellent job, and (last I looked) […]

  45. […] in its pettiness over allegedly targeting Vivaldi, and Facebook doesn’t as it gathers data and falsely accuses its own users of having malware on their machines.    On September 1, my colleague Euan Semple wrote, ‘As tools and services provided by […]

Leave a reply