Jack Yan
Global  |  Leadership  |  Experience  |  Media  |  Videos
Blog  |  Contact
 
  You can’t beat Wellington. Subscribe to my Facebook page Join my page on Facebook Follow me on Twitter Follow me on Drivetribe Follow me on Tumblr Follow me on Weibo Check out my Instagram account Follow me on Pinterest Subscribe to my blog’s RSS feed  

 

Share this page




Quick links


Surf to the online edition of Lucire





Add feeds



Get this blog via email
Enter your Email


Powered by FeedBlitz

Enter your email address:


Delivered by FeedBurner



 

The Persuader

My personal blog, started in 2006.



« | »

02.01.2016

Facebook forced me to download their anti-malware, and my own antivirus gets knocked out

When Facebook says it cares about security, I laugh. Every day I see bots, spammers and click-farm workers plague the site, and despite reporting them, Facebook lets them stay. It will make a statement saying it would no longer kick off drag queens and kings, then proceed to kick off drag queens and kings. So when I was blocked last night from using Facebook on my Windows 10 computer, after using a website with a Facebook messaging plug-in, with the claim that there was malware on the system, I knew something was fishy.
   Like Google’s false malware accusationsso serious that people have lost websites over them—I knew to take this one with a massive grain of salt. However, I didn’t have a choice: in order to get in to the site, I had to download a Kaspersky malware program, and let it run. The program never appeared in my installed list in Windows. I let it run overnight, for seven hours, whereupon it was frozen at 62 per cent. Restarting the computer, I was back to square one.




Above: Doing things the Facebook way. Listening to them was bound to end in tears.


Above: There’s no sign of Kaspersky in Windows’ installed programs’ list.

   Here’s where things started getting very strange. Windows 10 began saying I had no antivirus, anti-malware, or firewall up. Normally I would use McAfee. However, no matter how many times I tried to choose it, the warnings kept coming, thick and fast. In one case, it chose Windows Defender for me—only because I decided to let it run—and would not permit me to change it back through the settings. The timing of these events was all too suspicious.
   There was a rumour, denied by Kaspersky, that it was creating malware to throw off its competitors. The jury’s still out, but it’s just odd that while Kaspersky is running its Facebook scan, of what I knew to be non-existent malware, that McAfee would be inaccessible. I went to the McAfee website to file this.



Above: While the Kaspersky scan proceeded, McAfee was knocked out and could not be switched on. Coincidence?

   Unlike most people, I have options open to me, so I began to go on to Facebook using several different methods. A VirtualBox containing XP on the same computer was fine, if incredibly slow while Kaspersky was doing its thing. (Think about Windows XP on a 386.) Lubuntu was fine as well, as was Mac OS X. I Tweeted the McAfee community link, and thought it odd that it did not appear in Facebook (I have my Twitter set up to post there). I then tried to paste the link into Facebook manually, whereupon, in Lubuntu and Mac OS, I was told that my computer was now infected with either a virus or malware. Unlike Windows, I had the option of telling them they were in error, and I was able to continue using the machines.
   This really sounds like Facebook and Kaspersky have it in for McAfee and, possibly, rival products, if the scan knocks out your choice of antivirus and anti-malware program, and if the mere mention of mcafee.com inside Facebook results in a warning box saying your computer is infected.


Above: On a Mac, I couldn’t even tell people about the post on mcafee.com. The second I did, Facebook said my computer was infected. The same thing happened on Lubuntu. Facebook accuses you of infection on the mere mention of mcafee.com.

