<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ducktoes Computer Repair and Spyware Blog &#187; Alerts</title>
	<atom:link href="http://ducktoes.com/blog/index.php/category/alerts/feed/" rel="self" type="application/rss+xml" />
	<link>http://ducktoes.com/blog</link>
	<description>Ms. Ducktoes is on her way!  Saving computers everyday!</description>
	<lastBuildDate>Thu, 26 Jan 2012 15:40:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>&#8220;Click Here to Read this Message&#8221; Hotmail and MSN Virus</title>
		<link>http://ducktoes.com/blog/alerts/click-here-to-read-this-message-hotmail-virus/</link>
		<comments>http://ducktoes.com/blog/alerts/click-here-to-read-this-message-hotmail-virus/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 15:11:22 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Click here to read this message]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1914</guid>
		<description><![CDATA[I&#8217;ve gotten this infected email four times, including one from my sister, and one from my sister-in-law. All four came from Hotmail or MSN accounts so I assume it&#8217;s a Hotmail/MSN virus. The message looks like this or something similiar.  This is the one from my sister: And the one from my sister-in-law was even [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I&#8217;ve gotten this infected email four times, including one from my sister, and one from my sister-in-law. All four came from Hotmail or MSN accounts so I assume it&#8217;s a Hotmail/MSN virus.</p>
<p style="text-align: center;">The message looks like this or something similiar.  This is the one from my sister:<br />
<a href="http://ducktoes.com/blog/wp-content/uploads/2012/01/hotmailvirus.jpg"><img class="size-medium wp-image-1916 aligncenter" title="hotmailvirus" src="http://ducktoes.com/blog/wp-content/uploads/2012/01/hotmailvirus-300x120.jpg" alt="" width="300" height="120" /></a></p>
<p style="text-align: center;">And the one from my sister-in-law was even more sophisticated because it put my name in the message:</p>
<p style="text-align: center;"><a href="http://ducktoes.com/blog/wp-content/uploads/2012/01/trace2.gif"><img class="size-medium wp-image-1924 aligncenter" title="trace2" src="http://ducktoes.com/blog/wp-content/uploads/2012/01/trace2-300x86.gif" alt="" width="300" height="86" /></a></p>
<p>If you click on it you will get the virus too and it will send messages to everyone in your Hotmail or MSN account. What I don&#8217;t know if it infects your computer or if it just infects your account on Microsoft&#8217;s servers. I don&#8217;t want to click and find out, unless I do it on a junk computer.  <span style="text-align: center;">Until I have time to do that, I traced one email back to Spain.</span></p>
<p style="text-align: center;"><a href="http://ducktoes.com/blog/wp-content/uploads/2012/01/trace.jpg"><img class="size-full wp-image-1918 aligncenter" title="trace" src="http://ducktoes.com/blog/wp-content/uploads/2012/01/trace1.bmp" alt="" width="640" height="400" /></a></p>
<p>I sent an email to the address in Spain of the internet provider to warn them, to this address: abuse@orange.es.</p>
<p>The other came from Turkey.</p>
<p>If you&#8217;ve received this email and clicked on it, I recommend that you run <a href="http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html">Malwarebytes</a>.  If that doesn&#8217;t fix it, then call Ducktoes <a href="http://ducktoes.com">Computer Repair</a> and <a href="http://ducktoes.com/business_support.php">Calgary IT support</a> to help you.  We can even fix your computer over the internet remotely, anywhere in the world.</p>
<p><map name='google_ad_map_1914_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1914?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1914_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1914&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fclick-here-to-read-this-message-hotmail-virus%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/click-here-to-read-this-message-hotmail-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you Fall for this Scam? You may be Entitled to a Refund.</title>
		<link>http://ducktoes.com/blog/alerts/did-you-fall-for-this-scam-you-may-be-entitled-to-a-refund/</link>
		<comments>http://ducktoes.com/blog/alerts/did-you-fall-for-this-scam-you-may-be-entitled-to-a-refund/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 15:47:18 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1833</guid>
		<description><![CDATA[&#160; According to the LA Times, victims of the Winfixer, Drive Cleaner and Antivirus XP scam are entitled to a refund.  See here.  http://latimesblogs.latimes.com/money_co/2011/12/scam-watch-computer-virus-warning-ponzi-scheme-fake-bbb-email.html. If you fall for any other anti-virus scams or have a Rogue Anti-virus or Rogue Anti-Spyware, we can help at our Calgary Virus Removal lab.]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>&nbsp;</p>
<p>According to the LA Times, victims of the Winfixer, Drive Cleaner and Antivirus XP scam are entitled to a refund.  See here.  <a href="http://latimesblogs.latimes.com/money_co/2011/12/scam-watch-computer-virus-warning-ponzi-scheme-fake-bbb-email.html">http://latimesblogs.latimes.com/money_co/2011/12/scam-watch-computer-virus-warning-ponzi-scheme-fake-bbb-email.html</a>.</p>
<p>If you fall for any other anti-virus scams or have a Rogue Anti-virus or Rogue Anti-Spyware, we can help at our <a href="http://ducktoes.com">Calgary Virus Removal</a> lab.</p>
