<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ducktoes Computer Repair and Spyware Blog &#187; Individual Spywares</title>
	<atom:link href="http://ducktoes.com/blog/index.php/category/individual-spywares/feed/" rel="self" type="application/rss+xml" />
	<link>http://ducktoes.com/blog</link>
	<description>Ms. Ducktoes is on her way!  Saving computers everyday!</description>
	<lastBuildDate>Thu, 26 Jan 2012 15:40:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>How to remove the hdd virus</title>
		<link>http://ducktoes.com/blog/individual-spywares/how-to-remove-the-hdd-virus/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/how-to-remove-the-hdd-virus/#comments</comments>
		<pubDate>Thu, 16 Dec 2010 13:55:48 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[HDD virus removal]]></category>
		<category><![CDATA[How to remove HDD virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1581</guid>
		<description><![CDATA[The HDD virus advertises itself as a legitimate program, a hard drive defragmenter, but it&#8217;s really malware. If you fall for their ploy while trying to defragment your hard drive, you won&#8217;t be the first, since we&#8217;re seeing many infected computers in the Ducktoes virus lab. To get rid of HDD virus: 1. Download and [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<div id="attachment_1617" class="wp-caption aligncenter" style="width: 310px"><a href="http://ducktoes.com/blog/wp-content/uploads/2010/12/hdd-defragmenter.jpg"><img class="size-medium wp-image-1617" title="hdd-defragmenter" src="http://ducktoes.com/blog/wp-content/uploads/2010/12/hdd-defragmenter-300x202.jpg" alt="" width="300" height="202" /></a><p class="wp-caption-text">This is what the HDD Virus (Malware) looks like</p></div>
<p>The HDD virus advertises itself as a legitimate program, a hard drive defragmenter, but it&#8217;s really malware. If you fall for their ploy while trying to defragment your hard drive, you won&#8217;t be the first, since we&#8217;re seeing many infected computers in the Ducktoes virus lab.</p>
<p>To get rid of HDD virus:</p>
<p>1. Download and run Malwarebytes. <a href="http://malwarebytes.org">Click here</a> to get Malwarebytes. If you have trouble downloading and installing Malwarebytes, start in Safe Mode, by tapping the F8 key while booting. Then pick &#8220;Safe Mode with Networking.&#8221; Either way, you&#8217;ll need to update and run the program. Restart the computer.</p>
<p>2. Next download and run either <a href="http://download.cnet.com/AVG-Anti-Virus-Free-Edition-2012/3000-2239_4-10320142.html">AVG</a> or <a href="http://download.cnet.com/Avira-Free-Antivirus/3000-2239_4-10322935.html">Avira</a>. These are both excellent anti-viruses and both free for home use.</p>
<p>3. Then just to be safe, download and run <a href="http://www.superantispyware.com/download.html">Super-Anti-Spyware.</a></p>
<p>You should now be HDD Virus Free.</p>
<p>The next blog post will be about good, safe legitimate defragmenters, so stay posted.</p>
<p>If you&#8217;re having trouble removing viruses from your computer and you live in Calgary, come to our shop at 902 Centre St. NE right outside downtown or give us a call. We&#8217;re <a href="http://www.ducktoes.com">Ducktoes Calgary Computer Repair</a> and <a href="http://ducktoes.com/virus_removal.php">Virus Removal</a>.</p>
<p>Outside of Calgary, you can use Bleeping Computer to fix your computer for free.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>If you need <a href="http://ducktoes.com">computer repair click here</a> or <a href="http://ducktoes.com/business_support.php">IT business services click here.</a></p>
<p><map name='google_ad_map_1581_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1581?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1581_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1581&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fhow-to-remove-the-hdd-virus%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/how-to-remove-the-hdd-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fix the &quot;Open With&quot; Virus</title>
		<link>http://ducktoes.com/blog/individual-spywares/fix-the-open-with-virus/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/fix-the-open-with-virus/#comments</comments>
		<pubDate>Mon, 07 Sep 2009 14:25:04 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Fix Open With Virus]]></category>
		<category><![CDATA[Open With Virus]]></category>
		<category><![CDATA[Remove Open With Virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1255</guid>
		<description><![CDATA[I just fixed an odd virus: the &#8220;Open With&#8221; Virus. Everything I tried to open including my usual anti-virus programs prompted a dialog box asking what I wanted to open the AVG with. Of course that&#8217;s silly, you can&#8217;t open AVG with another program like Microsoft Word or Adobe Reader. It kept me from doing [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I just fixed an odd virus: the &#8220;Open With&#8221; Virus. Everything I tried to open including my usual anti-virus programs prompted a dialog box asking what I wanted to open the AVG with. Of course that&#8217;s silly, you can&#8217;t open AVG with another program like Microsoft Word or Adobe Reader. It kept me from doing anything. That&#8217;s why it&#8217;s called the &#8220;Open With&#8221; virus. The virus asks, What would like to open that with? Oh, I think I&#8217;ll open Internet Explorer with Civilization 4 (I have sons). And I&#8217;ll open itunes with Instant Messenger. See, it doesn&#8217;t make sense, and moreover it doesn&#8217;t work, in fact nothing works, and you are stuck. You are deep in the doo doo of Malwareland.</p>
<div id="attachment_1854" class="wp-caption aligncenter" style="width: 243px"><a href="http://ducktoes.com/blog/wp-content/uploads/2009/09/deepdoodoo3.jpg"><img class=" wp-image-1854 " style="border-image: initial; margin-top: 5px; margin-bottom: 5px; border-width: 2px; border-color: black; border-style: solid;" title="Calgary computer repair" src="http://ducktoes.com/blog/wp-content/uploads/2009/09/deepdoodoo3.jpg" alt="A photo of giant turds from computer repair Calgary" width="233" height="175" /></a><p class="wp-caption-text">You&#39;re in the deep doodoo of Malwareland.</p></div>