   Eventually, the entire system froze, and while I could still move the mouse about, I couldn’t access the task bar or go to other programs.
   I was forced to do a hard reboot.
   But you’re asking now: was I ever infected? No. It’s Google all over again.
   Peter, the very knowledgeable McAfee support tech who came to my aid many years ago, was present again and put me on to two other programs after this restart. Getsusp analysed my system for malware, and, you guessed it, found nothing. Malware Bytes did the same, and found some PUPs (potentially unwanted programs), all of which I knew about, and I had intentionally installed. They’ve been present for years. In other words, two other malware scanners told me my system was clean. Malware Bytes did, however, restore McAfee as the correct antivirus program, exactly as Peter had predicted.
   He also suggested a system restore, which sadly failed, with Windows giving the reason that an antivirus program was running. Having restored this system once before (after some bad advice from Microsoft), I knew it couldn’t be McAfee. The only difference on this computer: I had had Kaspersky doing its Facebook scan. It appears that Facebook and Kaspersky don’t want you restoring your system.
   I had fixed the newer issues, but the original one remained: I couldn’t get on to Facebook. The Kaspersky scan never finishes, incidentally—you’re stuck on 62, 73 or 98 per cent—and while not having a personal Facebook is no great loss, I have businesses that have presences there.
   I stumbled across a Reddit thread where others had been forced to download antivirus programs by Facebook, and, fortunately, a woman there had found where hers resided. In my case, it was at C:\Users\USERNAME\AppData\Local\Temp\FBScanner_331840299. Deleting this, and all cookies mentioning Facebook and Kaspersky, restored my access.
   What to do if you ever come across this? My advice is to, first, run Malware Bytes, but ensure you run the free version, and do not opt for the trials. Once you’re satisfied your computer is clean, head into your cookies and delete all the Facebook ones, and any from the antivirus provider it recommends. This second Reddit thread may be helpful, too. I don’t know if this will work completely, but anything is preferable to following Facebook’s instructions and wasting your time. I really need to stop following instructions from these big firms—you’d think after all these years, I’d know better.

PS.: I found this video from last July which suggests the malware accusations have nothing to do with your computer set-up:

In addition, I cannot paste any links in Facebook. The situation began deteriorating after I regained access. Initially, I could paste and like a few things, but that facility eventually disappeared. Regardless of platform, I get the same error I did on the Mac yesterday (see screen shot above). Liking things results in the below error, and the wisdom there is to wait it out till Facebook staff get back to work on Monday.

P.PS.: Holly Jahangiri confronted the same issue as I did a few days later. She was smarter than me: she didn’t download the anti-malware malware. Have a read of her post here: other than that one difference, it’s almost play for play what happened to me for four days. She’s also rightly frustrated, as I am, by Facebook’s inaction when it’s legitimately needed.

P.P.PS.: Not only does Kaspersky delete your comment when you ask on its blog how to remove the malware scanner, they also clam up when you ask them on Twitter.

P.P.P.PS.: I’m beginning to hear that deleting cookies will not work (April 26). Facebook seems intent on having you download their suspicious junk. In those cases, people have switched to another browser.

P.P.P.P.PS.: Andrew McPherson was hit with this more recently, with Facebook blocking the cookie-deleting method in some cases, and advises, ‘If you get this, you will need to change your Facebook password to something very long (a phrase will do), delete and clear your browsers cache and history, then delete your browser, then renew your IP address to a different number and then reinstall your browsers.’ If you cannot change your IP address but are using a router, then he suggests refreshing the address on that. Basically, Facebook is making it harder and harder for us to work around their bug. Once again, if you sign on using a different account using the same “infected” computer, there are no problems—which means the finger of blame should remain squarely pointed at Facebook.

P.P.P.P.P.PS.: June 17: for those who might find Andrew’s method too technical, the current wisdom is to wait it out. It does appear to take days, however. Reminds me of the time Facebook stopped working for me for 69 hours in 2014.

P.P.P.P.P.P.PS.: January 28, 2017: David has come up with a great solution in the comments (no. 103). You can fool Facebook into thinking you are using a Mac by changing the user-agent. He suggests a Chrome Extension. I have Modify Headers for Firefox, which might work, too.

P.P.P.P.P.P.P.PS.: May 9: Stephan, on my other thread on this topic (comment no. 66), confirms that David’s solution worked and has posted a few more details, including extensions for Firefox, Safari and Chrome.

Related posts

Filed under: internet, technology, USA—Jack Yan @ 06.10

127 Responses to ‘Facebook forced me to download their anti-malware, and my own antivirus gets knocked out’

  1. Jack Yan says:

    You are right, Ann—I hope you have since been able to access your account.

  2. […] more than customers—its distributors surely will think twice. (I’m also looking at you, Kaspersky. Another firm to avoid.)    4. Advertising your website in large letters and have it not […]

  3. David says:

    I did this I found on the net, took 2 seconds –
    Re: Facebook F-Secure malware scanner

    1. Change your user agent with a browser addon – that way you ‘fool’ facebook you are on a Mac – it will prompt you to confirm with an OK that you do not have viruses, instead of forcing you to download the redundant and un-necesarry extra online scanner.
    2. Facebook will see the fake user agent and instead of offering you to download the windows based online scanner will simply present you with a menu – asking “Did you run antivirus for Mac?”
    And you can press “Yes i did” and it lets you in for good.

