<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Antivirus2009</title>
	<atom:link href="http://anti-spyware-101.com/remove-antivirus2009/feed" rel="self" type="application/rss+xml" />
	<link>https://anti-spyware-101.com/remove-antivirus2009</link>
	<description>Spyware detection and removal guides</description>
	<lastBuildDate>Tue, 23 May 2017 10:32:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: shailesh</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-180200</link>
		<dc:creator>shailesh</dc:creator>
		<pubDate>Sun, 02 Aug 2009 16:07:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-180200</guid>
		<description>Antivirus pro installed itself on my computer. It does not allow me to connect to the web ti run antispyware programs or run the programs installed on my hard drive. Cannot locate the files with task manager. It has total contraol of my pC. Where do I start?</description>
		<content:encoded><![CDATA[<p>Antivirus pro installed itself on my computer. It does not allow me to connect to the web ti run antispyware programs or run the programs installed on my hard drive. Cannot locate the files with task manager. It has total contraol of my pC. Where do I start?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mahendradas</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-170406</link>
		<dc:creator>mahendradas</dc:creator>
		<pubDate>Fri, 15 May 2009 18:10:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-170406</guid>
		<description>But we need mobile security also that will be very useful for thousands of customers...</description>
		<content:encoded><![CDATA[<p>But we need mobile security also that will be very useful for thousands of customers...</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gene</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-135647</link>
		<dc:creator>Gene</dc:creator>
		<pubDate>Tue, 24 Feb 2009 14:01:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-135647</guid>
		<description>Wow, what a job to get rid of MSantispyware2009! I got this malware program doing research for a presentation I have coming up. The web site tricked me into loading it by telling me I needed to download a program to watch a video I wanted some information from. I started getting pop ups that looked like official Microsoft data and my explorer tryed to take me to the MS antispyware 2009 website constantly.
The 1st thing I did was find some htm files and some exe files in my hidden temporary internet files that matched some of the names of the popup&#039;s I was getting and delete them, then I went into msconfig and unchecked any suspicious looking items in my start menu, I restarted my cpu and this got rid of about 80% of the popup&#039;s. Next I went into add and remove programs and found 2 programs from crucialsoft and uninstalled them, MSas 2009, and 1stprice?, not sure of the name, but it had a bogus phone number 555-555-1234 under contact info and the url listed for support took me to the antispyware 2009 web site.
Next I downloaded and ran an updated version of my antivirus program and ran it, this got rid of some of the infected files,next I downloaded an upgraded version of my antispyware program and ran it, this got rid of a few more infected files, then I downloaded an antimalware program and ran it, this found about 50 more infected files and deleted them. Now I was down to one popup every 20 minutes or so, an alert message that my computer was still infected and when I hit cancel it tryed to take me to the antispyware 2009 web site. After a call to my IT. friend, he directed me to a website that had a free program called combofix, this program shows you all the programs running on your cpu and deletes some of them but allows you to see and find anything else suspicious and shows you where to find and delete them. I have been popup free since 5:00 PM Yesterday! Found another clever trick this jerk used, In windows Task manager he had 48 tasks scheduled to run abut 15 minutes apart to run a program called C:\WINDOWS\system32\TPuPyhMu.exe.a_a
this is the program that launched the web browser and directed it to his website.
All of the files listed at the top of the page were found and deleted along with the folowing files and folders. This process took me 2 full days to do, if you want to do it youself, I hope these will help. Good Luck!
 Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple)
HKEY_CURRENT_USER\SOFTWARE\CrucialSoft Ltd
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ms antispyware 2009 5.7
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -&gt; Data: c:\windows\system32\userinit.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -&gt; Data: system32\userinit.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -&gt; Bad: (1) Good: (0) 
Folders Infected:
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd 
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\BASE
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\DELETED
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG 
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\SAVED
Files Infected:
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3MZ7GQXG\216[1].jpg
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UM1TIS9N\216[1].jpg
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090222122213003.log
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090222140942078.log
C:\WINDOWS\system32\TPuPyhMu.exe.a_a
MSConfigStartUp-MS AntiSpyware 2009 - c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
MSConfigStartUp-Cognac - c:\docume~1\ADMINI~1\LOCALS~1\Temp\2019.exe</description>
		<content:encoded><![CDATA[<p>Wow, what a job to get rid of MSantispyware2009! I got this malware program doing research for a presentation I have coming up. The web site tricked me into loading it by telling me I needed to download a program to watch a video I wanted some information from. I started getting pop ups that looked like official Microsoft data and my explorer tryed to take me to the MS antispyware 2009 website constantly.<br />
The 1st thing I did was find some htm files and some exe files in my hidden temporary internet files that matched some of the names of the popup's I was getting and delete them, then I went into msconfig and unchecked any suspicious looking items in my start menu, I restarted my cpu and this got rid of about 80% of the popup's. Next I went into add and remove programs and found 2 programs from crucialsoft and uninstalled them, MSas 2009, and 1stprice?, not sure of the name, but it had a bogus phone number 555-555-1234 under contact info and the url listed for support took me to the antispyware 2009 web site.<br />
Next I downloaded and ran an updated version of my antivirus program and ran it, this got rid of some of the infected files,next I downloaded an upgraded version of my antispyware program and ran it, this got rid of a few more infected files, then I downloaded an antimalware program and ran it, this found about 50 more infected files and deleted them. Now I was down to one popup every 20 minutes or so, an alert message that my computer was still infected and when I hit cancel it tryed to take me to the antispyware 2009 web site. After a call to my IT. friend, he directed me to a website that had a free program called combofix, this program shows you all the programs running on your cpu and deletes some of them but allows you to see and find anything else suspicious and shows you where to find and delete them. I have been popup free since 5:00 PM Yesterday! Found another clever trick this jerk used, In windows Task manager he had 48 tasks scheduled to run abut 15 minutes apart to run a program called C:\WINDOWS\system32\TPuPyhMu.exe.a_a<br />
this is the program that launched the web browser and directed it to his website.<br />
All of the files listed at the top of the page were found and deleted along with the folowing files and folders. This process took me 2 full days to do, if you want to do it youself, I hope these will help. Good Luck!<br />
 Registry Keys Infected:<br />
HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple)<br />
HKEY_CURRENT_USER\SOFTWARE\CrucialSoft Ltd<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ms antispyware 2009 5.7<br />
Registry Data Items Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -&gt; Data: c:\windows\system32\userinit.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -&gt; Data: system32\userinit.exe<br />
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -&gt; Bad: (1) Good: (0)<br />
Folders Infected:<br />
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd<br />
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009<br />
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\BASE<br />
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\DELETED<br />
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG<br />
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\SAVED<br />
Files Infected:<br />
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\3MZ7GQXG\216[1].jpg<br />
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UM1TIS9N\216[1].jpg<br />
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090222122213003.log<br />
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090222140942078.log<br />
C:\WINDOWS\system32\TPuPyhMu.exe.a_a<br />
MSConfigStartUp-MS AntiSpyware 2009 - c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe<br />
MSConfigStartUp-Cognac - c:\docume~1\ADMINI~1\LOCALS~1\Temp\2019.exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Janet</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-135525</link>
		<dc:creator>Janet</dc:creator>
		<pubDate>Sun, 22 Feb 2009 02:09:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-135525</guid>
		<description>A friend downloaded Antivirus 360 on my computer.i have many bugs now &amp; im unable to uninstall it/How to get rid of this???I have CyberDenfender ,which is doign fine.Janet</description>
		<content:encoded><![CDATA[<p>A friend downloaded Antivirus 360 on my computer.i have many bugs now &amp; im unable to uninstall it/How to get rid of this???I have CyberDenfender ,which is doign fine.Janet</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: santosh</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-132936</link>
		<dc:creator>santosh</dc:creator>
		<pubDate>Fri, 23 Jan 2009 19:00:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-132936</guid>
		<description>k it seems form my research that the programs modifies the svchost files or some other files that deppends on it
It also changes some or one of the DNS cach files so that trendmicro.com points to the local maching

If i can figure out this DNS file and something to do with the DNS resolver then maybe i can stab it in the neck.

Deleting Temp IE files in hidden Local settings helps free you up</description>
		<content:encoded><![CDATA[<p>k it seems form my research that the programs modifies the svchost files or some other files that deppends on it<br />
It also changes some or one of the DNS cach files so that trendmicro.com points to the local maching</p>
<p>If i can figure out this DNS file and something to do with the DNS resolver then maybe i can stab it in the neck.</p>
<p>Deleting Temp IE files in hidden Local settings helps free you up</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dee</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-35720</link>
		<dc:creator>Dee</dc:creator>
		<pubDate>Wed, 10 Dec 2008 23:50:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-35720</guid>
		<description>ok it seems form my research that the programs modifies the svchost files or some other files that deppends on it
It also changes some or one of the DNS  cach files so that trendmicro.com points to the local maching

If i can figure out this DNS file and something to do with the DNS resolver then maybe i can stab  it in the neck.

Deleting Temp IE files  in hidden Local settings helps free you up</description>
		<content:encoded><![CDATA[<p>ok it seems form my research that the programs modifies the svchost files or some other files that deppends on it<br />
It also changes some or one of the DNS  cach files so that trendmicro.com points to the local maching</p>
<p>If i can figure out this DNS file and something to do with the DNS resolver then maybe i can stab  it in the neck.</p>
<p>Deleting Temp IE files  in hidden Local settings helps free you up</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: james</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-35471</link>
		<dc:creator>james</dc:creator>
		<pubDate>Tue, 02 Dec 2008 18:34:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-35471</guid>
		<description>This antivirus is a bunch of bulllllllllll! I just got my computor and its already infected with it. Someone told me that i would have to wipe my hard drive reinstall windows and use a program called zone alarm does anyone know if this is true. I would like to handle this without wipping my hard drive please let me know.</description>
		<content:encoded><![CDATA[<p>This antivirus is a bunch of bulllllllllll! I just got my computor and its already infected with it. Someone told me that i would have to wipe my hard drive reinstall windows and use a program called zone alarm does anyone know if this is true. I would like to handle this without wipping my hard drive please let me know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-34755</link>
		<dc:creator>.</dc:creator>
		<pubDate>Sat, 08 Nov 2008 21:47:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-34755</guid>
		<description>Thanks PARICIA!....but now when i go into add/remove programs and try to uninstall all it says is &quot;You already have antipro 2009 installed!&quot; yes i know that lol im trying to delete it:@! driving me crazy!</description>
		<content:encoded><![CDATA[<p>Thanks PARICIA!....but now when i go into add/remove programs and try to uninstall all it says is "You already have antipro 2009 installed!" yes i know that lol im trying to delete it:@! driving me crazy!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-34754</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Sat, 08 Nov 2008 20:51:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-34754</guid>
		<description>Bring your computer up in safemode with networking and then you can either remove this manually or use the removal tool. Dave</description>
		<content:encoded><![CDATA[<p>Bring your computer up in safemode with networking and then you can either remove this manually or use the removal tool. Dave</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PC Solutions UK</title>
		<link>https://anti-spyware-101.com/remove-antivirus2009#comment-34735</link>
		<dc:creator>PC Solutions UK</dc:creator>
		<pubDate>Sat, 08 Nov 2008 02:08:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-spyware-101.com/remove-antivirus2009#comment-34735</guid>
		<description>AntiVirus 2009 is proving to be very annoying and law inforcement agencies are dealing with the author of this \&#039;scam\&#039;. If you have this installed on your computer, it s very very hard, if not impossible to remove if you do not know exactly what your doing. The only true way of knowing that this has been fully removed from your system is to do a complete fresh install of Windows.</description>
		<content:encoded><![CDATA[<p>AntiVirus 2009 is proving to be very annoying and law inforcement agencies are dealing with the author of this \'scam\'. If you have this installed on your computer, it s very very hard, if not impossible to remove if you do not know exactly what your doing. The only true way of knowing that this has been fully removed from your system is to do a complete fresh install of Windows.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