<p>Some techs say you have to reformat if you get this virus, but Ms Ducktoes hates that word &#8220;reformat&#8221;. I&#8217;ve seen it make a grown man cry. And then when he cries, I cry, and then I get a sinus headache and my mascara runs down my cheeks. So I find it much better and less embarrassing to do this instead:</p>
<p>Right click on the program you want to run, such as AVG. From the choices displayed, click on &#8220;Run as&#8221; and pick your own user. There&#8217;s a box you have to uncheck too. I ran AVG and it quarantined the virus. Then I was able to do the usual virus clean up.</p>
<p><a href="http://ducktoes.com/blog/wp-content/uploads/2009/09/sickcomputer.jpg"><img class="size-full wp-image-1849 alignright" style="border-image: initial; border-width: 1px; border-color: black; border-style: solid; margin: 5px;" title="Computer repair Calgary" src="http://ducktoes.com/blog/wp-content/uploads/2009/09/sickcomputer.jpg" alt="A photo of infected computer from Calgary Computer repair" width="235" height="214" /></a></p>
<p>But if you don&#8217;t have an anti-virus on the computer already what do you do? Install <a href="http://malwarebytes.org">Malwarebytes</a> on another computer. You&#8217;ll get a set up icon on your desktop. Stick a flash drive (you can buy them at any electronics store) into the usb port and go to My Computer (Start &gt; My Computer, or just &#8220;Computer&#8221; on Vista) and you&#8217;ll see all your drives, your hard drive or drives, your dvd player, and now the flash drive. Click on the flash drive. A window will open. Now drag the set up icon of Malwarebytes into the flash drive&#8217;s window. Remove the flash drive.</p>
<p>Then put the flash drive into the infected computer. It will probably have to install as a drive. Go to My Computer. Find the Malwarebytes set-up icon. Right click on it and &#8220;Run As&#8221; your user. Let it install and run and do it&#8217;s thing.</p>
<p>After that go to this<span style="text-decoration: underline;"> <a href="http://ducktoes.com/blog/?p=1180">page on my blog, click these words here</a></span> and follow the rest of the instructions.</p>
<p>If you want, Ducktoes Computer Repair can fix your virus. <a href="http://ducktoes.com/remote.php">Click here to read more about our remote service.</a> <a href="http://ducktoes.com/book_online.php">Or click here to book remote appointment.</a> http://ducktoes.com/book_online.php We&#8217;ll get back to you.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1255_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1255?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1255_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1255&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Ffix-the-open-with-virus%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/fix-the-open-with-virus/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Trojan Horse Clicker &#8211; No My Friend Flicka.</title>
		<link>http://ducktoes.com/blog/uncategorized/trojan-horse-clicker-no-friend-flicker/</link>
		<comments>http://ducktoes.com/blog/uncategorized/trojan-horse-clicker-no-friend-flicker/#comments</comments>
		<pubDate>Sun, 30 Aug 2009 01:27:13 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[Calgary computer repair]]></category>
		<category><![CDATA[Combofix]]></category>
		<category><![CDATA[Grisoft]]></category>
		<category><![CDATA[Malwarebytes]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Trojan horse Clicker]]></category>
		<category><![CDATA[trojan horses]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1252</guid>
		<description><![CDATA[I just cleaned up a computer, an Acer laptop, that had tons of spyware and among them was Trojan Horse Clicker. To get rid of it and the rest of the spyware I did the usual: 1.First I ran Combofix. (I did this in Safe Mode with Networking.) To get into Safe Mode, I had [...]]]></description>
			<content:encoded><![CDATA[<p>I just cleaned up a computer, an Acer laptop, that had tons of spyware and among them was Trojan Horse Clicker.   To get rid of it and the rest of the spyware I did the usual:</p>
<p>1.First I ran Combofix.  (I did this in Safe Mode with Networking.)</p>
<p>To get into Safe Mode, I had to tap F8 as the computer booted.  If you tap at just the right time, a list of options in black and white is displayed on your screen.  If you get the usual Windows boot up, you&#8217;ve missed Safe Mode so you&#8217;ll have to restart and tap again.</p>
<p>Pick <em>Safe Mode with Networking</em>.  Then you&#8217;ll see a message asking if you&#8217;re sure you want to go into Safe Mode or if you&#8217;d rather use System Restore.  Click <em>yes</em> you do want to go into Safe Mode.  In Safe Mode you can then download and run Combofix.</p>
<p>When you get to the page, you&#8217;ll have to scroll down.  I usually pick the Bleeping Computer link.. you&#8217;ll have to scroll down.  It looks like this.</p>
<div id="attachment_1260" class="wp-caption aligncenter" style="width: 433px"><a href="http://ducktoes.com/myblog/wp-content/uploads/2009/08/combofix.gif"><img class="size-medium wp-image-1260" title="combofix" src="http://ducktoes.com/blog/wp-content/uploads/2009/08/combofix-300x164.gif" alt="" width="423" height="231" /></a><p class="wp-caption-text">This is a photo of the Bleeping Computer website where you download Combofix.</p></div>
<p>Download Combofix <a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix">here.</a></p>
<p>If you can&#8217;t download or run Combofix then you have very serious virus problems so see <a href="http://ducktoes.com/blog/2008/12/17/when-spyware-gets-really-bad-what-to-do-when-you-cant-do-anything/">this post</a>.</p>
<p>After I ran Combofix, enough spyware had been removed so that I could do the following in regular Windows mode.</p>
<p>2. Downloaded and installed AVG.</p>
<p>3. Downloaded and installed Malwarebytes.</p>
<p>4. Ran Malwarebytes.  Malwarebytes caught quite a few Trojans.  Also when I ran Malwarebytes, AVG&#8217;s residential shield caught a few more things that Malwarebytes going through the files seemed to stir up.</p>
<p>4.  Ran a full scan of AVG.  The AVG is what caught our friend Trojan Horse Clicker.</p>
<p><map name='google_ad_map_1252_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1252?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1252_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1252&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Funcategorized%2Ftrojan-horse-clicker-no-friend-flicker%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/uncategorized/trojan-horse-clicker-no-friend-flicker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Starware</title>
		<link>http://ducktoes.com/blog/individual-spywares/how-to-remove-starware/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/how-to-remove-starware/#comments</comments>
		<pubDate>Sun, 21 Jun 2009 13:10:53 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Toobars]]></category>
		<category><![CDATA[how to fix Starware]]></category>
		<category><![CDATA[How to remove Starware]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[toolbars. How to remove the toolbar Starware]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1225</guid>
		<description><![CDATA[I removed Starware from a photographer&#8217;s computer this week. The computer was oppressively slow and Outlook was crashing a lot. My client couldn&#8217;t work efficiently, since the interruptions slowed down the work he could do in a day. He was sooo frustrated. Starware took a tenacious hold of the operating system. It&#8217;d installed hundreds of [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I removed Starware from a photographer&#8217;s computer this week.  The computer was oppressively slow and Outlook was crashing a lot.  My client couldn&#8217;t work efficiently, since the interruptions slowed down the work he could do in a day. He was sooo frustrated.</p>
<p>Starware took a tenacious hold of the operating system. It&#8217;d installed hundreds of registry keys, files, and applications. The apps were running in the background, making the compute insufferably slow.  All for one harmless-looking toolbar.</p>
<p>If you must have a toolbar cluttering up your browser, use Google&#8217;s or Yahoo&#8217;s.  And indeed, it seems you must have both of them, since they are omni-present, appearing out of nowhere onto your browser with one mindless click of the mouse. It&#8217;s hard not to have them, whether you want them or not. But I digress..</p>
<p>After removing Starware, the computer acted normally and Outlook worked again.  The photographer could get on with his business.</p>
<p>Starware is a good name, since it was designed by someone much like a character out of Star Wars, not a hero like Hans Solo, but a Darth Vader who callously likes to muck up people&#8217;s lives and businesses by damaging their computers.  Someone who&#8217;s sold out to the dark side.</p>
<p>To remove Starware, I used <a href="http://malwarebytes.org">Malwarebytes</a>.  To download Malwarebytes, click <a href="http://malwarebytes.org">here</a>.  Or go there by typing http://malwarebytes.org in your browser&#8217;s address bar.  Be sure to update before you scan.</p>
<p>And take care out there.</p>
<p>Oh, baby, baby it&#8217;s a wild web.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1225_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1225?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1225_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1225&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fhow-to-remove-starware%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/how-to-remove-starware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Gaopdx</title>
		<link>http://ducktoes.com/blog/individual-spywares/how-to-remove-gaopdx/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/how-to-remove-gaopdx/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 03:19:05 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[Gaopdx]]></category>
		<category><![CDATA[Gaopdx removal]]></category>
		<category><![CDATA[rootkit removal]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1113</guid>
		<description><![CDATA[Hey the other night, I was at a house in Northeast Calgary that had a huge tv on the wall right in front of the computer. So I got to watch the Flames game while I fixed the computer which had the nasty and new Gaopdx rootkit. It was an exciting evening with a really [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Hey the other night, I was at a house in Northeast Calgary that had a huge tv on the wall right in front of the computer.  So I got to watch the Flames game while I fixed the computer which had the nasty and new Gaopdx rootkit.  It was an exciting evening with a really close game on the wall, and a really close fight with the computer..We all won in the end, both the Flames and Ms. Ducktoes.  I used Malwarebytes and Combo Fix to remove the potent rootkit.</p>
<p>Ducktoes is on her way, saving computers everyday!!!  It took me a couple of hours since Gaopdx made the computer so slow.  And the usual anti-spywares and anti-viruses didn&#8217;t work.</p>
<p>Malwarebytes removed these parts of the Gaopdx:  Trojan.Agent and Trojan.DNSChanger, but not the rootkit itself.  ComboFix removed the rootkit.</p>
<p>Since the malware would not let me download anything in Normal mode, I had to go into to Safe Mode to download both Malwarebytes and ComboFix.</p>
<p>This is what you need to do:<br />
Click here to download <a href="http://www.malwarebytes.org/">Malwarebytes</a> and here for <a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix">ComboFix.</a></p>
<p>But if your browser won&#8217;t let you download them, then you&#8217;ll have to go into Safe Mode by restarting the computer.  As the computer reboots, tap the F8 key several times.  You should get a black and white screen listing several options.  Pick &#8220;Safe Mode with Networking.&#8221;  When Safe Mode starts Windows you&#8217;ll be asked if you want to continue.  Pick &#8220;Yes.&#8221;</p>
<p>Now click here for <a href="http://www.malwarebytes.org/">Malwarebytes</a>.  Download the free version unless you&#8217;d like to buy the full one.  It&#8217;s a great program.  Then download and run <a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix">ComboFix.  </a>  There&#8217;s also a tutorial. Read it to learn how to run the program.  ComboFix removed the Gaopdx rootkit completely.</p>
<p>Whew, that was a close one!!!</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1113_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1113?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1113_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1113&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fhow-to-remove-gaopdx%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/how-to-remove-gaopdx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Downandup or Conficker USB Worm Prevention and Removal</title>
		<link>http://ducktoes.com/blog/alerts/downandup-or-conficker-usb-worm-prevention-and-removal/</link>
		<comments>http://ducktoes.com/blog/alerts/downandup-or-conficker-usb-worm-prevention-and-removal/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 21:05:22 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Conficker worm]]></category>
		<category><![CDATA[Fix Conficker worm]]></category>
		<category><![CDATA[Prevent Conficker worm]]></category>
		<category><![CDATA[remove Conficker worm]]></category>
		<category><![CDATA[stop Autoruns]]></category>
		<category><![CDATA[USB worm]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1058</guid>
		<description><![CDATA[Ms. Ducktoes is really busy removing spyware and replacing power supplies today, but I&#8217;ve noticed an influx of this new worm. So I thought I should warn you. It&#8217;s called the Downandup/Conficker worm. Millions of computers are infected. To avoid getting it, turn off Autoruns on your computer. Click here to learn how to turn [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes is really busy removing spyware and replacing power supplies today,  but I&#8217;ve noticed an influx of this new worm.  So I thought I should warn you. It&#8217;s called the Downandup/Conficker worm. Millions of computers are infected.  To avoid getting it, turn off Autoruns on your computer. <a href="http://ducktoes.com/blog/2009/01/14/how-to-prevent-usb-worm/">Click here to learn how to turn off Autoruns.</a></p>
<p>To fix or remove Downandup or Conficker worm, there are these free removal tools:<br />
<a href="ftp://ftp.f-secure.com/anti-virus/tools/beta/fsmrt.zip">ftp://ftp.f-secure.com/anti-virus/tools/beta/fsmrt.zip</a><br />
<a href="ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip">ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip</a></p>
<p>Then run <a href="http://ducktoes.com/blog/2009/01/04/best-free-anti-spyware-of-2008/">the usual Malwarebytes et al as in this post on Free Anti-spyware</a> just to get rid of any remaining spyware.  More later, my chickadees.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1058_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1058?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1058_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1058&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fdownandup-or-conficker-usb-worm-prevention-and-removal%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/downandup-or-conficker-usb-worm-prevention-and-removal/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Spying on Spouses or Lovers with Keyloggers</title>
		<link>http://ducktoes.com/blog/individual-spywares/spying-on-spouses-with-keyloggers/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/spying-on-spouses-with-keyloggers/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 18:47:25 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Keyloggers]]></category>
		<category><![CDATA[adultery and keyloggers]]></category>
		<category><![CDATA[affairs]]></category>
		<category><![CDATA[anti-spyware]]></category>
		<category><![CDATA[infidelity]]></category>
		<category><![CDATA[Infidelity and keyloggers]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[marriage]]></category>
		<category><![CDATA[marriage counseling]]></category>
		<category><![CDATA[recovering from an affair]]></category>
		<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[spying]]></category>
		<category><![CDATA[spying on spouses]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[stop the affair]]></category>
		<category><![CDATA[stopping adultery]]></category>
		<category><![CDATA[using keyloggers secretly]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1002</guid>
		<description><![CDATA[Sometimes computer repair jobs turn into something else. Sometimes Ms. Ducktoes is sitting quietly, concentrating on a computer and the client starts to talk, and before Ms. Ducktoes can say, &#8220;I think your hard drive is going bad,&#8221; she finds herself in the middle of a sensitive personal disclosure. Other times people request services that [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Sometimes computer repair jobs turn into something else.  Sometimes Ms. Ducktoes is sitting quietly, concentrating on a computer and the client starts to talk, and before Ms. Ducktoes can say, &#8220;I think your hard drive is going bad,&#8221; she finds herself in the middle of a sensitive personal disclosure.</p>
<p>Other times people request services that Ms. Ducktoes doesn&#8217;t do.  Like installing spyware.</p>
<p>Yesterday, Friday, a man called Ms. Ducktoes.  I&#8217;ll call him Henry.  Henry said he was worried about spyware on his computer.  But when I arrived at his door, it turned out what Henry really wanted was a program that would secretly track everything done on his computer, all e-mail, all websites visited, all Instant Messenger chats.  So he&#8217;d have a backup, he said.</p>
<p>I stared.  &#8220;You want a keylogger for a backup?&#8221;</p>
<p>Henry, probably hearing the incredulity in my voice, turned pale.  &#8220;What&#8217;s a keylogger?&#8221; he said.</p>
<p> &#8220;A keylogger is a type of spyware that records every keystroke typed on the keyboard and sometimes take screenshots of websites visited and e-mails viewed.&#8221;</p>
<p>He said, &#8220;Yes, that&#8217;s it, a keylogger.&#8221;</p>
<p>When I sat down in front of his computer, the screen displayed only one user: Naomi. &#8220;Who&#8217;s Naomi?&#8221; I asked.</p>
<p>&#8220;My wife.  It&#8217;s her computer.&#8221;</p>
<p>&#8220;Does Naomi know you&#8217;re making a backup of everything she does on-line?&#8221;</p>
<p>His voice came out shaky. &#8220;Yes,&#8221; he said.</p>
<p>&#8220;Okay,&#8221; I said, &#8220;but. it can&#8217;t be secret.  It has to give Naomi a warning the keylogger is recording her every keystroke.&#8221;  I sat up straigher.  &#8220;Otherwise it&#8217;s spyware.&#8221;</p>
<p>Henry raised his voice. &#8220;But I need to see what -.&#8221;  He screwed up his face like he might cry.</p>
<p>&#8220;You need to see what she&#8217;s doing?&#8221;</p>
<p>He nodded and started to cry into his hands.  &#8220;I think she&#8217;s seeing someone.  Having an affair. She instant messages until late at night.  She takes long lunches and is really distant.  But she denies it so I need proof.&#8221;</p>
<p>I patted his shoulder.  &#8220;Oh, I&#8217;m so sorry, Henry, but surely that&#8217;s not the best way.&#8221;</p>
<p>&#8220;I&#8217;m in so much pain,&#8221; he said.</p>
<p>&#8220;Yes, I&#8217;m sure you are. That&#8217;s a terrible thing to go through.&#8221;</p>
<p>He looked up, surprised.</p>
<p>&#8220;I&#8217;ve been down a road or two,&#8221; I said.  &#8220;Or three.  But can I tell you something I&#8217;ve learned from lots of counseling?&#8221;</p>
<p>Henry nodded.</p>
<p>&#8220;Spying isn&#8217;t going to relieve your pain or solve your problems. Spying just makes you a victim, too needy, too wrapped-up in Naomi&#8217;s activities, and too desperate. You need to do something positive, something for you. Something to raise yourself out of the emotional muck.  Something to give you your dignity back.&#8221;</p>
<p>Henry nodded solemnly. &#8220;Like what?&#8221;  he said.</p>
<p>&#8220;Well, you could exercise, and get buff, or take a class in something you like, or take a trip.  Maybe get counseling.&#8221;</p>
<p>&#8220;I don&#8217;t feel like doing anything,&#8221; Henry said.</p>
<p>&#8220;No, probably not.  But doing something fun or positive would relieve your obsession about your wife a bit.  Would make you more attractive.&#8221;</p>
<p>&#8220;To Naomi?&#8221;</p>
<p>&#8220;To yourself. To heck with Naomi.&#8221;</p>
<p>He looked farway.  &#8220;Maybe I&#8217;ll go skiing for the weekend.  By myself.&#8221;</p>
<p>&#8220;Good idea,&#8221; I said.  &#8220;Now give me some computer work to do.&#8221;</p>
<p>&#8220;Why?&#8221;</p>
<p>&#8220;Because I have to charge you my minimum charge anyway.&#8221;</p>
<p>So I took Henry&#8217;s own computer back to the shop and removed 259 spyware and viruses from it and really sped up its boot time.  Then I called his cell.  He didn&#8217;t answer but he did eventually call back from a hot tub in the mountains.  His voice sounded quite serene.  He said that his wife kept calling but he wasn&#8217;t returning her calls yet.</p>
<p>I know how tempting it can be to spy on your spouse&#8217;s or partner&#8217;s computer if they seem to be straying from you and the marriage.  But its not an action that will help.  If a marriage isn&#8217;t working for you don&#8217;t need spyware to act.  Act from your own needs and desires.  Do something to enhance your interest and joy in life and the world.  Something positive and life-affirming.  Your new outlook will be attractive to others.</p>
<p>You don&#8217;t need to buy spyware to save your marriage.  An alternative might be the wonderful newsletter from <a href="http://keepyourmarriage.com/">the &#8220;Keep your Marriage&#8221;  website.</a>  I&#8217;ve found it quite helpful and interesting.  Their book was good too.  It really helped me in making it through a bad time in my marriage and life.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1002_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1002?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1002_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1002&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fspying-on-spouses-with-keyloggers%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/spying-on-spouses-with-keyloggers/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to Prevent the USB Worm</title>
		<link>http://ducktoes.com/blog/basic-computer-tips/how-to-prevent-usb-worm/</link>
		<comments>http://ducktoes.com/blog/basic-computer-tips/how-to-prevent-usb-worm/#comments</comments>
		<pubDate>Wed, 14 Jan 2009 14:30:21 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Basic Computer Tips]]></category>
		<category><![CDATA[Hints for Techies]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[How to turn off autorun]]></category>
		<category><![CDATA[improve computer security]]></category>
		<category><![CDATA[Prevent USB Trojan]]></category>
		<category><![CDATA[Prevent USB worm]]></category>
		<category><![CDATA[remove CD restrictions]]></category>
		<category><![CDATA[Turn off Autorun]]></category>
		<category><![CDATA[USB trojan]]></category>
		<category><![CDATA[USB trojans]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=994</guid>
		<description><![CDATA[There&#8217;s a new USB worm about. It loads on your computer when you stick an infected USB drive (Flash memory drive) into a USB port or an infected CD into the CD drive. Since it installs through the Autorun function on Windows, this type of worm is easy to prevent. Simply turn off Autorun. To [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>There&#8217;s a new USB worm about.  It loads on your computer when you stick an infected USB  drive (Flash memory drive) into a USB port or an infected CD into the CD drive.  Since it installs through the Autorun function on Windows, this type of worm is easy to prevent.  Simply turn off Autorun.</p>
<p>To turn off Autorun do this:</p>
<p>1. Go to Start button then Run.<br />
2. Type in &#8220;gpedit.msc&#8221; without the quotes.<br />
3. The Group policy window will open.<br />
4. Choose &#8220;System&#8221; under &#8220;Administrative Templates.&#8221;<br />
5. Find &#8220;Turn off Autoplay&#8221; and double-click it.<br />
6.  You&#8217;ll see three choices with radio buttons (round check boxes) in front of them: Not configured, Enabled, Disabled.  Pick &#8220;Enabled.&#8221;<br />
7. Underneath the radio buttons you&#8217;ll see the words &#8220;Turn off Autoplay on.&#8221;  Choose &#8220;All drives.&#8221;</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Not only will this prevent the USB worm, it will also let you play some CDs without all the manufacturers&#8217; restrictions.</p>
<p><map name='google_ad_map_994_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/994?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_994_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=994&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fbasic-computer-tips%2Fhow-to-prevent-usb-worm%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/basic-computer-tips/how-to-prevent-usb-worm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Did you get Koobfaced on Facebook?</title>
		<link>http://ducktoes.com/blog/individual-spywares/did-you-get-koobfaced-on-facebook/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/did-you-get-koobfaced-on-facebook/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 13:02:21 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[how to fix Koobface virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=723</guid>
		<description><![CDATA[Yes, it&#8217;s true, there&#8217;s a virus from Facebook called Koobface. If you haven&#8217;t noticed, Koob is &#8220;book&#8221; backwards. If let to run it&#8217;s course, Koobface will turn your Facebook account backwards too, or at least inside out. It&#8217;ll also infect your computer system. You&#8217;ll notice it takes longer to go from website to website. And [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Yes, it&#8217;s true, there&#8217;s a virus from Facebook called Koobface.  If you haven&#8217;t noticed, Koob is &#8220;book&#8221; backwards.  If let to run it&#8217;s course, Koobface will turn your Facebook account backwards too, or at least inside out.  It&#8217;ll also infect your computer system.  You&#8217;ll notice it takes longer to go from website to website.  And sometimes when you search on Google, you may get a different search engine instead, a lame, bogus search engine whose primary purpose is to promote its ads.  It&#8217;s adware.</p>
<p>Facebook suggests you immediately change your password and run a good anti-virus.  A GOOD one.  If you want the best try Spyware Doctor with Antivirus, the highest rated anti-spyware around.</p>
<p><script type="text/javascript" language="javascript" src="http://www.dpbolvw.net/2666u0xmoqt-xpq2BFEEHIJC?target=_blank&mouseover=Y"></script></p>
<p>Here&#8217;s a <a href="http://tonysgeektips.wordpress.com/2008/12/04/update-on-koobface-virus/">site</a> that tells you how to fix your system.</p>
<p>Please feel free to comment and let me know how Koobface affects your Facebook account and your computer.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_723_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/723?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_723_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=723&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fdid-you-get-koobfaced-on-facebook%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/did-you-get-koobfaced-on-facebook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Be Careful on &quot;Hallmark and Postcard.exe virus removal&quot; Searches</title>
		<link>http://ducktoes.com/blog/alerts/hallmark-and-postcardexe-virus-google-searches/</link>
		<comments>http://ducktoes.com/blog/alerts/hallmark-and-postcardexe-virus-google-searches/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 15:23:49 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Windows XP Antivirus 2008/2009]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[New danger alert]]></category>
		<category><![CDATA[Remove Hallmark card virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=491</guid>
		<description><![CDATA[I&#8217;m concerned. Today while researching the Hallmark card and postcard.exe virus, I got these results on Google. The highlighted result in the middle leads to a download site for Windows XP Antivirus 2008/2009, a rogue Antivirus that is really a deadly virus for your computer. I mean a nasty. So this is the dramatic scenario, [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I&#8217;m concerned.  Today while researching the Hallmark card and postcard.exe virus, I got these results on Google.</p>
<div id="attachment_493" class="wp-caption aligncenter" style="width: 410px"><a href="http://ducktoes.com/myblog/wp-content/uploads/2008/11/google.jpg"><img class="size-full wp-image-493" title="google" src="http://ducktoes.com/myblog/wp-content/uploads/2008/11/google.jpg" alt="Google Results for " width="400" height="278" /></a><p class="wp-caption-text">Image of Google Results</p></div>
<p>The highlighted result in the middle leads to a download site for Windows XP Antivirus 2008/2009, a rogue Antivirus that is really a deadly virus for your computer.  I mean a nasty.</p>
<p>So this is the dramatic scenario, my innocent ducklings, you receive a Hallmark card or other e-card e-mail.  You know you are not supposed to open attachments on e-mails especially those ending with .exe or .dll but on this e-mail there are none. So you feel safe. There <em>is</em> a link, however, for you to see the Hallmark card (or other e-card) someone sent you.  You click the link. Instead of an ecard, your computer fills with the Hallmark card virus, and depending on what variant you download, a pretty bad virus.</p>
<p>Your computer is now looking and acting strange.  You&#8217;re worried.  You search online for solutions.  You search for &#8220;Hallmark card virus removal&#8221;.  You get results such as the ones above.  You may luck out and click Ducktoes or another legitimate antispyware site or you may click a link to the fraudulent rogue anti-virus  Windows XP Antivirus 2008/2009 above.  Immediately your computer starts to fill with an even more lethal virus.  So now you have one bad virus and one very bad virus.</p>
<p>The fraudulent website looks like this:</p>
<div id="attachment_496" class="wp-caption aligncenter" style="width: 510px"><a href="http://ducktoes.com/myblog/wp-content/uploads/2008/11/windowsantivirus.jpg"><img class="size-full wp-image-496" title="windowsantivirus" src="http://ducktoes.com/myblog/wp-content/uploads/2008/11/windowsantivirus.jpg" alt="Bogus Antivirus Site" width="500" height="380" /></a><p class="wp-caption-text">Bogus Antivirus Site</p></div>
<p>Now Ms. Ducktoes has to go to her day job fixing computers and get back to this later.  Please be careful until then.  Let me know what&#8217;s happening to your computer right now, so I have more information on what new variants there are and the type of frustation and problems you&#8217;re having, so I can help you more effectively.</p>
<p>Click on the <a href="http://ducktoes.com/blog/2008/11/18/hallmark-and-postcardexe-virus-google-searches/#comments">Comment</a> or No comment tag below.  Or e-mail me at admin@ducktoes.com.</p>
<p>And the virus removal techniques in yesterday&#8217;s post about <a href="http://ducktoes.com/blog/2008/11/14/how-to-fix-trojanvundo-in-safe-mode/">How to Fix Vundo in Safe Mode</a> should also be quite effective agains the Hallmark Card and Windows XP Anti-virus.  Give them a try. Until later.</p>
<p>Also I&#8217;m curious.  What spyware or virus are you struggling with right now?  Or if you don&#8217;t know, what symptoms do you have?  I invite your comments. <a href="http://ducktoes.com/blog/2008/11/18/hallmark-and-postcardexe-virus-google-searches/#comments">Comment here.</a></p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_491_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/491?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_491_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=491&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fhallmark-and-postcardexe-virus-google-searches%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/hallmark-and-postcardexe-virus-google-searches/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How to Fix Trojan.Vundo in Safe Mode (and other Malware too)</title>
		<link>http://ducktoes.com/blog/individual-spywares/how-to-fix-trojanvundo-in-safe-mode/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/how-to-fix-trojanvundo-in-safe-mode/#comments</comments>
		<pubDate>Sat, 15 Nov 2008 05:00:07 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[How to remove Trojan.Vundo]]></category>
		<category><![CDATA[How to repair Vundo]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=475</guid>
		<description><![CDATA[(Added later: This method is good for removing all kinds of spyware not just Vundo.) I&#8217;ve been fixing a few Vundo-infected computers this week among all the Windows XP Antivirus 2008/2009 infections. Vundo was not hard to remove, at least not as difficult as Windows XP Antivirus, but I had to do it in Safe [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br />
(Added later:  This method is good for removing all kinds of spyware not just Vundo.)</p>
<p>I&#8217;ve been fixing a few Vundo-infected computers this week among all the Windows XP Antivirus 2008/2009 infections. Vundo was not hard to remove, at least not as difficult as Windows XP Antivirus, but I had to do it in Safe Mode.   In the normal mode, the malware kept me from going online.  Well, actually, it let me go online but while online wouldn&#8217;t let me download any antispyware or tools to fight the malware.  And if I tried to start (click on) an antivirus or antispyware, it just didn&#8217;t open.</p>
<p>To go into Safe Mode, restart your computer.</p>
<p>As the computer reboots, tap the F8 key repeatedly.  A bunch of start up options will appear; pick &#8220;Safe Mode with Networking.&#8221;  A long list of drivers will scroll down your screen in black and white.  You&#8217;ll be asked if you want to go into Safe Mode, Y or N?  Y is for Safe Mode or N is for System Restore.  You want Y.</p>
<p>If you don&#8217;t tap F8 at just the right time, you&#8217;ll end up in normal Windows.  Just reboot and try again.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Once in Safe Mode, go online, and once online, come back to this blog http://ducktoes.com/blog (or just bookmark this page) and <a href="http://www.malwarebytes.org/">click here to download Malwarebytes Antispyware.</a></p>
<p>After it&#8217;s installed, update and run Malwarebytes Antispyware.  Remove the spyware and malware.</p>
<p>Now reboot and <a href="http://downloads.andymanchesta.com/RemovalTools/SDFix.exe">download SD Fix</a>.  If your computer is still too infected to download anything, boot into <i lang="">Safe Mode with Networking</i> and download SD Fix from there.  Either way, click on the icon and run it.</p>
<p>If you aren&#8217;t in Safe Mode already, reboot into Safe Mode.</p>
<p>Click on My Computer, then on the C drive.  At the top of the C drive, look for a folder that says SD Fix.   Open it.  Inside the folder you&#8217;ll see a file that says RunThis.bat. Click on it. It will run a program to clean up the Trojans. Type Y to begin. SD Fix will delete all the spyware or trojans it comes across. Then you’ll be asked to type any key to restart the computer. Do it, type a key.</p>
<p>Your computer will reboot. As it does, it will finish cleaning up the malware it has found.</p>
<p>After this, your computer should behave much better.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_475_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/475?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_475_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=475&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fhow-to-fix-trojanvundo-in-safe-mode%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/how-to-fix-trojanvundo-in-safe-mode/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Remove Windows XP Antivirus 2008 and 2009 with Spyware Doctor</title>
		<link>http://ducktoes.com/blog/individual-spywares/remove-windows-xp-antivirus-2008-and-2009-with-spyware-doctor/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/remove-windows-xp-antivirus-2008-and-2009-with-spyware-doctor/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 13:08:34 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Windows XP Antivirus 2008/2009]]></category>
		<category><![CDATA[Fix Windows Xp antivirus]]></category>
		<category><![CDATA[remove windows x]]></category>
		<category><![CDATA[Remove Windows Xp Antivirus 2009]]></category>
		<category><![CDATA[Repair Windows XP antivirus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=224</guid>
		<description><![CDATA[[ad#new]

Ms. Ducktoes is still in a flap due Windows Xp Anti-virus 2008/2009.  Too many people are losing everything on their computers and having to reformat their hard drives.  People are losing irreplaceable family photos.  Businesses are losing all their contacts and documents at enormous expense.

If your computer is infected, you can fix it without losing your precious photos, music, business data, and files. Spyware Doctor with Antivirus is one easy, no fuss solution. And as a bonus, afterward, your computer will be safe against future infections of other types of malware.  Otherwise if the malware progresses, you'll may lose everything and end up hiring a tech to reinstall your operating system.  Save yourself a lot of trouble and cost now and by using this top-rated anti-spyware.]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes is still in a flap due Windows Xp Anti-virus 2008/2009.  Too many people are losing everything on their computers and having to reformat their hard drives.  People are losing irreplaceable family photos.  Businesses are losing all their contacts and documents at enormous expense.</p>
<p>If your computer is infected, you can fix it without losing your precious photos, music, business data, and files. Spyware Doctor with Antivirus is one easy, no fuss solution. And as a bonus, afterward, your computer will be safe against future infections of other types of malware.  Otherwise if the malware progresses, you&#8217;ll may lose everything and end up hiring a tech to reinstall your operating system.  Save yourself a lot of trouble and cost now and by using this top-rated anti-spyware.  It repairs Windows XP Antivirus and many other difficult malwares.</p>
<p>Windows XP Antivirus 2008/2009 is a rogue antivirus.  It is made by criminals in Russia.  They&#8217;re trying to get your money by invading your computer.  Their malware manufactures fake alerts about trojans and spyware right on your desktop.  Eventually it&#8217;ll wreck your operating system. And if you actually buy this fraudulent product, the owners steal your credit card numbers.  And then flood your computer with even more spyware and malware.  It can be difficult to remove and hides deep in the coding of the operating system.  Once removed, it tends to return.</p>
<p>So all you darling ducklings out there everywhere, never buy anything that creates ads or alerts right on your desktop.  No legitimate company invades your desktop (nest-top) like that.</p>
<p>The creators of this destructive malware are generating many, many versions of their malware.  This is to make it difficult for anti-spyware and anti-virus programs to catch, remove, or heal all the different variants.  Elizabeth Rood of PC Tools says, &#8220;&#8230;last count, we have defined at least 22 variants of the program being offered.  They (creators of Windows XP Antivirus 2008) update the program every week, however, so keeping up is tricky. I believe the changes in the program behavior are being randomized via an automated programming method.&#8221;</p>
<p>To get rid of this menace once and for all, this is what she and I recommend:<br />
1.  Instead of just Spyware Doctor, purchase Spyware Doctor with Antivirus.<br />
2. Update Spyware Doctor with Antivirus and then run multiple scans.<br />
3.  After running one full scan, reboot in safe mode (Restart computer, tap F8 as computer starts up, choose Safe Mode.)<br />
4.  It typically takes more than one scan to remove it.</p>
<p>I found Spyware Doctor with Antivirus very effective against Windows XP Antivirus. If you just want to get rid of this terrible danger to you computer easily and prevent future dangers of all types, then get Spyware Doctor with Antivirus. It&#8217;ll remove Windows XP Antivirus now, at this instant.  Click the small ad of Spyware Doctor below.</p>
<p style="text-align: center;"><script type="text/javascript" language="javascript" src="http://www.dpbolvw.net/2666u0xmoqt-xpq2BFEEHIJC?target=_blank&mouseover=Y"></script></p>
<p style="text-align: left;">If you need help with the install, let me know, and I&#8217;ll help you via phone or remotely over the computer.</p>
<p>Call 403-483-0105.</p>
<p style="text-align: left;">Click here for my e-mail.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_224_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/224?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_224_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=224&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fremove-windows-xp-antivirus-2008-and-2009-with-spyware-doctor%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/remove-windows-xp-antivirus-2008-and-2009-with-spyware-doctor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.858 seconds -->

