Facebook Virus

Virus:   Bredolab (aka "Facebook virus").

REAL VIRUS

Example:   [Collected via e-mail, October 2009]

ATTENTION ::: CBS JUST REPORTED THAT THERE IS A VIRUS ON FACEBOOK...IT COMES IN THE FORM OF AN EMAIL CLAIMING TO BE FROM FACEBOOK WITH AN ATTACHMENT ASKING TO CHANGE PASSWORD...ONCE PASSWORD IS CHANGED THE COMPUTER HAS A VIRUS IN WHICH ALL PERSONAL INFO CAN BE ACCESSED...THEY SAID THAT IT SHOULD BE DELETED IF ANYONE GETS THE EMAIL...PASS THE WORD ON...

 

Origins:  

The Bredolab virus spreads by sending out phony Facebook password reset messages. The e-mails typically bear a subject line of "Facebook Password Reset Confirmation" and include a message purportedly from "The Facebook Team" warning the reader that his password has been changed for security reasons:


The bogus message informs the user that he can find his new Facebook password in an attached document, but opening that attachment launches an executable file that triggers the download of malware (the Bredolab Trojan) that can allow others to take countrol of the user's computer:
The malicious exe file connects to two servers to download additional malicious files and join the Bredolab botnet, which means the attackers have full control of the PC and can use it to steal personal information and send spam e-mails. One of the servers is in the Netherlands and the other one in Kazakhstan.
Additional information:  
    Facebook Security Facebook Security
(Facebook)
Last updated:   4 November 2009

The URL for this page is http://www.snopes.com/computer/virus/facebook.asp

Urban Legends Reference Pages © 1995-2009 by Barbara and David P. Mikkelson.
This material may not be reproduced without permission.
snopes and the snopes.com logo are registered service marks of snopes.com.