<p><map name='google_ad_map_1833_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1833?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1833_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1833&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fdid-you-fall-for-this-scam-you-may-be-entitled-to-a-refund%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/did-you-fall-for-this-scam-you-may-be-entitled-to-a-refund/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>This Phish will Bite your Butt</title>
		<link>http://ducktoes.com/blog/alerts/rogue-antivirus-from-google-ad/</link>
		<comments>http://ducktoes.com/blog/alerts/rogue-antivirus-from-google-ad/#comments</comments>
		<pubDate>Wed, 24 Aug 2011 13:50:46 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[phish website]]></category>
		<category><![CDATA[rogue anti-virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1693</guid>
		<description><![CDATA[Here&#8217;s a youtube video from Sophos that shows how you can get infected from a Google Ad advertising Norton.  Note how on the fake Norton website the colors are yellow like Norton Antivirus or Symantec, but there&#8217;s no real name, only the word &#8220;Anti-virus,&#8221; a clue you&#8217;re not getting the real deal, but a rogue [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Here&#8217;s a youtube video from Sophos that shows how you can get infected from a Google Ad advertising Norton.  Note how on the fake Norton website the colors are yellow like Norton Antivirus or Symantec, but there&#8217;s no real name, only the word &#8220;Anti-virus,&#8221; a clue you&#8217;re not getting the real deal, but a rogue antivirus.  Be aware when going to unfamiliar sites.  In the meantime, I&#8217;ll try to let Google know this is a fraudulent website.  We call that a phish website.  Try not to go phishing, the phish ARE biting, but are biting right in the ol kazoo, meaning where it hurts most: your wallet and computer. </p>
<p>If you did buy the fake Norton from the phish website, it wouldn&#8217;t work, and would infect your computer with more viruses and spyware.</p>
<p><iframe width="560" height="345" src="http://www.youtube.com/embed/oYyx_UoaZ7E" frameborder="0" allowfullscreen></iframe></p>
<p><map name='google_ad_map_1693_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1693?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1693_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1693&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Frogue-antivirus-from-google-ad%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/rogue-antivirus-from-google-ad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>If Microsoft Calls, Hang Up</title>
		<link>http://ducktoes.com/blog/alerts/if-you-get-a-call-from-microsoft-hang-up/</link>
		<comments>http://ducktoes.com/blog/alerts/if-you-get-a-call-from-microsoft-hang-up/#comments</comments>
		<pubDate>Tue, 23 Aug 2011 05:41:50 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1668</guid>
		<description><![CDATA[Many new Ducktoes clients have been victims of a phone scam where a caller from outside of Canada claims to be from Microsoft. The friendly and helpful caller convinces the client their computer is infected with viruses.  He sympathizes  and earns their trust.  And then persuades them to give him access to their computer and [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Many new Ducktoes clients have been victims of a phone scam where a caller from outside of Canada claims to                                                                                                                                                                                                                                                                                    be from Microsoft.  The friendly and helpful caller convinces the client their computer is infected with viruses.  He sympathizes  and earns their trust.  And then persuades them to give him access to their computer and even (yes, even!) payment with their credit card number.  He remotely controls the computer and &#8220;fixes&#8221; it.  After hanging up, the client gets that hair-prickling-the-back-of- your-neck, you been compromised feeling and calls Ducktoes to ask if this was a legitimate repair service by Microsoft.  I don&#8217;t even have time to tut-tut, instead I say, yikes, or the stronger language &#8220;omg,&#8221; hang up immediately and call your bank or credit card company to turn off the credit card!  They are lucky if the purchase price is the only amount withdrawn.  It&#8217;s often too late to get the $200 &#8211; $300 back of the dubious virus removal and computer repair costs, but often prevents even larger amounts from being stolen.</p>
<p>Then at the shop we remove the keyloggers: software that records every keystroke you make, also known as the &#8220;betrayed lover&#8221; software because many people use it to catch a straying partner in an affair by reading their emails and instant chats to other man or woman.  But the fraudsters don&#8217;t care if you&#8217;re stepping out, they&#8217;re out for cold cash, and oodles of it they must be making off Calgarians alone, not to speak of others all over North America.</p>
<p>In Winnipeg the police have issued a warning about the same fraudsters. <a href="http://winnipeg.ctv.ca/servlet/an/local/CTVNews/20110818/wpg_virus_scam_110818/20110818/?hub=WinnipegHome">Here&#8217;s the link to the CTV News story.</a> And <a href="http://www.canada.com/Calls+claiming+computer+problem+scam/5293387/story.html">here&#8217;s another story about the same scam</a>.</p>
<p>Microsoft doesn&#8217;t call people to tell them they have viruses or computer problems. They never do unsolicited computer repair.  So if you get a call telling you this, hang up.  If you&#8217;ve fallen for the scam, bring in your computer to Ducktoes Computer Repair or let us check it out remotely.  You may have a keylogger or other spyware.  Also speak immediately to your bank about the credit card purchase.  You&#8217;ll have to get a new card and number.</p>
<p><map name='google_ad_map_1668_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1668?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1668_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1668&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fif-you-get-a-call-from-microsoft-hang-up%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/if-you-get-a-call-from-microsoft-hang-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Be Careful when Downloading AVG from Google</title>
		<link>http://ducktoes.com/blog/alerts/be-careful-when-downloading-avg-from-google/</link>
		<comments>http://ducktoes.com/blog/alerts/be-careful-when-downloading-avg-from-google/#comments</comments>
		<pubDate>Sun, 13 Dec 2009 14:24:16 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[anti-virus applications]]></category>
		<category><![CDATA[Calgary computer repair]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1388</guid>
		<description><![CDATA[I like AVG&#8230;no bones about it. And I recommend it to my clients because it&#8217;s easy to use and it&#8217;s reliable and now with version 9.0 it&#8217;s also faster again. On the comparative tests at Virus.gr, AVG Free removed 97% of the viruses. I have clients&#8211;with teenage sons&#8212; who used to hire me every six [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I like AVG&#8230;no bones about it.  And I recommend it to my clients because it&#8217;s easy to use and it&#8217;s reliable and now with version 9.0 it&#8217;s also faster again.  On the comparative tests at Virus.gr, AVG Free removed 97% of the viruses.  I have clients&#8211;with teenage sons&#8212; who used to hire me every six months to clean their computers of malware,   I convinced them to try AVG and voila, two years later, and they still haven&#8217;t needed me to clean viruses again.  I know, amazing!!  And so much easier on the budget than computer repair bills.</p>
<p>If a client calls and asks me how to get AVG for their computer, I tell them to search for AVG on Google, but this week a client named Anna accidentally downloaded a virus from Google instead.  Among all the legitimate links for AVG in her Google search results, she managed to click on a link that lead to Antivirus 2010, a rogue anti-virus which I remove several times a week from other clients&#8217; computers.</p>
<p>Here&#8217;s where she clicked:</p>
<div id="attachment_1394" class="wp-caption aligncenter" style="width: 610px"><img class="size-full wp-image-1394" title="badlink" src="http://ducktoes.com/blog/wp-content/uploads/2009/12/badlink2.gif" alt="Don't download this one!" width="600" height="273" /><p class="wp-caption-text">Don&#39;t download this one!</p></div>
<p>All the rest of the links are good.  Look for http://avg.com or http://free.avg.com.  Or you can use the one I use from CNET&#8217;s download.com: <a href="http://download.cnet.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html">http://download.cnet.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html</a> Since it&#8217;s Cnet, you know it&#8217;s safe.  Just scroll down further in the Google search results for AVG.</p>
<p>Be careful out there, it&#8217;s a wild web!!</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1388_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1388?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1388_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1388&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fbe-careful-when-downloading-avg-from-google%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/be-careful-when-downloading-avg-from-google/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Alert:  P2Ps Spreading Dangerous Virus called Virut</title>
		<link>http://ducktoes.com/blog/alerts/virus-alert-p2ps-spreading-virut/</link>
		<comments>http://ducktoes.com/blog/alerts/virus-alert-p2ps-spreading-virut/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 14:55:53 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Peer-to-Peers]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Dangerous virus Virut]]></category>
		<category><![CDATA[Virut]]></category>
		<category><![CDATA[Warning about Virut]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1336</guid>
		<description><![CDATA[The worst virus I&#8217;ve ever seen is now making its way through Bit Torrent and Limewire and other file sharing programs. It&#8217;s called Virut. And once you have it it&#8217;s pretty much game over and time for a clean install. You&#8217;re done. At least you&#8217;re operating system is kaput. So if I were you I&#8217;d [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>The worst virus I&#8217;ve ever seen is now making its way through Bit Torrent and Limewire and other file sharing programs.  It&#8217;s called Virut.  And once you have it it&#8217;s pretty much game over and time for a clean install.  You&#8217;re done.  At least you&#8217;re operating system is kaput.  So if I were you I&#8217;d make sure your anti-virus is working and updating regularly.  And stay away from P2Ps until this settles down.  Lots of people are losing everything on their computers.  What makes Virut so nasty is that it patches itself to every executable, so everything time you run an anti-virus, it &#8220;patches itself&#8221; onto the anti-virus.  Also it changes system files, so if you &#8220;delete&#8221; instead of &#8220;cure&#8221; or &#8220;heal&#8221; them, you&#8217;ll be facing at least a Repair install.  </p>
