Showing posts with label delicious. Show all posts
Showing posts with label delicious. Show all posts

Saturday, 12 March 2011

How to remove VideoCodec3_05b - ICQCHK.exe - MSX.DLL [del.icio.us]

Do you have pop-ups or your computer infected with trojan or spyware ? Learn how to ask us for help, click here!

ICQCHK Trojan is installed by VideoCodec3_05b.exe to help you play “funny” movies. Now the Trojan’s web sites are closed.


Related files in the %SysDir% folder (usually c:\ Windows\System32):
kaboom.dll
iewatch.exe
A0003016.exe
VideoCodec3_05b.exe
sysmon.exe
msx.dll
gtrack.dll
ietool[1].exe
ietool[2].exe
ietool[3].exe


Removal Instructions

Download special software:
RegRun Reanimator
Unzip it to any folder on your hard drive.
* RegRun users need to open RegRun Start Control. Save icqchk_kill.rnr to the same folder.

* Script file works if Windows is installed to “C:\Windows”.
* Script file deletes Trojan’s files and registry entries. If not, open icqchk_kill.rnr in the Notepad.exe and replace “c:\Windows” to your path.

Restart your computer to the Safe mode.
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode. Open Reanimator.exe (or RegRun Start Control). Open Reanimator menu, “Execute Reanimator Job”. Choose icqchk_kill.rnr file.Restart your computer again to the Safe mode. Repeat the job execution. Restart to the Normal Windows mode. Open Reanimator and choose “Scan for Viruses” to be sure that it is complete. Visit RegRun Support center if you have any questions.
Open a support ticket and attach your detailed system report made by RegRun.February 1, 2006 on 5:08 am | In Trojan, Tutorials - HowTo | 1 Comment |



RSS feed for comments on this post. TrackBack URI


My Anti Spyware - Free antispyware programs and Spyware Removal Instructions.


Bookmarks this web HOW TO REMOVE COMPUTER VIRUS

Friday, 4 March 2011

How to remove Winhound [del.icio.us]

Do you have pop-ups or your computer infected with trojan or spyware ? Learn how to ask us for help, click here!

Winhound is a anti-spyware/antivirus program that is know to issue fake alerts on your computer in order to manipulate you into buying its full commercial version. If you are infected with this program you may receive virus alerts in your task bar that appear to be from Microsoft Security Center stating that you are infected with spyware and to run its special anti-spyware tool. This tool turns out to be the commercial version of Winhound. These alerts are fake and are a goad to have you buy the commercial version of this software. It will also hijack your desktop to show the following fake message: Warning Spyware Detected on Your System: Install an antivirus or spyware software to clean your computer.


1. print out these instructions before starting, because you will not be able to connect to the internet during most of this fix.
2. Download smitRem.exe and save to your desktop. Double- click it to extract it to it’s own folder on the desktop.
3. Download and Install Ad-aware SE. If you have a previous version of Ad-Aware installed during, the installation of the new version, you will be prompted to uninstall the older version – be sure to uninstall the previous version.
Run Ad-Aware. Click on the world icon at the top right of the Ad-Aware window and let AdAware update the reference list for the adware and malware. Close Ad-Aware.
4. Download and Install Ewido Security Suite. When installing, under “Additional Options” uncheck :
- “Install background guard”
- “Install scan via context menu”
Launch Ewido, there should be an icon on your desktop double-click it. You will need to update Ewido to the latest definition files. On the left hand side of the main screen click update. Then click on Start Update. The update will start and a progress bar will show the updates being installed.


It`s all programs.


Next, please reboot your computer in Safe Mode by doing the following:


1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.


Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Your desktop and icons will disappear and then reappear again — this is normal.
Wait for the tool to complete and Disk Cleanup to finish — this may take a while; please be patient.


Open Ad-aware and do a full scan. Remove all it finds.


Run Ewido: Click on scanner. Click on Complete System Scan and the scan will begin. NOTE: During some scans with ewido it is finding cases of false positives.
- You will need to step through the process of cleaning files one-by-one.
- If ewido detects a file you KNOW to be legitimate, select none as the action.
- DO NOT select “Perform action on all infections”
- If you are unsure of any entry found select none for now.
- When the scan is finished, click the Save report button at the bottom of the screen.


Close Ewido


Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck “Security Info” if present.


Restart your computer in normal mode.


Run the Panda online virus scan.


- Once you are on the Panda site click the Scan your PC button
- A new window will open…click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.


Finally, restart your computer.

December 26, 2005 on 9:38 am | In Malware removal, Rogue Anti Spyware, Tips, Tutorials - HowTo | No Comments |



Bookmarks this web HOW TO REMOVE COMPUTER VIRUS

Thursday, 3 March 2011

Mozilla released Firefox 1.5.0.1 to fix several vulnerabilities [del.icio.us]

MyAntiSpyware needs your support. Please make a link from your site to us.
Use the button: My Anti Spyware
My Anti Spyware - Free antispyware programs and Spyware Removal Instructions.