    3. Then revert back the user agent to its usual state
    4.[Optional] Change your password and run a rull AV scan with your own AV
    5. [Optional] Run an extra malware scan with malware bytes
    just my 2 cents

    Perfect, sod off Facebook. ME 1 – 0 Facebook. 100% works, you can do it manually or there is a Chrome Extension. I used the extension, turn to Sarfari, Loaded facebook, told them I did the scan, then clicked continue to Facebook. Then turn it back to Chrome, Close Chrome and reopened to check and I am in. Good luck, don’t download that software Facebook ask you to its a scam.

  4. Jack Yan says:

    An excellent idea, David! I use Modify Headers on Firefox, for those using Firefox. I will update the original post so people can see your idea. Thank you!

  5. @docgreen81 says:

    Same thing happened to me tonight in Google Chrome. One minute I’m surfing along reading comments, then I click a notification and *BAM*… Facebook logs me out and tells me that I have malware.

    Now, interesting side note… I’m an IT professional. Identifying and removing malware is one of my primary jobs. I have more than adequate malware protection on my computer, and can assure you that I do not, in fact, have malware on my PC.

    I also got a notification on my phone saying “You’re temporarily restricted from creating open graph actions” for 24 hrs.

    I had previously had issues pasting links into Facebook before this, but I had dismissed it as a problem with Chrome, and was always able to fix it by closing and re-opening the browser.

    Also, I had no problem at all logging into my Facebook account ON THE SAME DAMN COMPUTER using Internet Explorer.

    WTF?!

  6. Jack Yan says:

    It’s great to get a few very learned opinions on this issue this week. Thank you, Docgreen81. As a professional, you’ll know this is Facebook itself playing silly buggers and nothing to do with someone masquerading as Facebook. There are some who theorize that the download is malware (someone inside Facebook enjoys irony). What we do know is that the Facebook malware warning is, for the most part, BS, since you can get in with IE. Word of this forced download is spreading, so I hope Facebook will eventually have to acknowledge that they have been spying on us.

  7. Erika says:

    David, how do I “1. Change your user agent with a browser addon – that way you ‘fool’ facebook you are on a Mac”? I am not very computer savy, please help.

  8. Jack Yan says:

    Hi Erika, I use a browser add-on to change the user-agent, but I’m on Firefox. Is this what you’re using?
       My Firefox one is called Modify Headers and it can be located here. If you are on Firefox, give that a go—if you’re not clear on how it works, I can try to walk you through it.

  9. Anastasia says:

    Thank you so much for this post. I just run into this problem after reinstalling my pc, full clean install with malwarebytes on. Cleaning cookies didnt help but changing agent to Safari did the trick!
    Glad I found your post :)

  10. Jack Yan says:

    My pleasure, Anastasia! I’m happy this post has helped so many.

  11. Their site is full of spam and malware, yet they have the audacity to enforce “real names” policy, and force us to send them scanned PERSONAL IDs? Are they f**king kidding me? If this is the kind of racket Facebook has decided to be involved in, I’d rather not use Facebook anymore. I don’t understand how the law has not got involved. This is in fact “ransomware.”

  12. Jack Yan says:

    The law, and the tech press (whom I have alerted, too, but no one seems to think this is a worthy story). It looks very damning to me, but maybe no one wants to upset rich people these days. There’s a good reason ‘Welcome to Facebook’ can be abbreviated as WTF.
       I had been progressively cutting down on Facebook anyway, and these forced downloads simply sped up my de-Facebooking. I still have the odd work page on there but as to personal updates, I can’t be bothered. Personal sharing was down 25 per cent in 2015, 29 per cent in 2016, so I imagine they’re desperate to get our data by whatever means possible. Hopefully as word spreads about Facebook’s conduct, more and more will actually leave the site, or at least ensure that sharing is so low Facebook might as well be Myspace.

  13. SandraL says:

    Tonight I was on facebook for at least a couple of hours. I read a post, then went to read an article, posted the article – which was about Venezuela giving Trump $500K for his inauguration…which it got from Russia…and then BOOM! I got that message saying my laptop was infected.

    Now, that seems to me that this has something to do with Russia…but, I did NOT download their antivirus because I already have one running on my system.

    What I did do is sign into FB with not just one, but TWO other FB accounts…on the same computer. No problem. Got in just fine. Then tried to sign in on another computer with my main FB account and boom! same message saying my device was infected. So I know it is account specific.

    I ran two antivirus scans on my computer, and nothing came up. Ran malwarebytes and nothing came up.

