THREAT REMOVAL

Remove RayBan Instagram Scam from Your Device (Tagging Virus)

This article has been created in order to help explain how to remove the Instagram RayBan tag scam from your computer and stop it from auto tagging your friends from your profile.

The previously detected Facebook RayBan scam which we analyzed to happen in Facebook was encountered once more to occur via Instagram as well. The scam is likely caused by malware which enters your computer via more than one methods. The scam aims to take over Facebook and then Instagram accounts only to get victims to visit phishing pages that imitate the original Ray-Ban.com website, but in fact, may be aiming to trick victims into entering their financial data by luring them with discounts on RayBan® sunglasses.

Threat Summary

Name RayBan Instagram Scam
Type Instagram-related malware.
Short Description Takes control of the victim’s Instagram account and causes automatic shares as well as tagging to pictures that advertise RayBan sunglases with discounts.
Symptoms Your profile starts automatically sharing pictures and tagging your friends.
Distribution Method Via spammed web links and via other users that have already been infected.
Detection Tool See If Your System Has Been Affected by malware

Download

Malware Removal Tool

User Experience Join Our Forum to Discuss RayBan Instagram Scam.

RayBan Insta Virus – How Did I Get It

If you have had the chance of already seeing these pictures on some of your friends profiles on via your profile, there is a good chance that an infection campaign of tis virus is taking place. The strongest symptom that your device has been compromised by this malware is that your profile is sharing Ray-Ban images like the following on Instagram:

When the website on the shared picture is checked on online services, like Scamadviser, it is immediately established that the site is a high-risk one that is based in China, meaning that the spamming virus may originate from a place within China.

The main theory which experts believe to be leading users to become infected by this spamming virus is if you have clicked on a URL that is suspicious due to being careless. This may ultimately result in the direct installation of the malware that is related to this virus without you even noticing it. Furthermore, this software may also exist via an app or a browser extension that has obtained permissions to post on your behalf on Instagram and Facebook. Such apps often pretend to be useful, but the permissions which they use are privacy-invasive and they allow those apps to share absolutely any content on your behalf, making you both – the victim and the perpetrator. Keep reading this article to learn more about how this virus acts nefariously on your computer and how to make sure that it is stopped for good.

RayBan Virus on Facebook and Instagram – Complete Analysis

The first indicator of the RayBan Instagram Scam virus that posts RayBan photos appeared in the distant year 2016, where web links started appearing with the RayBan pictures offering sunglasses for sale under the following messages:

“Rayban Sunglasses Sale – Save 90% Payment Currency (USD, GBP, EUR) Latest Styles & Fast Shipping – Buy Now!”

Tbe messages followed a long and custom third-party URLs alongside a picture, which looks like the following:

Then, a year later, in 2017, reports have appeared of the scamming messages to continue to operate. One victim has stated the following to happen on her computer:

Hi, I got a facebook virus that posted photos of Ray Ban sunglasses and tagged a bunch of my friends in them. I’m not sure what caused it but two things happened the day the pictures were posted. The first thing was that I got a notification that somebody accessed my facebook account. I was in school at the time and so I didn’t do anything about it. Second thing was that I got an email that seemed completely legit but when I clicked it, it took me to a suspicious site which I closed immediately.

What is particularly interesting is that the victim also somehow received a spammed e-mail message which also leads to the same suspicious site advertised in the pictures and a custom redirect URL. We believe that the e-mails are extracted from compromised Facebook and Instagram accounts as a result of browser extensions on the web browsers of victims or suspicious apps being installed and now there is one more version – spammed web links on e-mail messages.

As soon as the RayBan Instagram Scam has taken over the control of your computer, it might as well do more than just share third-party web links. It may perform other malicious activities on your computer, such as:

  • Log the keystrokes you type.
  • Install malware on your computer.
  • Self-update in order to remain hidden.
  • Take screenshots on your device.
  • Track the websites you visit and the inforamtion you type in them.

