Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 22 May 2013

Skype virus: "this is a very nice photo of you" removal guide

Posted on 11:51 by Unknown
If you received a message from a friend saying: "this is a very nice photo of you" accompanied by a link (see image below) then your friend's computer is infected with malware. And if someone says that you're sending such messages to your friends then I'm afraid your computer is infected as well.

Updated (25/5/2013): It seems that more than a half of infected users are from Latin America. The virus is actually more sophisticated that I thought - it sends geo-targeted messages which is why its speed of propagation is above average. Users from Latin America usually get the same message in Spanish: "esta es una foto muy amable de tu parte". I'm sure users from other countries get the fake messages in their native languages as well, for example "Dies ist ein sehr schönes Foto von dir" in German.


If clicked the link leads to a website which offers web storage space. It's a popular and safe site that is misused by cyber criminals to hide their illegal activity. So, even if the file comes from what you think is a safe site, please scan the file with your antivirus software before opening it. Or even better, upload it to virustotal.com. Besides, you can't really tell the exact file extension from the link. It looks like an image file but it actually isn't. It's a zip file containing a malicious executable program.


The malicious file is detected as BackDoor.IRC.NgrBot.42 (DrWeb), a variant of Win32/Kryptik.BBHQ (ESET-NOD32) and Trojan.FakeMS (Malwarebytes). Most anti-malware programs detect this virus as ransomware. The detection rate on VirusTotal is low. Once installed, it may download different modules, for example password stealing module or a BitCoinMiner. One way or another, it will either steal your passwords or CPU power. Of course, it will keep sending malicious links to you friends, that's the whole point - to infect as many PCs as possible. The virus is launched each time the PC starts from the AppData folder. You can find the file and remove it manually, however, to completely remove this is a very nice photo of you" Skype virus, you will have to install an anti-malware software. It's a harmful infection that is spreading malware and spyware modules, needles to say they have to be removed from the system as well. Social engineering works really well in this case. Very often, such Skype spam virus links receive thousands of clicks per hour. Remember to always keep your antivirus software updates, otherwise it's useless, as new infections appear each day. Good luck and be safe online!

Written by Michael Kaur, http://deletemalware.blogspot.com



Removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





2. Download and run TDSSKiller. Press the button Start scan for the utility to start scanning.



3. Wait for the scan and disinfection process to be over. Then click Continue. Please reboot your computer after the disinfection is over.




Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Trojans | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • Facebook Security and Privacy Best Practices
    Facebook is the most popular social networking site. Nearly all of my friends have Facebook accounts. They log on to Facebook at least a cou...
  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Smartphone Security: Using Your Mobile Phone Safely
    Smartphone is like a little copy of your computer with lots of personal information: photos, text messages, access to e-mail account and oth...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Antispyis.com and other Antivirus Scan related domains
    New additions of misleading websites which promote a rogue security application called Antivirus Scan. antispyis.com afantispy.net softwaree...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Antivired.com and other Antivirus Monitor Related Domains
    Just a short note about several malicious domains related to the Antivirus Monitor fraud. This rogue anti-virus program reports non-existent...
  • WebCake Adware Removal Guide
    If you’re reading this it is very likely that your computer is infected with WebCake adware which displays extremely obnoxious and intrusiv...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ▼  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ▼  May (25)
      • Protecting Against Rootkits with RKhunter (Rootkit...
      • System Doctor 2014 Virus Removal Guide
      • Remove oyodomo.com pop ups and redirects (Uninstal...
      • Remove The United States Courts Virus (Uninstall G...
      • Remove "Internet Security 2014" Malware (Uninstall...
      • What is BCHelper.exe and how to remove it?
      • File "contained a virus and was deleted" removal, ...
      • Remove kaq.pagerte.net pop-up ads, removal instruc...
      • What is DefaultTabSearch.exe and how to remove it?
      • Skype virus: "this is a very nice photo of you" re...
      • BrowserProtect.exe: What you need to know, how to ...
      • Remove dnsbasic.com (Uninstall Guide)
      • What is cltmng.exe and how to remove it?
      • Remove Trojan.Zeroaccess!inf4 (Uninstall Guide)
      • What is ibsvc.exe and how to remove it?
      • RCMP Ukash virus, help on how to remove
      • Remove "You shall not pass" virus (Uninstall Guide)
      • SnapDo.exe - Process Information
      • Remove ad.xtendmedia pop-up "virus", removal instr...
      • Remove VisualBee, removal instructions
      • Remove Mysearchdial, removal instructions
      • YontooDesktop.exe - Application Error - What is it?
      • How to remove Chatzum, removal instructions
      • Remove Tuvaro, removal instructions
      • Remove Win32:Malware-gen, removal instructions
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile