<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jigsaw Boys &#187; virtumonde</title>
	<atom:link href="http://www.jigsawboys.com/tag/virtumonde/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jigsawboys.com</link>
	<description>Security, Network and Computer Tech Tip Database!</description>
	<lastBuildDate>Wed, 17 Aug 2011 22:59:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Howto: Remove Virtumonde</title>
		<link>http://www.jigsawboys.com/2008/08/16/howto-remove-virtumonde/</link>
		<comments>http://www.jigsawboys.com/2008/08/16/howto-remove-virtumonde/#comments</comments>
		<pubDate>Sat, 16 Aug 2008 09:58:05 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Spyware & Virus Removal]]></category>
		<category><![CDATA[virtumonde]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=149</guid>
		<description><![CDATA[If you&#8217;ve managed to attract the known trojan VirtuMonde &#8211; then you&#8217;re in trouble. This nasty trojan is known to act as a rogue antispyware program, showing advertisments and popups on your machine. Not only will it make your machine run slow, but also is known to perform denial of service attacks on websites of [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;ve managed to attract the known trojan VirtuMonde &#8211; then you&#8217;re in trouble. This nasty trojan is known to act as a rogue antispyware program, showing advertisments and popups on your machine. Not only will it make your machine run slow, but also is known to perform denial of service attacks on websites of the attackers choosing.</p>
<h3>Technical Details</h3>
<p>If you&#8217;re receiving popups that advise you to install software to fix &#8220;system deterioration&#8221;, then you most likely have the Virtumonde trojan. Other symptoms include disabling the windows registry editor and hiding the taskbar.</p>
<h3>Removal</h3>
<p>The first step in removing the trojan is to stop it from starting up apon startup.<br />
Delete the following registry keys. (If not possible, launch regedit from safe mode)</p>
<p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\&#8221;WindowsUpd&#8221;<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\&#8221;SysUpd&#8221;</p>
<p>Because this trojan generates randomly named dll files in your windows/system32/ folder &#8211; we cannot suggest an exact guide to removing the virtumonde trojan. Instead you&#8217;ll need to download an up to date Anti-Virus engine in order to scan your entire system, and remove this virtumonde trojan.</p>
<p>Don&#8217;t have a virus scanner? <a href="http://www.kaspersky.com.au/page/35/free-kaspersky-trial.aspx">Try Kaspersky&#8217;s 30 day free trial</a>.</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/08/16/howto-remove-virtumonde/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

