| |

Facebook Photo Virus

Over the last couple of days, a Facebook virus has been going around, cropping up in user’s notifications that someone has, “commented on a photo of you” or “posted a photo of you.” Upon clicking the link, however, you’re taken to a blank 3rd party app page that is automatically installed on your profile.

From what I’ve gathered so far, there are 2 types of links (but could be more). The link includes “beta-dislike” or “photo-comments” in the URL. Simply mousing over the link in the notification will show the URL in the bottom left corner of your browser. If you see either one of those, DON”T CLICK ON IT. Photo links on Facebook are in this format: http://www.facebook.com/photo.php?pid=<ID>&subj=<ID>&id=<ID>. There could also be more info after the ?, but no other slashes in the URL. If you see any other slashes, err on the side of caution.

If You Have Been Duped:

Don’t fret. So far, I haven’t seen any password stealing, profile changing, or other malicious actions. However, I have read that some of the code found in the app may be storing information and sending it to a 3rd party website. This leads me to believe the writer of the app is probably storing the information to sell it to spammers. Here’s how you can fix it.

First, uninstall the application. Go to Applications->Edit Applications in the bottom left  of the chat bar. Make sure “Show: Recently Used” is selected in the drop down box in the top right on the Edit Applications page. Check those apps, look for an app called “Tagged?,” and uninstall it. If you don’t see “Tagged?,” check for other apps that you did not install and get rid of them. Next, it would be worthwhile to change your Facebook password for good measure.

Finally, report the link. In your Notifications, right click the link and copy it from  the notification in question. Go to this page, fill out the form, and submit.  If you have any more information on this little Facebook pandemic, make sure to leave them in the comments! I will post updates here as well (so if you’re reading this on Facebook, you might want to click through to my blog).

54 Comments

  1. OMG !! I have been duped
    what can I do ??????
    I am on Mac ?? are there some risk that it could be infected ??

  2. I have been caught out and now every time I try to access http://www.facebook.com, it tells me I can’t connect to the website. Facebook is the only website it seems to be affecting so far. This means, however, that I can’t get onto the site to uninstall the application…

  3. I fell for this on Saturday or Sunday, it came from my brother, so I thought it was legit. It seemed to be taking a long time to open, so I cancelled it out before I could see anything. I thought nothing of it at the time, until a friend asked me about the crazy picture of a horror flick woman I sent her, which of course I did not. (I didn’t see the pic, but that is how it was described) I followed your directions, but cannot see anything in my apps I can delete,… the only app I have is Living Social. Anyway, maybe it’s unrelated, but now I can only view pics. I cannot make a comment or tag, etc. I cannot see in my settings how to repair this either. Hmmmmm. What to do, oh wise one? 😉

  4. Hi! Thaks for the advice. Immediately realized it was a virus when it automatically started sending things to my friends. The app appears on my list of recently used ones, but won’t let me delete it. I press the ‘x’ and nothing happens. Any pointers?

  5. @Les: Try viewing all Authorized App (in the dropdown Show: Authorized) and deleting anything you no longer use or looks suspicious. As for the comments thing, it could be a security setting on their end. Were you able to comment before?

    @hege: Try refreshing the page- the request could just be getting hung up.

  6. Yeah, it tried to get me this morning. Hopefully it doesn’t, I won’t click it. Thanks so much for posting.

  7. I found it in my apps settings called Unnamed app. I just deleted it. When i clicked on it originally, it did take a long time to come up. When it did, a pic of a horrorful looking clown came up and was inverting colors back and forth. It didn’t seem like anything was different, so I’m guessing it was just something lame.

  8. thanks joe ! I I followed your directions and that seems to be ok 🙂
    but is there any possibility that my software ( OS X ) has been infected or is it only limited to my facebook account ?

  9. The application was named photo in my account. I deleted it, the facebook application called photo is the one you cant delete, so the other was obvious fake and I changed my pw immediately and reported it to fb. Still I am having a lot of trouble with fb in the last days so I dont know whether it is because of the virus or just normal fb chaos…

  10. I received a notification that a friend had posted something on my wall. When I clicked on it a screen came up with a horrific looking clown that was flashing. After closing out of it, this was sent to many of my friends. What is this and what should I do? I changed my password immediately, but am afraid that I have a virus of some sort. When I went into the Applications settings, under added profile tabs, there was an unnamed app. I deleted this app. Is there anything else that I should do? Please help!

