<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jigsaw Boys &#187; virus removal</title>
	<atom:link href="http://www.jigsawboys.com/tag/virus-removal/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jigsawboys.com</link>
	<description>Security, Network and Computer Tech Tip Database!</description>
	<lastBuildDate>Wed, 17 Aug 2011 22:59:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>How To: Remove Virus Trigger 2009</title>
		<link>http://www.jigsawboys.com/2008/11/13/remove-virus-trigger-2009/</link>
		<comments>http://www.jigsawboys.com/2008/11/13/remove-virus-trigger-2009/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 04:19:36 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Rogue AntiVirus Removal]]></category>
		<category><![CDATA[spyware doctor]]></category>
		<category><![CDATA[spyware removal]]></category>
		<category><![CDATA[virus removal]]></category>
		<category><![CDATA[virus trigger 2009]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=215</guid>
		<description><![CDATA[Yet another rogue spyware program on the loose, this time named "Virus Trigger 2009". One thing I noticed about this program, is that the website looks quite professional and appears in the number 1 spot in google when you search for keyword "Virus Trigger 2009". Nasty huh. READ more to find out how to removal this malicious program.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>Yet another rogue spyware program on the loose, this time named &#8220;Virus Trigger 2009&#8243;.</p>
<p>One thing I noticed about this program, is that the website looks quite professional and appears in the number 1 spot in google when you search for keyword &#8220;Virus Trigger 2009&#8243;. Nasty huh.</p>
<p>Time to check this baby out.</p>
<p>After firing up my dummy box, I proceeded to download Virus Trigger 2009.</p>
<h3>Screenshots</h3>
<p><a href="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/virus-trigger-2009-1.jpg"><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/virus-trigger-2009-1-300x225.jpg" alt="" title="virus-trigger-2009-1" width="300" height="225" class="alignnone size-medium wp-image-216" /></a></p>
<p><a href="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/virus-trigger-2009-2.jpg"><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/virus-trigger-2009-2-300x224.jpg" alt="" title="virus-trigger-2009-2" width="300" height="224" class="alignnone size-medium wp-image-217" /></a></p>
<p>Like most Rogue Spyware applications, its hard to actually minimize or close the Virus Trigger window, especially when it prompts you to purchase the application.</p>
<h3>Manual Removal of Virus Trigger 2009</h3>
<div style="padding: 4px 4px 4px 4px; border: solid 1px #BFBFBF;background-color: #F7F7F7;">
<strong>Virus Trigger 2009 installs itself into the following folder.</strong><br />
c:\program files\VirusTriggerBin <- Delete this folder</p>
<p><strong>Virus Trigger 2009 runs as the following processes</strong><br />
VirusTriggerBin.exe and uninst.exe <- Use the taskmanager to kill these processes</p>
<p><strong>Removing from Startup</strong><br />
To remove this program from starting up when your computer starts, following these instructions</p>
<p>1) Click the start menu, then run<br />
2) Type “msconfig” and hit enter<br />
3) Click the startup Tab<br />
4) Untick “VirusTriggerBin”<br />
5) Reboot
</p></div>
<h3>The Solution</h3>
<p>Whilst you can manually remove &#8220;Virus Trigger 2009&#8243; by simply deleting registry keys and files as per the manual removal stage featured above, its much easier to remove &#8220;Virus Trigger 2009&#8243; simply by using PCTools Spyware Doctor..</p>
<p>%productBox%</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/11/13/remove-virus-trigger-2009/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How To: Remove Ultra Antivirus 2009</title>
		<link>http://www.jigsawboys.com/2008/11/11/how-to-remove-ultra-antivirus-2009/</link>
		<comments>http://www.jigsawboys.com/2008/11/11/how-to-remove-ultra-antivirus-2009/#comments</comments>
		<pubDate>Tue, 11 Nov 2008 11:59:13 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Rogue AntiVirus Removal]]></category>
		<category><![CDATA[internet security]]></category>
		<category><![CDATA[pctools]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Ultra Antivirus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=200</guid>
		<description><![CDATA[Yet another nasty rogue anti-spyware program is amongst us, this time named "Ultra Antivirus 2009". I managed to get this baby loaded on my test machine and boy did I let her rip! Read this post to learn how to remove this bad boy.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>Yet another nasty rogue anti-spyware program is amongst us, this time named &#8220;Ultra Antivirus 2009&#8243;. I managed to get this baby loaded on my test machine and boy did I let her rip!</p>
<p>Ultra Antivirus 2009 pretends to be a &#8220;Anti-Spyware&#8221; program, often tricking users into thinking its a legitimate program. The main goal of Ultra Antivirus 2009 is to trick users into purchasing the software, often by providing fake scan results and informing the user that the software detected threats on the computer. </p>
<p>But alas that is not true, and when reality kicks in; your computer is in fact fine. Ultra Antivirus 2009&#8242;s main goal is to get you to <strong>Purchase Their Product</strong>! </p>
