Sync Blog Subscribers

« Activision passes on Ghostbusters, Brutal Legend | Main | Find music by singing or humming »

August 06, 2008

Facebook virus infecting 'Friends' lists

115
Comments

Posted by Marc Saltzman at 2:45 PM | E-mail this post

Facebook

DangerWarning to all Facebook users: a new virus is going around that appears to infect the Facebook users' Friends lists. It sends out an email message with a link that asks you to download a plug-in to view a video. One word: don't.

Already more than a dozen times today I've received this email message, or a variation of it, from Facebook "friends":

Jeff sent you a message.

Subject: Hey friend. "You've been catched on hidden cam, yo."

As with any other email you receive within Facebook, users will get this message in their Facebook email inbox as well as their default email program, such as Outlook or Outlook Express.

Following this messages is a long URL (website address) that, when clicked, takes you to what appears to be a YouTube video. This is not YouTube. When you click the video to begin, a message pops up and says you first need to download a newer Flash player to play the video. Do not do this. It's a virus.

Symantec's Norton Antivirus software has flagged this as a "high risk" Infostealer.Gampass virus. More info on this particular Trojan vius is here. (Note: Symantec warns the risk level is "low," since it originated in 2006, but this new Facebook email is a new iteration of the same virus.)

You might be inclined to click on this link because it's from a friend, but they did not intentionally send it to you -- and yes, their Facebook photo is attached, too.

Here's what it looks like in Facebook:

Virus_msg_facebook_2

and here's what you see if you follow the link to the fake YouTube site:

Virus_video_2

And the dialog box instructing you to download the malicious code:

Virus_download

Pass this onto your Facebook friends so they do not download and open this "codecsetup.exe" file.

What to do if you downloaded the virus?

Unfortunately, there's no quick fix if you run this virus, says Marc Fossi, manager of system development, at  Symantec's security response team:

"The Trojan is not new -- it’s only the attack mechanism that is. Clicking the link won’t infect anyone. The threat is only installed if the user downloads and executes the “codecsetup.exe” file he refers to. Since Gampass can also download and install other threats onto the computer there is not a single disinfection procedure available. The user should download the latest virus definition files and run a full scan of their computer.  Always keep antivirus definition files up to date is the only thing that will warn the users ahead of time. This doesn’t exploit a vulnerability so there isn’t a patch available. But the full system scan should disinfect Gampass and any other threats it downloads and installs."

If you enjoyed this post, why not subscribe to this blog via RSS? It's easy and you'll never miss another sync article.

Technorati Tags: , , , , , , ,

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d834cd346e69e200e553ee27e58834

Listed below are links to weblogs that reference this blog post:

» Another Facebook virus making the rounds from Abandoned Stuff by Saskboy
There is a very good reason to be wary of emails that come from Facebook, especially the ones that ask you to add an application. In fact, its poor email use to log into a website after clicking a link inside an email (which is exactly what Face... [Read More]

Show Comments (115) « Why are comments hidden by default?

Feed You can follow this conversation by subscribing to the comment feed for this post.

Post a comment

If you have a TypeKey or TypePad account, please Sign In

iconSubscribe to Sync
via email


Enter your email address:

You will receive a daily email from Sync with the latest stories and you can unsubscribe anytime.
We don't sell email lists.

Advertisement

Recent Comments

About