Bookmarks this web HOW TO REMOVE COMPUTER VIRUS

Wednesday, 2 March 2011

New rogue anti spyware - AlfaCleaner [del.icio.us]

Do you have pop-ups or your computer infected with trojan or spyware ? Learn how to ask us for help, click here!

Sunbelt and Spyware Warrior reports about new rogue anti spyware AlfaCleaner.
alfa cleaner rogue antispyware
AlfaCleaner is a variant of the Anti Virus Pro, Winhound Spyware Remover, & XSRemover
Downloadable from alfacleaner.com, innovagest2000.com


We recommend to blocking specific domains and IP address:



x-stories.org – 69.50.187.19
zlex.org – 85.255.115.227, 85.255.116.213, 85.255.117.51
Noi.themovie.com that calls the x-stories.org – 69.50.187.19
Cleanchan.net – (formally fullchain.net) -195.255.177.21


If your PC don`t have WMF patch, please patch now. The Alfa Cleaner using wmf exploit for install.


Update: read How to remove AlfaCleaner

February 2, 2006 on 6:51 am | In Rogue Anti Spyware | 3 Comments |



RSS feed for comments on this post. TrackBack URI


My Anti Spyware - Free antispyware programs and Spyware Removal Instructions.


Bookmarks this web HOW TO REMOVE COMPUTER VIRUS

Tuesday, 1 March 2011

Remove Win32/Mywife.E@mm BlackWorm, W32.Blackmal.E@mm, WORM_GREW.A, W32/Nyxem-D, Email-Worm.Win32.VB.bi now [del.icio.us]

Do you have pop-ups or your computer infected with trojan or spyware ? Learn how to ask us for help, click here!

On systems that are infected by Win32/Mywife@E.mm, BlackWorm, W32.Blackmal.E@mm, WORM_GREW.A, W32/Nyxem-D, Email-Worm.Win32.VB.bi, the malware is intended to permanently corrupt a number of common document format files on the third day of every month. February 3, 2006 is the first time this malware is expected to permanently corrupt the content of specific document format files. The malware also modifies or deletes files and registry keys associated with certain computer security-related applications. This prevents these applications from running when Windows starts.


Microsoft wants to make customers aware of the Mywife mass mailing malware variant named Win32/Mywife.E@mm. The mass mailing malware tries to entice users through social engineering efforts into opening an attached file in an e-mail message. If the recipient opens the file, the malware sends itself to all the contacts that are contained in the system’s address book. The malware may also spread over writeable network shares on systems that have blank administrator passwords.


Customers using Windows XP Service Pack 1, Windows XP Service Pack 2, Windows Server 2003, or Windows Server 2003 Service Pack 1 may be at reduced risk from this malware; if the account password is blank, the account is not valid as a network credential. In an environment where you can guarantee physical security, you do not need to use the account across the network, and you are using Windows XP or Windows Server 2003, a blank password is better than a weak password. By default, blank passwords can only be used locally in Windows XP and Windows Server 2003.


Customers who are using the most recent and updated antivirus software could be at a reduced risk of infection from the Win32/Mywife.E@mm malware. Customers should verify this with their antivirus vendor. Antivirus vendors have assigned different names to this malware but the Common Malware Enumeration (CME) group has assigned it ID CME-24.


Customers who believe that they are infected with the Mywife malware, or who are not sure whether they are infected, should contact their antivirus vendor. Alternatively, Windows Live Safety Center Beta Web site provides the ability to choose “Protection Scan” to ensure that systems are free of infection. Additionally, the Windows OneCare Live Beta, which is available for English language systems, provides detection for and protection against the Mywife malware and its known variants.


Also you can try the how to for remove Win32/Mywife.E@mm malware

February 2, 2006 on 8:58 am | In Tips, Virus | No Comments |



Bookmarks this web HOW TO REMOVE COMPUTER VIRUS

Wednesday, 16 February 2011

Wimamp exploit used to push spyware [del.icio.us]

Do you have pop-ups or your computer infected with trojan or spyware ? Learn how to ask us for help, click here!

The Winamp vulnerability in version 5.12 was announced at Secunia just a few days ago, details here. Note the Secunia advisory says “an exploit is publicly available”. Nullsoft released Wimamp 5.13 the same day the exploit was announced, but the spyware pushers saw an opportunity to infect more machines and make more money. SunbeltBLOG posted a Winamp exploit found in the wild today. A malicious Winamp playlist file (.pls) was discovered that causes Winamp to open and subsequently download an ugly CoolWebSearch infection called HomeSearch Assistant, also dubbed Trojan/Startpage.HSA, along with ransomware anti-spyware SpySheriff. The Sunbelt post states the exploit takes place from 008k.com, IP 195.225.177.27 at Netcathosting and recommends network admins and home users to block the site. Netcathosting is one of those ISP’s known to host spyware. Sunbelt also posted a screenshot of the hijacked browser showing domain lookfor.cc (link to dnsstuff.com).

February 6, 2006 on 12:30 am | In Exploits & Vulnerabilities | No Comments |



RSS feed for comments on this post. TrackBack URI



My Anti Spyware - Free antispyware programs and Spyware Removal Instruction


Bookmarks this web HOW TO REMOVE COMPUTER VIRUS