  11. I received notification last night from a firned that it posted to my wall, a big colorful clown face… ugly thing… then it went to my friends pages as photos sent… I followed the instructions above and hopefully fixed it. My password will be changed immediately!

  12. Luckily, I’ve not been duped, but I’ve been searching for news blurbs to link to so that I can warn my FB friends not to beware. Sadly, nothing is out there. Thanks for the write up and advice.

  13. I was affected by the same virus just a short while ago. Was completely panicking so thank you Joe for your advice and assistance.

    It came up in my notifications section, saying a friend had tagged a photo of me. The first time, it told me to allow an application called ‘Feed’ to see the photo and I was suspicious so I didn’t. But then another notification came up and this time I was distracted doing something else and clicked through to allow the application and immediately this picture of a horrific flashing clown and had text that said something about a zoo.

    I immediately clicked away and was about to cuss the friend because I thought they were playing the fool when I saw a ton more notifications of the same type coming through from random people.

    And then my fiance told me that he saw a notification from me on his wall saying I commented on a photo so I knew it had infiltrated my account.

    I followed your instructions and I was able to delete the application. I also blocked it from sending notifications to me and reported the feed’s notifications as spam. I also sent a report to FB with the details.

    Still feeling a bit shaky though… hate when things like this happen.

  14. yup. same thing. except initially, it wouldn’t load facebook anymore, now its not loading ANY webpages. internet is completely blown on my laptop even though it shows an active connection. please help- if you know what to do?? i already ran a virus scan and it found nothing. please email me

  15. I’ve apparently had this for a while. Not sure how I got it, b/c the Notifications list only goes back a few days. Sad that there’s no way to block an app if its profile page is malfunctioning, as my “un named app”‘s was.

  16. I had one of my friends “like” my photo and then I went to see that photo and my photo popped up on a blank page. After that everytime i go to my facebook its asking for my password. I go to Facebook from my favorites so it never asks for a password or sign in. It is named “un named app” it was in my recently used and added to profile.

  17. I took screenshots of my apps list before deleting the unnamed app. i then tried to upload the screenshots so friends could see what needed to be deleted and found i could upload them (it said successful) but never asked me to save them …and the album remains empty. seems now i can’t add any more photos to my profile ….sux !!

  18. I fell for the friend posting a comment on a photo of you thing, saw the scary woman face, reported it, and deleted it. It did send it to my friends, and now I have a Spyware virus on my computer that I have been trying for days to get rid of. This is such a pain! My computer is sooo slow, has tons of pop-ups, and keeps telling me its infected every 5 minutes. Ugh.. I can’t seem to find where the spyware is on the computer to delete it and neither can my antivirus protection. Everyone please post on your facebook to warn your friends not to open this virus! Please spread the word!

  19. To Danielle C., the EXACT same thing has been happening to me, though stopped today…FB wouldn’t open, other Internet sites wouldn’t open, even with an active connection? Another thing that’s been happening is that I’ll click on something in FB and my whole screen will go black for a minute then come back, or when on Google, the whole screen will go white…all I can say is to try re-booting a few times, and clicking the thing on Windows that asks if you want to diagnose the problem and let that run awhile…seems to help…otherwise, if it still happens, maybe get a tech person to check it out…I might still have to.

  20. I use (isn’t illegal advertising) AVAST ANTIVIRUS Free edition and I have never had problems, however the place in my homepege <, bye. 🙂

  21. wait…someone said it may show up as photos in the applications page? I def have that, but I’m not sure whether to delete it….I can’t find anything else suspicious, but i thought the photos app had always been there….anyone?

  22. I found 2 that could’ve been poosibilities…one said “un named app” and I was still having problems, then I found 2 apps in my drop down list named ” Comments” and I removed them both since they weren’t FB apps which you cannot delete, hopefully this will take it out.

  23. To be on the safe side..delete all unused apps and ones you rnt sure of ..if need be..u can always install the ones you need again to be safe.
    The virus/script has been found under several names including imitating names of apps already in use.

  24. If it’s called “photos” or some other thing that looks and sounds like your normal facebook default apps like feed, photos, comments, etc; Check if you can delete it, if you can then its fake. You can’t delete the real default apps.

