Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 22 May 2013

Skype virus: "this is a very nice photo of you" removal guide

Posted on 11:51 by Unknown
If you received a message from a friend saying: "this is a very nice photo of you" accompanied by a link (see image below) then your friend's computer is infected with malware. And if someone says that you're sending such messages to your friends then I'm afraid your computer is infected as well.

Updated (25/5/2013): It seems that more than a half of infected users are from Latin America. The virus is actually more sophisticated that I thought - it sends geo-targeted messages which is why its speed of propagation is above average. Users from Latin America usually get the same message in Spanish: "esta es una foto muy amable de tu parte". I'm sure users from other countries get the fake messages in their native languages as well, for example "Dies ist ein sehr schönes Foto von dir" in German.


If clicked the link leads to a website which offers web storage space. It's a popular and safe site that is misused by cyber criminals to hide their illegal activity. So, even if the file comes from what you think is a safe site, please scan the file with your antivirus software before opening it. Or even better, upload it to virustotal.com. Besides, you can't really tell the exact file extension from the link. It looks like an image file but it actually isn't. It's a zip file containing a malicious executable program.


The malicious file is detected as BackDoor.IRC.NgrBot.42 (DrWeb), a variant of Win32/Kryptik.BBHQ (ESET-NOD32) and Trojan.FakeMS (Malwarebytes). Most anti-malware programs detect this virus as ransomware. The detection rate on VirusTotal is low. Once installed, it may download different modules, for example password stealing module or a BitCoinMiner. One way or another, it will either steal your passwords or CPU power. Of course, it will keep sending malicious links to you friends, that's the whole point - to infect as many PCs as possible. The virus is launched each time the PC starts from the AppData folder. You can find the file and remove it manually, however, to completely remove this is a very nice photo of you" Skype virus, you will have to install an anti-malware software. It's a harmful infection that is spreading malware and spyware modules, needles to say they have to be removed from the system as well. Social engineering works really well in this case. Very often, such Skype spam virus links receive thousands of clicks per hour. Remember to always keep your antivirus software updates, otherwise it's useless, as new infections appear each day. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.




Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Trojans | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • Remove Rattlingsearchsystem.com (Uninstall Guide)
    Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
  • Remove TR/ATRAPS.Gen2, removal instructions
    Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
  • Remove "System Check" (Uninstall Guide)
    System Check is malicious software posing as Windows system utility. Although, it may look like a real thing, it isn't! You are actuall...
  • Remove Windows Attention Utility (Uninstall Guide)
    Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...
  • Remove Chitka pop up ads, removal instructions
    Chitka pop up ads are truly annoying, lots of people have this issue, but the worse part is that these frequent intrusive pop-ups are caused...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ▼  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ▼  May (25)
      • Protecting Against Rootkits with RKhunter (Rootkit...
      • System Doctor 2014 Virus Removal Guide
      • Remove oyodomo.com pop ups and redirects (Uninstal...
      • Remove The United States Courts Virus (Uninstall G...
      • Remove "Internet Security 2014" Malware (Uninstall...
      • What is BCHelper.exe and how to remove it?
      • File "contained a virus and was deleted" removal, ...
      • Remove kaq.pagerte.net pop-up ads, removal instruc...
      • What is DefaultTabSearch.exe and how to remove it?
      • Skype virus: "this is a very nice photo of you" re...
      • BrowserProtect.exe: What you need to know, how to ...
      • Remove dnsbasic.com (Uninstall Guide)
      • What is cltmng.exe and how to remove it?
      • Remove Trojan.Zeroaccess!inf4 (Uninstall Guide)
      • What is ibsvc.exe and how to remove it?
      • RCMP Ukash virus, help on how to remove
      • Remove "You shall not pass" virus (Uninstall Guide)
      • SnapDo.exe - Process Information
      • Remove ad.xtendmedia pop-up "virus", removal instr...
      • Remove VisualBee, removal instructions
      • Remove Mysearchdial, removal instructions
      • YontooDesktop.exe - Application Error - What is it?
      • How to remove Chatzum, removal instructions
      • Remove Tuvaro, removal instructions
      • Remove Win32:Malware-gen, removal instructions
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile