<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jigsaw Boys &#187; Rogue AntiVirus Removal</title>
	<atom:link href="http://www.jigsawboys.com/category/network-security/rogue-antivirus-removal/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jigsawboys.com</link>
	<description>Security, Network and Computer Tech Tip Database!</description>
	<lastBuildDate>Wed, 17 Aug 2011 22:59:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>How To: Remove Virus Trigger 2009</title>
		<link>http://www.jigsawboys.com/2008/11/13/remove-virus-trigger-2009/</link>
		<comments>http://www.jigsawboys.com/2008/11/13/remove-virus-trigger-2009/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 04:19:36 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Rogue AntiVirus Removal]]></category>
		<category><![CDATA[spyware doctor]]></category>
		<category><![CDATA[spyware removal]]></category>
		<category><![CDATA[virus removal]]></category>
		<category><![CDATA[virus trigger 2009]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=215</guid>
		<description><![CDATA[Yet another rogue spyware program on the loose, this time named "Virus Trigger 2009". One thing I noticed about this program, is that the website looks quite professional and appears in the number 1 spot in google when you search for keyword "Virus Trigger 2009". Nasty huh. READ more to find out how to removal this malicious program.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>Yet another rogue spyware program on the loose, this time named &#8220;Virus Trigger 2009&#8243;.</p>
<p>One thing I noticed about this program, is that the website looks quite professional and appears in the number 1 spot in google when you search for keyword &#8220;Virus Trigger 2009&#8243;. Nasty huh.</p>
<p>Time to check this baby out.</p>
<p>After firing up my dummy box, I proceeded to download Virus Trigger 2009.</p>
<h3>Screenshots</h3>
<p><a href="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/virus-trigger-2009-1.jpg"><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/virus-trigger-2009-1-300x225.jpg" alt="" title="virus-trigger-2009-1" width="300" height="225" class="alignnone size-medium wp-image-216" /></a></p>
<p><a href="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/virus-trigger-2009-2.jpg"><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/virus-trigger-2009-2-300x224.jpg" alt="" title="virus-trigger-2009-2" width="300" height="224" class="alignnone size-medium wp-image-217" /></a></p>
<p>Like most Rogue Spyware applications, its hard to actually minimize or close the Virus Trigger window, especially when it prompts you to purchase the application.</p>
<h3>Manual Removal of Virus Trigger 2009</h3>
<div style="padding: 4px 4px 4px 4px; border: solid 1px #BFBFBF;background-color: #F7F7F7;">
<strong>Virus Trigger 2009 installs itself into the following folder.</strong><br />
c:\program files\VirusTriggerBin <- Delete this folder</p>
<p><strong>Virus Trigger 2009 runs as the following processes</strong><br />
VirusTriggerBin.exe and uninst.exe <- Use the taskmanager to kill these processes</p>
<p><strong>Removing from Startup</strong><br />
To remove this program from starting up when your computer starts, following these instructions</p>
<p>1) Click the start menu, then run<br />
2) Type “msconfig” and hit enter<br />
3) Click the startup Tab<br />
4) Untick “VirusTriggerBin”<br />
5) Reboot
</p></div>
<h3>The Solution</h3>
<p>Whilst you can manually remove &#8220;Virus Trigger 2009&#8243; by simply deleting registry keys and files as per the manual removal stage featured above, its much easier to remove &#8220;Virus Trigger 2009&#8243; simply by using PCTools Spyware Doctor..</p>
<p>%productBox%</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/11/13/remove-virus-trigger-2009/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How To: Remove Ultra Antivirus 2009</title>
		<link>http://www.jigsawboys.com/2008/11/11/how-to-remove-ultra-antivirus-2009/</link>
		<comments>http://www.jigsawboys.com/2008/11/11/how-to-remove-ultra-antivirus-2009/#comments</comments>
		<pubDate>Tue, 11 Nov 2008 11:59:13 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Rogue AntiVirus Removal]]></category>
		<category><![CDATA[internet security]]></category>
		<category><![CDATA[pctools]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Ultra Antivirus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=200</guid>
		<description><![CDATA[Yet another nasty rogue anti-spyware program is amongst us, this time named "Ultra Antivirus 2009". I managed to get this baby loaded on my test machine and boy did I let her rip! Read this post to learn how to remove this bad boy.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>Yet another nasty rogue anti-spyware program is amongst us, this time named &#8220;Ultra Antivirus 2009&#8243;. I managed to get this baby loaded on my test machine and boy did I let her rip!</p>
<p>Ultra Antivirus 2009 pretends to be a &#8220;Anti-Spyware&#8221; program, often tricking users into thinking its a legitimate program. The main goal of Ultra Antivirus 2009 is to trick users into purchasing the software, often by providing fake scan results and informing the user that the software detected threats on the computer. </p>
<p>But alas that is not true, and when reality kicks in; your computer is in fact fine. Ultra Antivirus 2009&#8242;s main goal is to get you to <strong>Purchase Their Product</strong>! </p>
<p><strong>For gods sake DON&#8217;T DO IT!</strong></p>
<h3>Screenshots</h3>
<p><a href="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/ultra-antivirus-2009-1.jpg"><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/ultra-antivirus-2009-1-300x225.jpg" alt="" title="ultra-antivirus-2009-1" width="300" height="225" class="alignnone size-medium wp-image-201" /></a></p>
<p><a href="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/ultra-antivirus-2009-2.jpg"><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/ultra-antivirus-2009-2-300x222.jpg" alt="" title="ultra-antivirus-2009-2" width="300" height="222" class="alignnone size-medium wp-image-203" /></a></p>
<h3>Analysis Stage</h3>
<p>Ultra Antivirus 2009 installs itself into the following folder.<br />
<code>c:\program files\UltraAv <- Delete this folder!</code></p>
<p>Through some analysis, I uncovered that Ultra Antivirus 2009 connects to the following server in order to retrieve new information regarding payment details.<br />
<code>Internet Protocol, Src: 91.208.0.223 (91.208.0.223)</code><br />
Not Good ..</p>
<p><strong>Removing from Startup</strong><br />
To remove this program from starting up when your computer starts, following these instructions</p>
<p>1) Click the start menu, then run<br />
2) Type "msconfig" and hit enter<br />
3) Click the startup Tab<br />
4) Untick "UltraAV"<br />
5) Reboot</p>
<h3>The Solution</h3>
<p>Whilst you can manually remove Spyware protector by simply deleting registry keys and files as per the Analysis stage featured above, its much easier to remove Ultra Antivirus 2009 simply by using PCTools Spyware Doctor.</p>
<p>%productBox%</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/11/11/how-to-remove-ultra-antivirus-2009/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How To: Remove MS Antivirus 2008</title>
		<link>http://www.jigsawboys.com/2008/08/31/how-to-remove-ms-antivirus-2008/</link>
		<comments>http://www.jigsawboys.com/2008/08/31/how-to-remove-ms-antivirus-2008/#comments</comments>
		<pubDate>Sun, 31 Aug 2008 10:09:51 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Rogue AntiVirus Removal]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=155</guid>
		<description><![CDATA[The latest edition in rogue antispyware programs, MS AntiVirus - looks and feels like a regular antispyware application, but in fact - deadly as hell.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>The latest edition in rogue antispyware programs, MS AntiVirus &#8211; looks and feels like a regular antispyware application, but in fact &#8211; deadly as hell.</p>
<p>For those that don&#8217;t know, a &#8220;Rogue Anti-Spyware&#8221; program is a fairly new form of threat that entices users to download a program to protect their PC, but in fact the software they download is a form of malware, designed to entice users to <strong><em>pay</em></strong> for the software, in order to remove it. The main goal of Rogue Anti-Spyware programs is to make money, infecting and performing unwanted actions on your PC is just a measure in order to get you to &#8220;pay up&#8221;.</p>
<p>I wanted to see this MS AntiVirus 2008 program in action, so I fired up my Windows XP test box and gave it a whirl.</p>
<h3>First I infected my PC with the MS AntiVirus program</h3>
<p>See how MS AntiVirus 2008 looks and behaves like an AntiSpyware program, designed to trick the user that it is a legitimate program.</p>
<p><a href='http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-1.jpg'><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-1-300x223.jpg" alt="" title="ms-antivirus-howto-remove-1" width="300" height="223" class="alignnone size-medium wp-image-157" /></a></p>
<h3>Fake infection</h3>