But the main purpose of the RayBan Instagram Scam is to keep spreading those fake web links that lead to the fraudulent RayBan sites. These sites may often resemble the original sites and the scam is continuing to evolve which suggests that the scammers are tracking the original site. Here is how the original site of RayBan (www.ray-ban.com) looked in comparison to the website which we detected to be associated with the scams:

The scam has kept evolving adding newer and newer pictures on Instagram. Here are the ones that we have detected to appear so far:

Be advised that if you see RayBan Instagram Scam virus on your friend’s profile to not open the web links under absolutely any circumstances, since it may lure you to enter your financial information in order to purchase sunglasses. This may result in financial theft of your personal information and may even result in financial loss i.e. you may order a product that will not arrive.

How to Get Rid of RayBan Scam Virus on Instagram (PC and Mobile Removal)

Before actually removing RayBan Instagram Scam, there are several things that you should assume, especially if the malware is posting from your profile and the main one of those is that you have been compromised. This is why we advise you to log in from a clean device that is malware-free and perform the following activities:

1. Restrict Facebook and Instagram additions groups and other types of entities to use your Instagram and Facebook account.
2. Log out all of the previous Facebook and Instagram logins from all of the devices.
3. Change your password and enable two-factor authentication.

As soon as this has happened, you should immediately start removing this RayBan Instagram Scam virus from your PC. The best methods to do so is by following the removal instructions underneath this article. They have been created to help you delete this virus either manually or automatically. If you lack the experience in removing this malware manually from your computer, security experts strongly advise removing it automatically, preferably with the aid of advanced anti-malware software, for which we also have a suggestion underneath. Such a tool will effectively scan your computer for malware and make sure to help you remove the RayBan virus from your computer plus detect other intrusive programs and fully secure your PC against future infections.

If you use Instagram and Facebook on your smartphone only, we strongly recommend that you immediately reset your device back to its factory settings so that you are able to delete all apps and thus delete the malicious RayBan Instagram Scam app that is taking over your Instagram and Facebook permissions to display the RayBan virus messages.

Avatar

Ventsislav Krastev

Ventsislav is a cybersecurity expert at SensorsTechForum since 2015. He has been researching, covering, helping victims with the latest malware infections plus testing and reviewing software and the newest tech developments. Having graduated Marketing as well, Ventsislav also has passion for learning new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management, Network Administration and Computer Administration of System Applications, he found his true calling within the cybersecrurity industry and is a strong believer in the education of every user towards online safety and security.

More Posts - Website

Follow Me:
Twitter


Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer

How to Remove RayBan Instagram Scam from Windows.


Step 1: Boot Your PC In Safe Mode to isolate and remove RayBan Instagram Scam

OFFER

Manual Removal Usually Takes Time and You Risk Damaging Your Files If Not Careful!
We Recommend To Scan Your PC with SpyHunter

Keep in mind, that SpyHunter’s scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware removal tool to remove the malware threats. Read our SpyHunter 5 review. Click on the corresponding links to check SpyHunter's EULA, Privacy Policy and Threat Assessment Criteria

1. Hold Windows key() + R


2. The "Run" Window will appear. In it, type "msconfig" and click OK.


3. Go to the "Boot" tab. There select "Safe Boot" and then click "Apply" and "OK".
Tip: Make sure to reverse those changes by unticking Safe Boot after that, because your system will always boot in Safe Boot from now on.


4. When prompted, click on "Restart" to go into Safe Mode.


5. You can recognise Safe Mode by the words written on the corners of your screen.


Step 2: Uninstall RayBan Instagram Scam and related software from Windows

Here is a method in few easy steps that should be able to uninstall most programs. No matter if you are using Windows 10, 8, 7, Vista or XP, those steps will get the job done. Dragging the program or its folder to the recycle bin can be a very bad decision. If you do that, bits and pieces of the program are left behind, and that can lead to unstable work of your PC, errors with the file type associations and other unpleasant activities. The proper way to get a program off your computer is to Uninstall it. To do that:


1. Hold the Windows Logo Button and "R" on your keyboard. A Pop-up window will appear.


2. In the field type in "appwiz.cpl" and press ENTER.


3. This will open a window with all the programs installed on the PC. Select the program that you want to remove, and press "Uninstall"
Follow the instructions above and you will successfully uninstall most programs.