<p>Some fixes for Virut run in Safe Mode, but on my client&#8217;s computer,  Safe Mode isn&#8217;t working.  I&#8217;m right now trying a method I saw on the Internet that uses <a href="http://www.youtube.com/watch?v=FGDl-IMOt1g">Dr. Web. Cure-it.</a></p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>    </p>
<p><map name='google_ad_map_1336_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1336?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1336_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1336&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fvirus-alert-p2ps-spreading-virut%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/virus-alert-p2ps-spreading-virut/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Downandup or Conficker USB Worm Prevention and Removal</title>
		<link>http://ducktoes.com/blog/alerts/downandup-or-conficker-usb-worm-prevention-and-removal/</link>
		<comments>http://ducktoes.com/blog/alerts/downandup-or-conficker-usb-worm-prevention-and-removal/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 21:05:22 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Conficker worm]]></category>
		<category><![CDATA[Fix Conficker worm]]></category>
		<category><![CDATA[Prevent Conficker worm]]></category>
		<category><![CDATA[remove Conficker worm]]></category>
		<category><![CDATA[stop Autoruns]]></category>
		<category><![CDATA[USB worm]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1058</guid>
		<description><![CDATA[Ms. Ducktoes is really busy removing spyware and replacing power supplies today, but I&#8217;ve noticed an influx of this new worm. So I thought I should warn you. It&#8217;s called the Downandup/Conficker worm. Millions of computers are infected. To avoid getting it, turn off Autoruns on your computer. Click here to learn how to turn [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes is really busy removing spyware and replacing power supplies today,  but I&#8217;ve noticed an influx of this new worm.  So I thought I should warn you. It&#8217;s called the Downandup/Conficker worm. Millions of computers are infected.  To avoid getting it, turn off Autoruns on your computer. <a href="http://ducktoes.com/blog/2009/01/14/how-to-prevent-usb-worm/">Click here to learn how to turn off Autoruns.</a></p>
<p>To fix or remove Downandup or Conficker worm, there are these free removal tools:<br />
<a href="ftp://ftp.f-secure.com/anti-virus/tools/beta/fsmrt.zip">ftp://ftp.f-secure.com/anti-virus/tools/beta/fsmrt.zip</a><br />
<a href="ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip">ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip</a></p>
<p>Then run <a href="http://ducktoes.com/blog/2009/01/04/best-free-anti-spyware-of-2008/">the usual Malwarebytes et al as in this post on Free Anti-spyware</a> just to get rid of any remaining spyware.  More later, my chickadees.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1058_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1058?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1058_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1058&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fdownandup-or-conficker-usb-worm-prevention-and-removal%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/downandup-or-conficker-usb-worm-prevention-and-removal/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Hallmark Card Virus (Again) and the Evil AntivirusOn.com</title>
		<link>http://ducktoes.com/blog/alerts/hallmark-card-virus-again-and-antivirusoncom/</link>
		<comments>http://ducktoes.com/blog/alerts/hallmark-card-virus-again-and-antivirusoncom/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 15:44:52 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Windows XP Antivirus 2008/2009]]></category>
		<category><![CDATA[AntivirusOn.com]]></category>
		<category><![CDATA[Fix Hallmark card virus]]></category>
		<category><![CDATA[Remove Windows XP Antivirus 2008]]></category>
		<category><![CDATA[Remove Windows Xp Antivirus 2009]]></category>
		<category><![CDATA[rogue anti-virus]]></category>
		<category><![CDATA[Youtube virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1039</guid>
		<description><![CDATA[Ms. Ducktoes really feels for the readers whose computers have the Hallmark card virus. So many of you are still coming to this blog for a fix. This has been going on for months. Since so many of you are still getting infected, today I went on-line to do a more research. I was wondering [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes really feels for the readers whose computers have the Hallmark card virus.  So many of you are still coming to this blog for a fix. This has been going on for months.</p>
<p>Since so many of you are still getting infected, today I went on-line to do a more research.  I was wondering if there were any new variants etc.</p>
<p>What I found troubled me:<br />
<a href="http://ducktoes.com/myblog/wp-content/uploads/2009/01/youtubevirus.gif"><img src="http://ducktoes.com/myblog/wp-content/uploads/2009/01/youtubevirus.gif" alt="This Google search result for &quot;hallmark virus&quot; leads to a Youtube video." title="youtubevirus" width="400" height="79" class="size-full wp-image-1040" /></a></p>
<p>The links lead to a Youtube video which pretends to be a Tutorial but really is an ad for AntispywareOn.com, a rogue anti-virus site that will give you&#8211;you guessed it&#8211;more spyware and viruses.  You can play the video without getting infected but don&#8217;t go to AntivirusOn.com. The video&#8217;s not much to see; it&#8217;s mostly obscured by big letters telling you to go to AntivirusOn.com. <a href="http://www.youtube.com/watch?v=KMHHXIGQEDo">Click here to see the video.</a></p>
<p><a href="http://www.eggheadcafe.com/video.aspx?videoid=129475">Now here&#8217;s a video that&#8217;s more interesting. </a> The video maker &#8220;Video search engine&#8221; infects a virtual machine with what you get on AntivirusOn.com and makes a video of the result.  And, oh dear, the result looks surprisingly familiar:  like another variant of the Windows XP Antivirus 2008/2009!</p>
<p>Ms. Ducktoes wants to stamp her (web) foot, she&#8217;s so sick of the Hallmark card virus and the Windows XP Anti-virus!!!</p>
<p>If you have the Hallmark virus, don&#8217;t go to AntivirusOn.com and even get more spyware and viruses.  I&#8217;m sure some of you have already.</p>
<p>If you need to remove the Hallmark Card virus, the Windows Xp Anti-virus 2008/2009 or any other spyware, <a href="http://ducktoes.com/blog/2009/01/04/best-free-anti-spyware-of-2008/">try this first.</a></p>
<p>If you already have bad spyware problems and can&#8217;t download the anti-spyware above<a href="http://ducktoes.com/blog/2008/11/14/how-to-fix-trojanvundo-in-safe-mode/">go here for a fix.</a></p>
<p>Good luck and as always your comments are most welcome.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1039_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1039?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1039_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1039&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fhallmark-card-virus-again-and-antivirusoncom%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/hallmark-card-virus-again-and-antivirusoncom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Be Careful on &quot;Hallmark and Postcard.exe virus removal&quot; Searches</title>
		<link>http://ducktoes.com/blog/alerts/hallmark-and-postcardexe-virus-google-searches/</link>
		<comments>http://ducktoes.com/blog/alerts/hallmark-and-postcardexe-virus-google-searches/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 15:23:49 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Windows XP Antivirus 2008/2009]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[New danger alert]]></category>
		<category><![CDATA[Remove Hallmark card virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=491</guid>
		<description><![CDATA[I&#8217;m concerned. Today while researching the Hallmark card and postcard.exe virus, I got these results on Google. The highlighted result in the middle leads to a download site for Windows XP Antivirus 2008/2009, a rogue Antivirus that is really a deadly virus for your computer. I mean a nasty. So this is the dramatic scenario, [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I&#8217;m concerned.  Today while researching the Hallmark card and postcard.exe virus, I got these results on Google.</p>
<div id="attachment_493" class="wp-caption aligncenter" style="width: 410px"><a href="http://ducktoes.com/myblog/wp-content/uploads/2008/11/google.jpg"><img class="size-full wp-image-493" title="google" src="http://ducktoes.com/myblog/wp-content/uploads/2008/11/google.jpg" alt="Google Results for " width="400" height="278" /></a><p class="wp-caption-text">Image of Google Results</p></div>
<p>The highlighted result in the middle leads to a download site for Windows XP Antivirus 2008/2009, a rogue Antivirus that is really a deadly virus for your computer.  I mean a nasty.</p>
<p>So this is the dramatic scenario, my innocent ducklings, you receive a Hallmark card or other e-card e-mail.  You know you are not supposed to open attachments on e-mails especially those ending with .exe or .dll but on this e-mail there are none. So you feel safe. There <em>is</em> a link, however, for you to see the Hallmark card (or other e-card) someone sent you.  You click the link. Instead of an ecard, your computer fills with the Hallmark card virus, and depending on what variant you download, a pretty bad virus.</p>
<p>Your computer is now looking and acting strange.  You&#8217;re worried.  You search online for solutions.  You search for &#8220;Hallmark card virus removal&#8221;.  You get results such as the ones above.  You may luck out and click Ducktoes or another legitimate antispyware site or you may click a link to the fraudulent rogue anti-virus  Windows XP Antivirus 2008/2009 above.  Immediately your computer starts to fill with an even more lethal virus.  So now you have one bad virus and one very bad virus.</p>
<p>The fraudulent website looks like this:</p>
<div id="attachment_496" class="wp-caption aligncenter" style="width: 510px"><a href="http://ducktoes.com/myblog/wp-content/uploads/2008/11/windowsantivirus.jpg"><img class="size-full wp-image-496" title="windowsantivirus" src="http://ducktoes.com/myblog/wp-content/uploads/2008/11/windowsantivirus.jpg" alt="Bogus Antivirus Site" width="500" height="380" /></a><p class="wp-caption-text">Bogus Antivirus Site</p></div>
<p>Now Ms. Ducktoes has to go to her day job fixing computers and get back to this later.  Please be careful until then.  Let me know what&#8217;s happening to your computer right now, so I have more information on what new variants there are and the type of frustation and problems you&#8217;re having, so I can help you more effectively.</p>
<p>Click on the <a href="http://ducktoes.com/blog/2008/11/18/hallmark-and-postcardexe-virus-google-searches/#comments">Comment</a> or No comment tag below.  Or e-mail me at admin@ducktoes.com.</p>
<p>And the virus removal techniques in yesterday&#8217;s post about <a href="http://ducktoes.com/blog/2008/11/14/how-to-fix-trojanvundo-in-safe-mode/">How to Fix Vundo in Safe Mode</a> should also be quite effective agains the Hallmark Card and Windows XP Anti-virus.  Give them a try. Until later.</p>
<p>Also I&#8217;m curious.  What spyware or virus are you struggling with right now?  Or if you don&#8217;t know, what symptoms do you have?  I invite your comments. <a href="http://ducktoes.com/blog/2008/11/18/hallmark-and-postcardexe-virus-google-searches/#comments">Comment here.</a></p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_491_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/491?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_491_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=491&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fhallmark-and-postcardexe-virus-google-searches%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/hallmark-and-postcardexe-virus-google-searches/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hallmark Card Virus Fix and Removal</title>
		<link>http://ducktoes.com/blog/alerts/hallmark-card-virus-fix/</link>
		<comments>http://ducktoes.com/blog/alerts/hallmark-card-virus-fix/#comments</comments>
		<pubDate>Sun, 05 Oct 2008 15:45:42 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Computer Repair Tools]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Hallmark card fix]]></category>
		<category><![CDATA[Hallmark card fraud]]></category>
		<category><![CDATA[hallmark card spyware]]></category>
		<category><![CDATA[Hallmark card virus not a fraud]]></category>
		<category><![CDATA[Remove Hallmark card virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=167</guid>
		<description><![CDATA[Many, many people are coming to this blog site looking for a fix for the Hallmark card virus. So it&#8217;s not a hoax!!! (The hoax part is that the virus will wipe out your hard drive. It doesn&#8217;t. But it does make a mess.) The e-mails going out purport to be a link to Hallmark [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Many, many people are coming to this blog site looking for a fix for the Hallmark card virus.  So it&#8217;s not a hoax!!! (The hoax part is that the virus will wipe out your hard drive.  It doesn&#8217;t.  But it does make a mess.)  The e-mails going out purport to be a link to Hallmark card, read more here <a href="http://ducktoes.com/blog/2008/05/06/trojan-and-virus-alert-phoney-hallmark-e-card/#comment-10370">(see this post)</a>, and if you click that link, you&#8217;ll get a direct download of a virus.</p>
<p>If you already have the Hallmark Card virus, there is a fix, or several of them.  Usually, normal virus software will remove it.  Here are some free anti-virus software that will do the trick.  Make sure your software is updated first, after you install and before you run the scan.  Without virus definitions, it&#8217;s impossible to catch anything.</p>
<p>First to get rid of the virus use one on these antivirus software:</p>
<p><a href="http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html?tag=mncol&amp;cdlPid=10891365">AVG 8 Free for Personal Use</a><br />
<a href="http://www.download.com/Avast-Home-Edition/3000-2239_4-10019223.html?tag=mncol&amp;cdlPid=10888427">Avast!</a><br />
<a href="http://www.download.com/Dr-Web-CureIt/3000-2239_4-10605754.html">Dr. Web CureIt</a></p>
<p>Then use this antispyware:<br />
<a href="http://www.superantispyware.com/superantispywarefreevspro.html">SuperAntiSpyware</a></p>
<p><a href="http://www.superantispyware.com/superantispywarefreevspro.html"></a><br />
<script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 110x32, created 1/21/08 */
google_ad_slot = "9211795734";
google_ad_width = 110;
google_ad_height = 32;
google_cpa_choice = ""; // on file
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Virus software is not enough.  You&#8217;ll also need an excellent anti-spyware tool.  Call me at 403-483-0105, if you have any questions.  (Please, not in the middle of the night in Canada, however!)</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Now if your computer is so bad already it won&#8217;t allow you to download anything, you&#8217;ll need to go into safe mode.<br />
1.  Restart your computer and tap the F8 key repeatedly.  Soon you&#8217;ll get to a screen that has many different options.</p>
<p>2. Pick the one (use your up and down arrows to move) that says <strong>Safe Mode with Networking.</strong></p>
<p>3.  A long list of drivers will scroll down the screen.  Then you&#8217;ll be given and option of Yes or No.  Pick Yes, you do want to go into Safe Mode.</p>
<p>4.  Now open your browser such as Internet Explorer or Firefox.  And type in http://ducktoes.com/blog.  Find this post Hallmark Card Fix.  And click this link to download <a href="http://www.malwarebytes.org/">Malwarebytes Antispyware</a>.</p>
<p>5. Run and update the program.  Make sure you update it first.  If your computer (actually the virus or malware) won&#8217;t let you update it, run it anyway.  Do the quick scan first.  Remove the malware it finds and restart the computer and then run it again.  If you can update it on the second time, update it and run it again, this time do the full scan.</p>
<p>Then go to the top of this blog post and install one of the antiviruses and the SuperAntispyware.</p>
<p>Good luck and let me know what works or doesn&#8217;t for you. Also let me know if it&#8217;s hard to download the antispyware.  How bad is the virus?  Click <a href="http://ducktoes.com/blog/2008/10/05/hallmark-card-virus-fix/#comments">here</a> to comment.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_167_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/167?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_167_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=167&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fhallmark-card-virus-fix%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/hallmark-card-virus-fix/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Ad Agent BN</title>
		<link>http://ducktoes.com/blog/alerts/ad-agent-bn/</link>
		<comments>http://ducktoes.com/blog/alerts/ad-agent-bn/#comments</comments>
		<pubDate>Sun, 28 Sep 2008 14:58:59 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Ad Agent BN]]></category>
		<category><![CDATA[Free AVG 8]]></category>
		<category><![CDATA[Purchase Spyware Doctor]]></category>
		<category><![CDATA[Remove Ad Agent BN]]></category>
		<category><![CDATA[Remove anti-spyware]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=118</guid>
		<description><![CDATA[Ms. Ducktoes now has eat her words, and take back what she said about Grisoft&#8217;s free AVG 8 in her last blog. AVG has proved to be a real trooper (a State Trooper even or an RCMP Mountie!) against the criminal and fraudulent Ad Agent BN. This week the malware has been extremely difficutl to [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes now has eat her words, and take back what she said about Grisoft&#8217;s free AVG 8 in her last blog. AVG has proved to be a real trooper (a State Trooper even or an RCMP Mountie!) against the criminal and fraudulent Ad Agent BN.</p>
<p>This week the malware has been extremely difficutl to get rid of.  Ad Agent BN has been one of the worst.  </p>
<p>Ad Agent BN was on a client&#8217;s computer, along with several other related Trojans.  The client, a friendly twenty-something young man named Matt, had somehow gotten this rogue anti-spyware on his computer.  At first the rogue program ran fake warning pop-ups on his desktop saying the computer had spyware.  But much worse it then locked up the Matt&#8217;s Control Panel, Start menu, and Windows Explorer.  Also Run and Search were not accessible. </p>
<p>Matt, a student, needed to turn in his assignments.  They were not backed up.  The computer was going down fast along with Matt&#8217;s marks.  I took out the hard drive of his computer and connected it to another computer and ran Spy Sweeper, Avira, and Avast! on the mounted disk.  They found several viruses and trojan horses.  I also ran regedit by mounting the hive of the harddrive and deleted some infected keys.  However when I reconnected the hard drive to Matt&#8217;s computer, the spyware and viruses were still there.  And they were active!!</p>
<p>Ms. Ducktoes, now in a tizzy about Matt&#8217;s marks, not to mention his photos and music, had to do something more.  Ducktoes to the rescue!  </p>
<p>This is what worked.  You can do it too:</p>
<p>1. Boot into Safe Mode with Networking.  To do this: Restart the computer.  Tap the the F8 key several times while the computer boots up. When you get to the screen with several booting options select Safe Mode with Networking.  </p>
<p>2. After Windows starts, then download PC Tools Spyware Doctor, purchase, update it, and run the scan.  </p>
<p><img src="http://www.lduhtrp.net/image-3158811-10540127" alt="" border="0" height="40" width="150" /></a></p>
<p>3. Restart the computer, let it boot into regular mode several times, restart it after each scan as Spyware Doctor recommends.  <a href="http://www.anrdoezrs.net/click-3158811-10540127" target="_top"</a></p>
<p>4. Boot back into Safe Mode with Networking. Download AVG free.<a href="http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html"> Download AVG 8 free</a> for home users.   </p>
<p>5. AVG doesn&#8217;t update in Safe Mode.  So restart the computer into regular mode.  Update AVG.  Now run Spyware Doctor.  While Spyware Doctor is running the Avg Shields will kick into effect and remove the processes.  Using the two programs together will get rid of the Ad Agent BN.  </p>
<p>I know that the programs during install tell you that it&#8217;s not good to have two anti-viruses running at the same time but it worked!!</p>
<p>So I&#8217;m now using free AVG 8 again for all my clients.  </p>
<p>Let me know&#8211;click the Comments link below&#8211; if this works for you.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_118_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/118?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_118_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=118&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fad-agent-bn%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/ad-agent-bn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dangerous New Trend, Serious and Urgent Alert!! Don&#8217;t click that link!!</title>
		<link>http://ducktoes.com/blog/alerts/dangerous-new-trend-serious-and-urgent-alert-dont-click-that-link/</link>
		<comments>http://ducktoes.com/blog/alerts/dangerous-new-trend-serious-and-urgent-alert-dont-click-that-link/#comments</comments>
		<pubDate>Mon, 12 May 2008 09:06:37 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[e-mails that link to trojans and spyware]]></category>
		<category><![CDATA[Ecard virus]]></category>
		<category><![CDATA[Hallmark card e-card]]></category>
		<category><![CDATA[new phish trend]]></category>
		<category><![CDATA[Paypal e-mail virus]]></category>
		<category><![CDATA[phish e-mails of binary code]]></category>
		<category><![CDATA[postcard fraud]]></category>
		<category><![CDATA[postcard hoax]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/2008/05/12/urgent-new-trend-serious-alert-dont-click-that-link-2/</guid>
		<description><![CDATA[Ms. Ducktoes is in a flap and a flutter because right now there is a new type of spyware danger that is so new it is causing a bit of havoc and making all of us anti-spyware professionals work overtime. Thousands of computers are infected. Phoney e-mails that purport to be from friends or legitimate [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes is in a flap and a flutter because right now there is a new type of spyware danger that is so new it is causing a bit of havoc and making all of us anti-spyware professionals work overtime.  Thousands of computers are infected.   Phoney e-mails that purport to be from friends or legitimate businesses encourage the victims to click a link.  This will initiate a download of a most dangerous group of spyware and viruses.  One is a trojan horse that lets the criminal hacker take over your computer and control it remotely.  Others will install a back door in your computer that gives hackers access to do even more damage or add even more spyware.  Still others tell you, in a warning on your desktop, that you have spyware, and try to get you to buy a rogue anti-spyware, that will give you even more malware.</p>
<p>I have received three of these phoney, dangerous e-mails.  One told me a friend had sent me a Hallmark card that linked to a nasty download of binary code (trojan).  I already wrote a blog about that one.  <a href="http://ducktoes.com/blog/2008/05/06/trojan-and-virus-alert-phoney-hallmark-e-card/">Read it here.</a></p>
<p>Another, my cousin Jack warned  his friends and family about, a postcard e-mail that links to a virus download.  Here is his e-mail:</p>
<p><em>Please be careful of the upcoming virus.</em></p>
<p><em> Big Virus coming</em></p>
<p><em> http://www.snopes.com/computer/virus/postcard.asp</em></p>
<p><em> Hi All, I checked with Norton Anti-Virus, and they are gearing up for this virus!</em></p>
<p><em> I checked Snopes (URL above:), and it is for real!!</em></p>
<p><em> Get this E-mail message sent around to your contacts ASAP.</em></p>
<p><em> PLEASE FORWARD THIS WARNING AMONG FRIENDS, FAMILY AND CONTACTS!</em></p>
<p><em> You should be alert during the next few days. Do not open any message with an attachment entitled &#8216;POSTCARD,&#8217; regardless of who sent it to you. It<br />
Is a virus which opens A POSTCARD IMAGE, which &#8216;burns&#8217; the whole hard disc C of your computer.</em></p>
<p><em> This virus will be received from someone who has your e-mail address in his/her contact list. This is the reason why you need to send this e-mail to all your contacts It is better to receive this message 25 times than to receive the virus and open it.</em></p>
<p><em> If you receive a mail called&#8217; POSTCARD,&#8217; even though sent to you by a friend, do not open it! Shut down your computer immediately.</em></p>
<p><em> This is the worst virus announced by CNN. It has been classified by Microsoft as the most destructive virus ever. This virus was discovered by McAfee yesterday, and there is no repair yet for this kind of virus.<br />
This virus simply destroys the Zero Sector of the Hard Disc, where the vital<br />
Nformation is kept.</em></p>
<p><em> COPY THIS E-MAIL, AND SEND IT TO YOUR FRIENDS. REMEMBER: IF YOU SEND IT<br />
TO THEM, YOU WILL BENEFIT ALL OF US. &#8220;</em></p>
<p>While the e-mail is incorrect that the virus will burn a hole in your hard drive, it may cause you to have to get your hard drive reformatted, which will indeed burn all your data, which is essentially the same thing.  Also it lets the attackers take control your computer. The trojan is very difficult to remove.  The e-mail is confusing a few viruses and hoaxes but is a good warning nevertheless, since it lets everyone know not to open the postcard e-mails.  I did receive one this week so it&#8217;s definitely making the rounds.</p>
<p>The third one I received&#8211;today&#8211;was supposedly from Paypal.  It said my account had been limited.  But the link to fix the account limitation problem was&#8212;again, you guessed it&#8212;a link to a download of nasty virus code.</p>
<p>So the Phishers and Hackers have stepped up their attacks with a new method.  Instead of just getting your passwords and account numbers and credit card numbers as they do in regular phish e-mails and websites, now they give you an immediate download of binary code.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br />
Read<a href="http://ducktoes.com/blog/how-to-protect-yourself-from-spyware-and-viruses-2/">my guide to preventing spyware</a>. Or the Self-Help tutorials <a href="http://www.ducktoes.com">here.</a></p>
<p>Please feel free to comment.  I invite all comments.  Or let me know what your experience is with e-card viruses.  I&#8217;d really like to find out what is going on in the larger world.</p>
<p><map name='google_ad_map_89_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/89?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_89_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=89&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fdangerous-new-trend-serious-and-urgent-alert-dont-click-that-link%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/dangerous-new-trend-serious-and-urgent-alert-dont-click-that-link/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 1.412 seconds -->