<p><strong>For gods sake DON&#8217;T DO IT!</strong></p>
<h3>Screenshots</h3>
<p><a href="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/ultra-antivirus-2009-1.jpg"><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/ultra-antivirus-2009-1-300x225.jpg" alt="" title="ultra-antivirus-2009-1" width="300" height="225" class="alignnone size-medium wp-image-201" /></a></p>
<p><a href="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/ultra-antivirus-2009-2.jpg"><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/11/ultra-antivirus-2009-2-300x222.jpg" alt="" title="ultra-antivirus-2009-2" width="300" height="222" class="alignnone size-medium wp-image-203" /></a></p>
<h3>Analysis Stage</h3>
<p>Ultra Antivirus 2009 installs itself into the following folder.<br />
<code>c:\program files\UltraAv <- Delete this folder!</code></p>
<p>Through some analysis, I uncovered that Ultra Antivirus 2009 connects to the following server in order to retrieve new information regarding payment details.<br />
<code>Internet Protocol, Src: 91.208.0.223 (91.208.0.223)</code><br />
Not Good ..</p>
<p><strong>Removing from Startup</strong><br />
To remove this program from starting up when your computer starts, following these instructions</p>
<p>1) Click the start menu, then run<br />
2) Type "msconfig" and hit enter<br />
3) Click the startup Tab<br />
4) Untick "UltraAV"<br />
5) Reboot</p>
<h3>The Solution</h3>
<p>Whilst you can manually remove Spyware protector by simply deleting registry keys and files as per the Analysis stage featured above, its much easier to remove Ultra Antivirus 2009 simply by using PCTools Spyware Doctor.</p>
<p>%productBox%</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/11/11/how-to-remove-ultra-antivirus-2009/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Remove Win32/Heur Virus</title>
		<link>http://www.jigsawboys.com/2008/11/11/remove-win32heur-virus/</link>
		<comments>http://www.jigsawboys.com/2008/11/11/remove-win32heur-virus/#comments</comments>
		<pubDate>Tue, 11 Nov 2008 02:00:54 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Spyware & Virus Removal]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=198</guid>
		<description><![CDATA[So a friend of mine had a virus called &#8220;Win32/Heur&#8221;. According to research, the Win32 Heur virus spreads via peer to peer programs such as iMesh, WinMX, Ares and torrents. This virus is nasty for a few reasons; It actually records your browsing activities and displays advertisements to you based on your usage. It de-activates [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>So a friend of mine had a virus called &#8220;Win32/Heur&#8221;. According to research, the Win32 Heur virus spreads via peer to peer programs such as iMesh, WinMX, Ares and torrents. This virus is nasty for a few reasons;</p>
<ul>
<li>It actually records your browsing activities and displays advertisements to you based on your usage.</li>
<li>It de-activates your anti-virus and firewall programs</li>
<li>It spreads like crazy!</li>
<h3>How can I fix this?</h3>
<p>To remove the Win32/Heur virus I ended up getting my friend to download <a href="http://www.kqzyfj.com/click-3133939-10539712" target="_top">PCTools Internet Security</a> which completely removed the virus.</p>
<p>Its free to download so give it a try!</p>
<p><a href="http://www.jigsawboys.com/recommends/pctools-internet-security" target="_top"><br />
<img src="http://www.ftjcfx.com/image-3133939-10540129" width="150" height="40" alt="" border="0"/></a></p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/11/11/remove-win32heur-virus/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How To: Remove MS Antivirus 2008</title>
		<link>http://www.jigsawboys.com/2008/08/31/how-to-remove-ms-antivirus-2008/</link>
		<comments>http://www.jigsawboys.com/2008/08/31/how-to-remove-ms-antivirus-2008/#comments</comments>
		<pubDate>Sun, 31 Aug 2008 10:09:51 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Rogue AntiVirus Removal]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=155</guid>
		<description><![CDATA[The latest edition in rogue antispyware programs, MS AntiVirus - looks and feels like a regular antispyware application, but in fact - deadly as hell.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>The latest edition in rogue antispyware programs, MS AntiVirus &#8211; looks and feels like a regular antispyware application, but in fact &#8211; deadly as hell.</p>
<p>For those that don&#8217;t know, a &#8220;Rogue Anti-Spyware&#8221; program is a fairly new form of threat that entices users to download a program to protect their PC, but in fact the software they download is a form of malware, designed to entice users to <strong><em>pay</em></strong> for the software, in order to remove it. The main goal of Rogue Anti-Spyware programs is to make money, infecting and performing unwanted actions on your PC is just a measure in order to get you to &#8220;pay up&#8221;.</p>
<p>I wanted to see this MS AntiVirus 2008 program in action, so I fired up my Windows XP test box and gave it a whirl.</p>
<h3>First I infected my PC with the MS AntiVirus program</h3>
<p>See how MS AntiVirus 2008 looks and behaves like an AntiSpyware program, designed to trick the user that it is a legitimate program.</p>
<p><a href='http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-1.jpg'><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-1-300x223.jpg" alt="" title="ms-antivirus-howto-remove-1" width="300" height="223" class="alignnone size-medium wp-image-157" /></a></p>
<h3>Fake infection</h3>
<p>The below screenshot shows MS AntiVirus 2008 telling me that my system is infected. Rogue AntiSpyware often uses &#8220;fake spyware results&#8221; to inject fear into the user, so they feel the need to buy the software to remove the &#8220;fake results&#8221;.</p>
<p><a href='http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-2.jpg'><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-2-300x221.jpg" alt="" title="ms-antivirus-howto-remove-2" width="300" height="221" class="alignnone size-medium wp-image-158" /></a></p>
<h3>MS AntiVirus 2008 communicating to a third party</h3>
<p>The below screenshot shows packet sniffing software &#8220;WireShark&#8221;, detecting MS AntiVirus 2008 talking to a third party web service, namely a MACOS web server called &#8220;WebObjects&#8221; &#8211; nasty stuff.</p>
<p><a href='http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-3.jpg'><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/ms-antivirus-howto-remove-3-300x221.jpg" alt="" title="ms-antivirus-howto-remove-3" width="300" height="221" class="alignnone size-medium wp-image-159" /></a></p>
<p>Okay its time to get rid of this nasty program, time to whip out AdAlert.</p>
<h3>Removing MS AntiVirus XP with AdAlert</h3>
<p>I cracked open AdAlert and performed a full scan; below are the results.</p>
<p><a href='http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/before-adalert-remove-1.jpg'><img src="http://www.jigsawboys.com/wp-content/themes/mimbo2.2/images//2008/08/before-adalert-remove-1-300x223.jpg" alt="" title="before-adalert-remove-1" width="300" height="223" class="alignnone size-medium wp-image-160" /></a></p>
<div class="salesBox">
<span class="heading">The result: A clean system</span><br />
<a href="http://www.jigsawboys.com/out.php?id=adalert">AdAlert</a> managed to disinfect my heavily infected system, deleting key registry files, application files and desktop shortcuts &#8211; no traces of MS AntiVirus 2008 are left behind.</p>
<p>If you&#8217;re infected with MS AntiVirus 2008 and are looking for an easy, fast way to remove it &#8211; I suggest you give <a href="http://www.jigsawboys.com/out.php?id=adalert">AdAlert</a> a whirl. <a href="http://www.jigsawboys.com/out.php?id=adalert">You can download AdAlert here</a>.</p>
<p><span class="downloadlink"><a href="http://www.jigsawboys.com/out.php?id=adalert">Download AdAlert for Free now!</a></span>
</div>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/08/31/how-to-remove-ms-antivirus-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Howto: Remove Virtumonde</title>
		<link>http://www.jigsawboys.com/2008/08/16/howto-remove-virtumonde/</link>
		<comments>http://www.jigsawboys.com/2008/08/16/howto-remove-virtumonde/#comments</comments>
		<pubDate>Sat, 16 Aug 2008 09:58:05 +0000</pubDate>
		<dc:creator>Jamsi</dc:creator>
				<category><![CDATA[Spyware & Virus Removal]]></category>
		<category><![CDATA[virtumonde]]></category>
		<category><![CDATA[virus removal]]></category>

		<guid isPermaLink="false">http://www.jigsawboys.com/?p=149</guid>
		<description><![CDATA[If you&#8217;ve managed to attract the known trojan VirtuMonde &#8211; then you&#8217;re in trouble. This nasty trojan is known to act as a rogue antispyware program, showing advertisments and popups on your machine. Not only will it make your machine run slow, but also is known to perform denial of service attacks on websites of [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;ve managed to attract the known trojan VirtuMonde &#8211; then you&#8217;re in trouble. This nasty trojan is known to act as a rogue antispyware program, showing advertisments and popups on your machine. Not only will it make your machine run slow, but also is known to perform denial of service attacks on websites of the attackers choosing.</p>
<h3>Technical Details</h3>
<p>If you&#8217;re receiving popups that advise you to install software to fix &#8220;system deterioration&#8221;, then you most likely have the Virtumonde trojan. Other symptoms include disabling the windows registry editor and hiding the taskbar.</p>
<h3>Removal</h3>
<p>The first step in removing the trojan is to stop it from starting up apon startup.<br />
Delete the following registry keys. (If not possible, launch regedit from safe mode)</p>
<p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\&#8221;WindowsUpd&#8221;<br />
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\&#8221;SysUpd&#8221;</p>
<p>Because this trojan generates randomly named dll files in your windows/system32/ folder &#8211; we cannot suggest an exact guide to removing the virtumonde trojan. Instead you&#8217;ll need to download an up to date Anti-Virus engine in order to scan your entire system, and remove this virtumonde trojan.</p>
<p>Don&#8217;t have a virus scanner? <a href="http://www.kaspersky.com.au/page/35/free-kaspersky-trial.aspx">Try Kaspersky&#8217;s 30 day free trial</a>.</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.jigsawboys.com/2008/08/16/howto-remove-virtumonde/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

