How to Remove Windows Live MSN Messenger common Message Spread and Image Virus

  • log out of Windows Live MSN Messenger.
  • Click "Start" and then select "Run", Type "msconfig" to bring up the System Configuration window.
  • Click on "Startup" tab. Search for the file "xxxsvc.exe," which is the MSN photo virus, or "hotkeysvc.exe" and "MsgSpread" which are also common MSN viruses. Uncheck their boxes to shut them down.
  • Select "OK" to accept the changes.
  • Restart your computer to boot the new configurations and MSN Messenger should now be clean.


To remove PIC1234 msn virus:


  • Close Windows Live MSN Messenger
  • Goto ‘Start> Run’ [type] “msconfig”
  • Click the tab at the top right hand corner of the window that pop up that says “Startup”
  • Uncheck the box next to “MSN Messenger”.
  • Hit Ok, when it asks if you want to restart your computer say “no”.
  • Hit Ctr, Alt, Del find “MsgSpread” and click End Task (if the file is there).
  • Open My Documents
  • Double click “Messenger Service Received Files” if you don't see a folder called that then go to My Computer> C> Program Files> Messenger Service Received Files
  • delete the file called PIC1234(1)(1)(1)(1)(1)(1)(1)(1).exe, - right click it ONCE and select delete.
  • On the desktop right click the “Recycle Bin” and click empty.

Trojan Removal - Trojan.PWS.Onlinegames.KDCI

Trojan Behavior


  • hidden autorun.inf file on the root of your system (usually C:\autorun.inf)
  • creates a hidden executable file on the same folder location as the autorun.inf, pointed in the autorun.inf by an open statement
  • creates a hidden Link Library file and a hidden executable file in your temporary folder (located in your [LocalSettingsFolder], i.e it could be in C:\Documents and Settings\username\Local Settings\Temp)

Trojan Technical Description


it is one of the most spreading online-games password stealer malware "families" out-there.

Upon execution, it creates autorun.inf files pointing to copies of itself, making sure it can survive after a system restart. These files will be located on root of the local drives of an affected system.

It creates another copy of itself into the temporary folder of the current user, where it also drops a new dll file which implements all the functionality required for stealing passwords related to MapleStory, The Lord Of The Rings Online, Knight Online, Dekaron or other games. The newly created copy will be registered for running at the system start-up by a new entry created under HKCU\SoftWare\Microsoft\Windows\CurrentVersion\Run (named cdoosoft, having the path of the file as its value). At this point, the original infected file deletes itself from the disk, removing its traces.

The .dll file from the temp folder will then be written into the memory space of the explorer.exe process and executed. The malicious code injected into explorer.exe is responsable for setting the hooks needed for stealing passwords and also for further propagation by periodical (two times a minute) creation of autorun.inf files (and of the associated executable files) in the root folder of the local partitions.

How to remove Email Spy - Email Spyware Removal

How to Kill processes:


  • Press CTRL+ALT+DEL to open Task Manager.
  • Select processes (escp.exe, vmsdrv.exe, vmsprog.exe) and click on the "End Process" button to kill them.
  • Remove the related files: escp.exe, vmsdrv.exe, vmsprog.exe


How to Delete registry values:


  • Go to Start > Run > type "regedit" and then click OK to open the Registry Editor.
  • Go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VxD
  • Delete entries whose data value is the spyware files detected earlier.
  • Right click on it and select the "Delete" option to delete the value.




then Delete Directory: "C:\Program Files\Email Spy"

How to remove Email Spy - Email Spyware Removal

How to Remove Trojan.Win32.Patched

Trojan.Win32.Patched saves itself in one of the registry keys and start up folders, this trojan may also obstruct with operations of other software.

Trojan.Win32.Patched:


Trojan.Win32.Patched trojan attaches windows components that patched by a malicious application. Some malware patches system components in order to close security service and add its code to a system component and then patch certain functions of the original file to point to an appended code. following are to be revised files:
winlogon.exe
wininet.dll
kernel32.dll
iexplore.exe

System Affected:


Windows95, Windows98, WindowsME, Windows2000, WindowsNT, WindowsXP, Windows2003

How to Remove Trojan.Win32.Patched


use antivirus software to scan infected disk partition, if Trojan.Win32.Patched trojan is detected, check the "Disinfect" action and not to delete it. In this case, anti-virus software will try to restore the infected files.

How to Remove Facebook Virus - Facebook Virus Removal - Protect your Computer from facebook koobface virus

one Facebook Virus, Koobface, is a worm that replicates through social networking sites like Facebook and MySpace. It comes as a message from one of your friends, that contains a link to some video with a tempting message to download it. Examples of facebook virus Messages:
  • You must see it!!! LOL.
  • Paris Hilton Tosses Dwarf On The Street
  • My friend catched you on hidden cam
  • Examiners Caught Downloading Grades From The Internet
  • Is it really celebrity?
  • Funny Moments
  • You look so amazing funny on our new video
  • You've been caught on a hidden camera
  • You just look awesome in this new video
If you click on the link, you will be redirected to a another site that looks like YouTube. You will then get a message that you must update / install a plugin and sometimes it asks you to install an updated Flash player. if you install the plug-in, you will actually installing the Koobface facebook virus.

koobface Facebook virus has the potential to get in your computer and annoy Facebook friends by hijacking your email and spread the virus.
how to remove facebook virus

How to Protect your Computer from Facebook Virus?


Never click on untrusted links, and Don't download plugins or updates from untrusted sites. If you receive a suspicious facebook message, delete it without clicking any links.

How to remove Facebook Virus


You may need to Restart your computer in "Safe Mode".
1. End these processes:
fbtre6.exe
mstre6.exe

2. Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “c:\windows\mstre6.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “C:\Windows\fbtre6.exe”
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating

3. Delete these files:
C:\\Windows\\fbtre6.exe
C:\\Windows\\fmark2.dat
Search for tinyproxy.exe, if found then also delete it.

How to protect your computer from viruses spyware and hackers

below are tips on How to protect your computer from viruses spyware and hackers:

  • Install and Configure Anti-virus Software for Daily Live Updates
  • Update anti virus viruses definitions
  • Install only Trusted Software, Only Install Software from a Reputable Company
  • Keep Your Operating system Updated with Critical Patches (Update Windows)
  • Avoid P2P File Sharing Software
  • Use Strong Passwords
  • Delete Unknown Emails, Check the Source of your E-mail, Delete Spam, and Be Careful with E-mail Attachments
  • Run Virus Scans Regularly
  • Pay Attention and Act on Security Alerts
  • Be careful what you attach to your computer
  • Avoid Shady and Disreputable Web Sites
  • Turn On or Install a Firewall
  • Limit the Use of Administrator Level Accounts
  • Secure Your Wireless Network
  • Lock the screen or logout when away and shutdown the computer when not in use
  • Use a Complex Password for Login

Internet Security Suites Software - top internet security suites

Below is a list of top internet security suites software that will help you protect your computer, detect and remove viruses, spyware and worms.

The list includes a brief review and description for each Internet Security Suite.

Norton Internet Security: fast, light, excellent security, but poor anti-spam and parental controls. criticized for being bloated, slow and sucking up massive amounts of computer memory.

Trend Micro PC-cillin Internet Security: Top marks for ease of installation and use, as well as features. Its protection isn’t stunning, but it will get the job done.

McAfee Internet Security Suite: Easier to use and lighter on system resources than ever, McAfee Internet Security packs in a tonne of features at a reasonable cost.

AVG Internet Security: easy to use and fast but relatively weak anti-spyware, Web protection and anti-phishing. Probably the best known for its free anti-virus and anti-spyware tools, it also produces a suite that combines with a firewall.

BitDefender Internet Security: powerful and configurable firewall solid anti-virus, and cheap, but more technical, weak anti-spyware. Although it is cheaper than all the other suites here, BitDefender Internet Security is more comprehensive than several of the other products.

CA Internet Security Suite Plus: excellent parental controls, Simple interface, good anti-spam, but Questionable performance. CA Internet Security Suite Plus stood out for its remarkably poor performance, its 2008 version test results are a major black mark against it.

F-Secure Internet Security: Does little to shield the user from its complexity, but does have excellent virus and spyware detection rates.

Kaspersky Internet Security: It is still a little technical, and some of the extra features are a little lacking, but Kaspersky provides excellent protection at a reasonable price.

ZoneAlarm Internet Security Suite: Technical users loves it, and even beginners should be able to approach ZoneAlarm with some confidence. It is full of features, and most are very well-implemented.

Elements of Internet Security Suites:


Anti-malware
Anti-phishing
Anti-spam
Anti-spyware
Anti-virus
Backup
Firewall
Parental controls
System cleaning
Web protection
Computers blogs