Facebook and rootkits???

The machines we love to hate

Moderator: Wiz Feinberg

User avatar
Richard Sinkler
Posts: 17824
Joined: 15 Aug 1998 12:01 am
Location: aka: Rusty Strings -- Missoula, Montana
State/Province: Montana
Country: United States

Facebook and rootkits???

Post by Richard Sinkler »

Today I had a friend try out a Facebook/ReverbNation page to test it out (our band is trying to set one up). I wanted to see how someone who is not a Facebook member accesses and sees the page. He first accessed FB by typing in www.facebook.com but only had an option to join, so he did nothing. Then I had him click on the url to our page. He viewed the page, but did nothing else.

After that, he ran a scan on his computer with PC Tools Spyware Doctor, which he uses twice a day. From his email to me:
On my next scheduled PC Doctor scan after visiting Facebook, I had 11 files infected with Rootkit CL.
He also uses MalwareBytes and Norton Anti-virus, and they didn't detect these rootkits.

My question is: Since he only opened pages and had no other interaction, like viewing videos, listening to music, or downloading files, is it possible to get rootkits (and I guess viruses etc...) by just viewing a page on the internet?

I have been using FB for a year or so now, and don't think I ever had any problems with rootkits, viruses etc... I use Trend Micro Internet Security Plus and occasionally MalwareBytes.
Carter D10 8p/7k, Dekley S10 3p/4k C6 setup, Regal RD40 Dobro, Recording King Professional Dobro, NV400, NV112, Ibanez Gio guitar, Epiphone SG Special (open G slide and regular G tuning guitar) .

Playing for 55 years and still counting.
User avatar
Wiz Feinberg
Posts: 6114
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
State/Province: Michigan
Country: United States

Post by Wiz Feinberg »

It's hard to say without consulting with him, but this sounds like a serious false positive from Spyware Doctor. Tell him to update the definitions, reboot and scan again. Update MBAM and Norton and scan with them also.

A rootkit typically exists inside one file, not 11. While it is technically possible to get infected by just going to any web page, if it has been poisoned with an iframe redirect to malware servers, it is unlikely that the URL www.facebook.com contains exploits.

But, where did he surf before going to Facebook.com? What browser was he using? If Safari, or Internet Explorer, silent exploits are common. If Firefox or Google Chrome, infections must be manually approved by trickery.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog