There is currently in-the-wild a new and dangerous backdoor virus out there targeting users of the Yahoo! Instant Messenger and Skype applications. Backdoor.Tofsee is a very advanced and smart virus that uses social engineering and USB drives in order to spread.
Once installed, instead of just sending random messages to all of your contacts, Backdoor.Tofsee will actually monitor your conversations for times to send a message to your friends instructing them to download an image. Because there is a current conversation going on, your friend may not suspect anything is wrong and immediately download the virus. In addition to spreading via your conversations with your friends, if it detects that a flash drive is inserted into a USB port, it will automatically copy itself to it so when you insert it into another computer, it will be executed and infect their system.
Tofsee also automatically updates itself with new messages periodically in order to keep the messages it sends different so a potential victim will not grow suspect of all of their friends sending the same messages and links. In addition to this automatic update, Tofsee can also detect what language you are using and send the messages in English, Spanish, Italian, Dutch, German, and French making the same virus usable all over the world and you less suspicious when your friend spontaneously starts speaking German for no reason.
Backdoor.Tofsee will also install a rootkit driver that will hide all of its files and activities on your computer. It will also prevent you from obtaining Windows Updates or visiting the website of a long list of AntiVirus software companies. It even tries to prevent you from installing AntiVirus software to remove the infection. Once Tofsee finishes all of this, its ultimate goal is complete. It opens a backdoor and allows full remote access to your computer allowing the person who infected you to use your computer to do anything they wish. From installing more malware to sending SPAM emails to thousands of email addresses.
You can read more about Backdoor.Tofsee at Help Net Security.