Step 3: Clean any registries, created by RayBan Instagram Scam on your computer.

The usually targeted registries of Windows machines are the following:

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

You can access them by opening the Windows registry editor and deleting any values, created by RayBan Instagram Scam there. This can happen by following the steps underneath:

1. Open the Run Window again, type "regedit" and click OK.


2. When you open it, you can freely navigate to the Run and RunOnce keys, whose locations are shown above.


3. You can remove the value of the virus by right-clicking on it and removing it.
Tip: To find a virus-created value, you can right-click on it and click "Modify" to see which file it is set to run. If this is the virus file location, remove the value.

IMPORTANT!
Before starting "Step 4", please boot back into Normal mode, in case you are currently in Safe Mode.
This will enable you to install and use SpyHunter 5 successfully.

Step 4: Scan for RayBan Instagram Scam with SpyHunter Anti-Malware Tool

1. Click on the "Download" button to proceed to SpyHunter's download page.


It is recommended to run a scan before purchasing the full version of the software to make sure that the current version of the malware can be detected by SpyHunter. Click on the corresponding links to check SpyHunter's EULA, Privacy Policy and Threat Assessment Criteria.


2. After you have installed SpyHunter, wait for it to update automatically.

SpyHunter5-update-2018


3. After the update process has finished, click on the 'Malware/PC Scan' tab. A new window will appear. Click on 'Start Scan'.

SpyHunter5-Free-Scan-2018


4. After SpyHunter has finished scanning your PC for any files of the associated threat and found them, you can try to get them removed automatically and permanently by clicking on the 'Next' button.

SpyHunter-5-Free-Scan-Next-2018

If any threats have been removed, it is highly recommended to restart your PC.


Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer

Get rid of RayBan Instagram Scam from Mac OS X.


Step 1: Uninstall RayBan Instagram Scam and remove related files and objects

OFFER
Manual Removal Usually Takes Time and You Risk Damaging Your Files If Not Careful!
We Recommend To Scan Your Mac with SpyHunter for Mac
Keep in mind, that SpyHunter for Mac needs to purchased to remove the malware threats. Click on the corresponding links to check SpyHunter’s EULA and Privacy Policy


1. Hit the ⇧+⌘+U keys to open Utilities. Another way is to click on “Go” and then click “Utilities”, like the image below shows:


2. Find Activity Monitor and double-click it:


3. In the Activity Monitor look for any suspicious processes, belonging or related to RayBan Instagram Scam:

Tip: To quit a process completely, choose the “Force Quit” option.


4. Click on the "Go" button again, but this time select Applications. Another way is with the ⇧+⌘+A buttons.


5. In the Applications menu, look for any suspicious app or an app with a name, similar or identical to RayBan Instagram Scam. If you find it, right-click on the app and select “Move to Trash”.


6: Select Accounts, after which click on the Login Items preference. Your Mac will then show you a list of items that start automatically when you log in. Look for any suspicious apps identical or similar to RayBan Instagram Scam. Check the app you want to stop from running automatically and then select on the Minus (“-“) icon to hide it.


7: Remove any left-over files that might be related to this threat manually by following the sub-steps below:

  • Go to Finder.
  • In the search bar type the name of the app that you want to remove.
  • Above the search bar change the two drop down menus to “System Files” and “Are Included” so that you can see all of the files associated with the application you want to remove. Bear in mind that some of the files may not be related to the app so be very careful which files you delete.
  • If all of the files are related, hold the ⌘+A buttons to select them and then drive them to “Trash”.

