• On TV.com: Dollhouse CANCELED, What Went Wrong?
February 23, 2009 10:25 PM PST

Facebook users targeted by rogue application

by Steven Musil
  • Font size
  • Print
  • 3 comments

A new piece of malware making the rounds on Facebook falsely warns users that their friends have had problems viewing their profiles, posing a potential threat to users' personal information.

The rogue application, dubbed "Error Check System," displays an error message in the notifications section that reads "(Friend's name) has faced some errors when checking your profile View The Errors Message."

But the warnings are fake and a viral attempt to spread the application and recruit more Facebook users, according to Graham Cluley, a senior technology consultant with Sophos. While saying that there is no evidence of personal information theft, Cluley noted in a blog posting that utilizing an error message about the recipient's profile was "sneaky."

"This is an important reminder to all Facebook users that they must exercise caution about which third-party applications they install on their profile, and everyone should remember that Facebook does not approve applications before they are made available on their site," Cluley wrote. "You really are putting your trust in complete strangers when you add that next application to your Facebook profile."

However, non-Facebook members are at risk as well. A Web search of "Error Check System" will yield a link to a site that contains code that will initiate a fake virus scan and try to fool users into installing malware disguised as antivirus software, Cluley wrote in a second blog. Sophos identified the malware as Sus/FakeAV-A and Troj/FakeAV-LL.

"The worry is that in many people's rush to find out more about the suspicious application's behaviour on Facebook they may well run straight into a scareware author's trap," Cluley wrote. However, he noted, "Is it possible that the original Facebook application was actually a red herring, and the real dangerous payload came from people Googling for information?"

Facebook users already infected by the application can uninstall it by using the Edit tab in the Applications section of their Facebook profile.

Steven Musil is the night news editor at CNET News. Before joining CNET News in 2000, Steven spent 10 years at various Bay Area newspapers. E-mail Steven.
advertisement
Click Here
Recent posts from Security
EFF sues feds for info on social-network surveillance
Microsoft: November security updates are fine
Fake CDC vaccine e-mail leads to malware
IBM buys database security firm Guardium
Microsoft actively urges IE 6 users to upgrade
Microsoft investigating 'black screen of death'
Pub fined $13k for Wi-Fi copyright infringement
Tips for safe online shopping
Add a Comment (Log in or register) (3 Comments)
  • prev
  • 1
  • next
by Harrison912 February 24, 2009 11:17 AM PST
I'm typically on FaceBook to socially market my safety and security web site as well as raise awareness for its products through discussion with friends so I'm very interested in any security issues there. Thanks, Steven, for this information.
Reply to this comment
by BenjaminWright February 24, 2009 12:03 PM PST
Facebook carries many security issues. My research documents reports of the Koobface worm infecting (or attempting to infect) workplace-related computers by way of Facebook. Employers/organizations thus have security as a reason to block social network sites. http://computersafety.wordpress.com/2009/01/19/security-threat-facebook-and-myspace-at-work/ --Ben
Reply to this comment
by ThomasWhitney February 25, 2009 10:12 AM PST
Facebook is becoming a very widely used social networking services for businesses (and individuals alike). For it to remain as such as time moves forward will depend on their ability to maintain the integrity of their digital security functions.

My favorite place for up to date information on digital security is http://www.justaskgemalto.com but they haven't mentioned this yet. It must be very recent.
Reply to this comment
(3 Comments)
  • prev
  • 1
  • next
advertisement

Inside the Apple, er, Microsoft Store

Although Redmond's foray into retail bears a big resemblance to Apple's approach, Microsoft has added some distinctive features to draw casual PC buyers and techies alike.

Big marketing budget drives Moto Droid sales

Verizon and Motorola are spending big bucks--$100 million--on marketing the new smartphone, and it looks like it will pay off with 1 million devices sold by year's end.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right