  25. thank you for the heads up !! its been doing my head in to be hornest , again thanks i shall also let others now bout this and wot it may be ?

  26. also go into the drop down menu and select added to profile… i found the unnamed app there ……click on the X Then close facebook to remove

  27. ok so i got this app, it sent me something yesterday saying a couple of my friends commented on a photo of me so i clicked to see what photo and what they said… nothing came up but this blank page and then this horrible pic of a clown, but i couldnt navigate away from the page, so im sooo glad i read this so i can hopefully take action against it.

  28. I did what you said but I still cant access my own profile. There was no “tagged’ app in any of my applicaitons lists. Any other ideas?

  29. I got done by this,i reveived a notification saying my friend commented on a photo of me so i clicked on it, to open it to see which pic it was and got an app called “comments” so i allowed it and then my friend told me its a virus. I deleted the the app and changed my password, ran my anti virus (avast) straight away and i also ran malwarebytes anti malware and they both picked it up. these are totally free to download

  30. Miki you may have to restore ur computer back to an earlier date b4 u had problems with it…from the control panel go to maintenance and see if that helps.

  31. It just happened to me! I have changed my password and i am now running a scan, however going through my app settings i cannot find any of the names mentioned above!

  32. It happened to me, byt sadly before I read your blog.
    I was able to block the app at the source by going down to the bottom of the screen and clicking on the link at the bottom that takes you to the info page.

    I did have a notification windo open and found the URL to be different from that which you posted above so I have included it here for further warning usage.: –

    http://apps.facebook.com/phottags/?_fb_fromhash=f8178c97a8b8c398b809bc46b5ad8c93

    hope it of use.

  33. I have gotten this several times but in my total blondeness and computer unsaavy I never knew how to find the link again after I saw it in the notifications. And then got frustrated when I couldn’t figure out which picture they were talking about. Thank you for this info, I DID have it and am now free of it. Passed it along to my computer techie hubby who is trying to find a way to block it. Thanks again.

  34. i am the same. my hubbie not being computer smart clicked the link and now i cant do anything on my facebook. when i click to remove all unused apps it wont load when i go to comment or post it wont let me and i cant view previous comments. i cant see how i can remove this app if i can’t view all authorised app’s because it wont load. this had not happened before the link was clicked by my hubbie. very frustrating!

  35. I had same situation – but have no applications which are not from “my list”. Does it mean that I’m not infected?

  36. I was redirected to a virus website the other day when I was browsing through my friend’s photos! Now, yesterday, when I was browsing through MY OWN photos, the same thing happened AGAIN! And my antivirus at the bottom popped up saying “TROJAN HORSE WAS DETECTED AND BLOCKED” That was scary! lol. I’m trying to decide if I should just stay off FAcebook or what not….. Also, I want to add more friends on it, but I’m afraid it will happen to them too if they click on one of my photos!! I don’t what to do about Facebook!! Any ideas??

  37. Someone has posted a picture on my facebook and i cant see it but my friends can see it. Someone please help me, can i get it off.

  38. Never ceases to amaze me that blackhat parties are on the never ending road to creating havoc for the general computer user. I rarely use Facebook, but I know as a in the field computer tech, many of my clients do. Thanks for posting up this information, I shall find it very useful for adding to my ‘bag of tricks’ for fighting against the ever increasing hacks being used through web 2.0 technologies.

  39. Is Facebook team doing something about this? I had been duped by something like this once and I ended up dis-activating my account! It really just keep in coming. Is the blackhat people brighter than those implementing the securities?

  40. Well, some time ago it was global security alert about Facebook Video Virus (so called Koobface). It gets into your PC when you try to watch certain Facebook video and get an error:

    “You need to update your Adobe Flash”

    or something like this – and you download file like setup.exe. When you install it you are infected.

    The major annoyance of this virus is strange captcha which appears on every shutdown of your PC. PC won’t shut down until you type in symbols.

    Seems Facebook Photo Virus has the same authors.

  41. I cant get on my facebook and i have done what you said to do and it hadnt help so what do i do now !!!!

  42. I’ve been affected by this too. Facebook is the only website it seems to be affecting so far. I ended up de-activating my account! It really just keeps on coming. Are the black hat people brighter than those implementing the securities? P

Leave a Reply

Your email address will not be published. Required fields are marked *