In case you cannot remove RayBan Instagram Scam via Step 1 above:

In case you cannot find the virus files and objects in your Applications or other places we have shown above, you can manually look for them in the Libraries of your Mac. But before doing this, please read the disclaimer below:

Disclaimer! If you are about to tamper with Library files on Mac, be sure to know the name of the virus file, because if you delete the wrong file, it may cause irreversible damage to your MacOS. Continue on your own responsibility!

1: Click on "Go" and Then "Go to Folder" as shown underneath:

2: Type in "/Library/LauchAgents/" and click Ok:

3: Delete all of the virus files that have similar or the same name as RayBan Instagram Scam. If you believe there is no such file, do not delete anything.

You can repeat the same procedure with the following other Library directories:

→ ~/Library/LaunchAgents
/Library/LaunchDaemons

Tip: ~ is there on purpose, because it leads to more LaunchAgents.


Step 2: Scan for and remove malware from your Mac

When you are facing problems on your Mac as a result of unwanted scripts, programs and malware, the recommended way of eliminating the threat is by using an anti-malware program. Combo Cleaner offers advanced security features along with other modules that will improve your Mac’s security and protect it in the future.



Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer


Remove RayBan Instagram Scam from Google Chrome.


Step 1: Start Google Chrome and open the drop menu


Step 2: Move the cursor over "Tools" and then from the extended menu choose "Extensions"


Step 3: From the opened "Extensions" menu locate the unwanted extension and click on its "Remove" button.


Step 4: After the extension is removed, restart Google Chrome by closing it from the red "X" button at the top right corner and start it again.


Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer


Erase RayBan Instagram Scam from Mozilla Firefox.

Step 1: Start Mozilla Firefox. Open the menu window


Step 2: Select the "Add-ons" icon from the menu.


Step 3: Select the unwanted extension and click "Remove"


Step 4: After the extension is removed, restart Mozilla Firefox by closing it from the red "X" button at the top right corner and start it again.



Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer


Uninstall RayBan Instagram Scam from Microsoft Edge.


Step 1: Start Edge browser.


Step 2: Open the drop menu by clicking on the icon at the top right corner.


Step 3: From the drop menu select "Extensions".


Step 4: Choose the suspected malicious extension you want to remove and then click on the gear icon.


Step 5: Remove the malicious extension by scrolling down and then clicking on Uninstall.



Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer


Remove RayBan Instagram Scam from Safari.


Step 1: Start the Safari app.


Step 2: After hovering your mouse cursor to the top of the screen, click on the Safari text to open its drop down menu.


Step 3: From the menu, click on "Preferences".

stf-safari preferences


Step 4: After that, select the 'Extensions' Tab.

stf-safari-extensions


Step 5: Click once on the extension you want to remove.


Step 6: Click 'Uninstall'.

stf-safari uninstall

A pop-up window will appear asking for confirmation to uninstall the extension. Select 'Uninstall' again, and the RayBan Instagram Scam will be removed.


How to Reset Safari
IMPORTANT: Before resetting Safari make sure you back up all your saved passwords within the browser in case you forget them.

Start Safari and then click on the gear leaver icon.

Click the Reset Safari button and you will reset the browser.


Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer


Eliminate RayBan Instagram Scam from Internet Explorer.


Step 1: Start Internet Explorer.


Step 2: Click on the gear icon labeled 'Tools' to open the drop menu and select 'Manage Add-ons'


Step 3: In the 'Manage Add-ons' window.


Step 4: Select the extension you want to remove and then click 'Disable'. A pop-up window will appear to inform you that you are about to disable the selected extension, and some more add-ons might be disabled as well. Leave all the boxes checked, and click 'Disable'.


Step 5: After the unwanted extension has been removed, restart Internet Explorer by closing it from the red 'X' button located at the top right corner and start it again.


Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Stay tuned
Subscribe for our newsletter regarding the latest cybersecurity and tech-related news.