    Tried deleting cache and cookies, tried signing in with two different browsers on both computers, and same result. I can sign in with two different accounts but not with my main account.

    I am FUMING! Is Facebook in cahoot with a third company? OR has Facebook itself been hacked and thereby, all user accounts? Are we being monitored for what we upload? or what links we post? Or content?

    Because it seems very, very suspicious that as soon as I tried to post this article, which btw, did NOT post, as I can view what I post through my other accounts via “friends”…that suddenly I’m logged out and I get this notice from FB. Very VERY SUSPICIOUS.

  14. Miles says:

    Which Chrome extension should I use? There is no mention of the one to use?

  15. Jack Yan says:

    Hi Miles: on Firefox, it’s Modify Headers. Because Chrome is Google, I don’t use it, and I suspect David, whose suggestion it was, didn’t subscribe to the comments. I’m sure if you look up header modifications and user agent in wherever Chrome has its add-on library, you’ll find something to suit.

  16. […] have long maintained that Facebook’s databases are dying (hence their need to force people to download malware) and tonight’s discovery is a case of ‘What more proof do you need?’    Tonight, I […]

  17. Cee says:

    Just got that infamous message by facebook

    Let’s Check Your Device for Malicious Software
    Hi Cee, we’re continuously working to keep your account secure. We’ve noticed that this device may be infected with malicious software. To continue to use Facebook, you can either use other devices or clean this device by downloading the scanner provided by Facebook and Trend Micro.

    I tried cleaning the cookies there chrome://settings/cookies

    Nothing

    I tried logging in from explorer browser- same message by facebook.

    Anything I could try ? I am not an expert like you guys.. I have “Windows Defender” and it says it is all ok..

    Thanks for any input!

  18. Jack Yan says:

    Cee, if you scroll up you’ll see a comment by David, who suggests using an extension to modify your headers. There’s a separate comment on this blog (on another thread) which confirms that it works. They are slightly technical but in the second link, Stephan gives step-by-step instructions, and I would highly recommend what he says. I assume you’re using Chrome (because of the chrome://settings/cookies you mention)?

  19. Cee says:

    Thank you Jack Yan.. I read it but must sit with someone who understands the topic I am afraid..
    Apart from that FB ‘s last message was to block my account for 2 days and 22 hours… Wondering what will happen after that time !

  20. Jack Yan says:

    That’s really interesting, Cee. If Facebook has given a time, then it proves once and for all this has nothing to do with malware, and they are lying to you. There’s evidently something wrong with their databases and it’ll take then three days to fix. Others have reported that they were locked out for three days (up to a month in one case). I think in two days and nine hours (given I am replying to you much later), Facebook will just work as though nothing has happened.

  21. Cee says:

    It s really a big joke this FB thing… Wish I did not have to be part of it but my business page is there and until another option is worth it, I will remain there.
    I will report on friday and see if I am back in or not! :)
    Cheers Jack and everyone!

  22. Jack Yan says:

    Thank you, Cee! Like you, if I didn’t have work pages to manage, I’d happily abandon Facebook. I see very little point to it now in 2017.

  23. Suzie says:

    My problem is that I got this message on my employer computer and the last thing I need to do is call the help desk to clean it up. My office manager knows that all of us do this but none of the others have gotten this message. How can I get rid of it from a computer that belongs to the state?

  24. Jack Yan says:

    It might be an idea to contact the help desk because few people seem to believe this is happening. Demonstrate that any other account on your PC is fine, just not yours. Show them this post, and also refer them to my comment above. Hopefully the fix those two users posted still works.

  25. Tina Cosgrove says:

    I got this stupid message this morning using chrome! I refused to download Kaspersky. I did a full scan running my software and cleared my browser history and cache. Still couldnt get into facebook. Switched to firefox and got logged in with no problem!

    BTW i had searched facebook help and found a few people posting about this. I only ever found responses asking for screenshots but never an explanation of why it is happening.

  26. Jack Yan says:

    Great to know you got back in, Tina. Facebook (and Kaspersky, etc.) will never come clean about this—they haven’t to date and I doubt they ever will, probably because whatever they are planting on to our computers is dodgy.

  27. Cee says:

    it seems I forgot to check back with you guys…. sorry about that!
    So yep..the following Friday after that ban of 22hours or so, I was back in as if nothing happened and FB even had the nerve to inform me I had not posted anything those past days…
    Can someone please create something else –worthy– than this FB????

    Cheers everyone!

Leave a reply