<p>The below screenshot shows MS AntiVirus 2008 telling me that my system is infected. Rogue AntiSpyware often uses &#8220;fake spyware results&#8221; to inject fear into the user, so they feel the need to buy the software to remove the &#8220;fake results&#8221;.</p>
<p><a href='http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-2.jpg'><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-2-300x221.jpg" alt="" title="ms-antivirus-howto-remove-2" width="300" height="221" class="alignnone size-medium wp-image-158" /></a></p>
<h3>MS AntiVirus 2008 communicating to a third party</h3>
<p>The below screenshot shows packet sniffing software &#8220;WireShark&#8221;, detecting MS AntiVirus 2008 talking to a third party web service, namely a MACOS web server called &#8220;WebObjects&#8221; &#8211; nasty stuff.</p>
<p><a href='http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-3.jpg'><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-3-300x221.jpg" alt="" title="ms-antivirus-howto-remove-3" width="300" height="221" class="alignnone size-medium wp-image-159" /></a></p>
<p>Okay its time to get rid of this nasty program, time to whip out AdAlert.</p>
<h3>Removing MS AntiVirus XP with AdAlert</h3>
<p>I cracked open AdAlert and performed a full scan; below are the results.</p>
<p><a href='http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/before-adalert-remove-1.jpg'><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/before-adalert-remove-1-300x223.jpg" alt="" title="before-adalert-remove-1" width="300" height="223" class="alignnone size-medium wp-image-160" /></a></p>
<div class="salesBox">
<span class="heading">The result: A clean system</span><br />
<a href="http://www.jigsawboys.com/out.php?id=adalert">AdAlert</a> managed to disinfect my heavily infected system, deleting key registry files, application files and desktop shortcuts &#8211; no traces of MS AntiVirus 2008 are left behind.</p>
<p>If you&#8217;re infected with MS AntiVirus 2008 and are looking for an easy, fast way to remove it &#8211; I suggest you give <a href="http://www.jigsawboys.com/out.php?id=adalert">AdAlert</a> a whirl. <a href="http://www.jigsawboys.com/out.php?id=adalert">You can download AdAlert here</a>.</p>
<p><span class="downloadlink"><a href="http://www.jigsawboys.com/out.php?id=adalert">Download AdAlert for Free now!</a></span>
</div>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/08/31/how-to-remove-ms-antivirus-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To: Remove AntiMalware Guard</title>
		<link>http://www.jigsawboys.com/2008/08/07/howto-remove-antimalware-guard/</link>
		<comments>http://www.jigsawboys.com/2008/08/07/howto-remove-antimalware-guard/#comments</comments>
		<pubDate>Thu, 07 Aug 2008 00:30:02 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Rogue AntiVirus Removal]]></category>
		<category><![CDATA[antispyware]]></category>
		<category><![CDATA[remove malware guard]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=136</guid>
		<description><![CDATA[If you've been unlucky to install AntiMalware Guard, then you might have some difficulty in removing it. AntiMalware Guard poses as a fake anti-spamware program and is designed to show FALSE spyware results. To kill and remove AntiMalware, you are going to do a little digging - so lets get started.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;ve been unlucky to install AntiMalware Guard, then you might have some difficulty in removing it. AntiMalware Guard poses as a fake anti-spamware program and is designed to show FALSE spyware results. To kill and remove AntiMalware, you are going to do a little digging &#8211; so lets get started.</p>
<h2>Kill the process</h2>
<p>First of all, kill the executable which should show in your processes list as </p>
<p>&#8220;AntiMalwareGuard_Free[1].exe&#8221;.</p>
<h2>Remove registry entries</h2>
<p>Next, fire up regedit (Start>run>regedit) and proceed to delete the following keys/folders if they exist.</p>
<p>HKEY_LOCAL_MACHINE/Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AntiMalwareGuard</p>
<p>HKEY_CURRENT_USER/Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AntiMalwareGuard</p>
<h2>Reboot</h2>
<p>Reboot your computer and AntiMalware Guard should be gone!</p>
<p>However I cannot state this enough, you must install and have an up to date AntiVirus and AntiSpyware application to stop threats like this from entering your computer in the first place. I&#8217;ve reviewed popular antispyware products <a href="http://www.jigsawboys.com/2008/08/07/howto-remove-spyware/">AdAlert and NoAdware here</a>.</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/08/07/howto-remove-antimalware-guard/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

