<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ducktoes Computer Repair and Spyware Blog &#187; Rogue Anti-spyware</title>
	<atom:link href="http://ducktoes.com/blog/index.php/category/rogue-anti-spyware/feed/" rel="self" type="application/rss+xml" />
	<link>http://ducktoes.com/blog</link>
	<description>Ms. Ducktoes is on her way!  Saving computers everyday!</description>
	<lastBuildDate>Thu, 26 Jan 2012 15:40:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Did you Fall for this Scam? You may be Entitled to a Refund.</title>
		<link>http://ducktoes.com/blog/alerts/did-you-fall-for-this-scam-you-may-be-entitled-to-a-refund/</link>
		<comments>http://ducktoes.com/blog/alerts/did-you-fall-for-this-scam-you-may-be-entitled-to-a-refund/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 15:47:18 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1833</guid>
		<description><![CDATA[&#160; According to the LA Times, victims of the Winfixer, Drive Cleaner and Antivirus XP scam are entitled to a refund.  See here.  http://latimesblogs.latimes.com/money_co/2011/12/scam-watch-computer-virus-warning-ponzi-scheme-fake-bbb-email.html. If you fall for any other anti-virus scams or have a Rogue Anti-virus or Rogue Anti-Spyware, we can help at our Calgary Virus Removal lab.]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>&nbsp;</p>
<p>According to the LA Times, victims of the Winfixer, Drive Cleaner and Antivirus XP scam are entitled to a refund.  See here.  <a href="http://latimesblogs.latimes.com/money_co/2011/12/scam-watch-computer-virus-warning-ponzi-scheme-fake-bbb-email.html">http://latimesblogs.latimes.com/money_co/2011/12/scam-watch-computer-virus-warning-ponzi-scheme-fake-bbb-email.html</a>.</p>
<p>If you fall for any other anti-virus scams or have a Rogue Anti-virus or Rogue Anti-Spyware, we can help at our <a href="http://ducktoes.com">Calgary Virus Removal</a> lab.</p>
<p><map name='google_ad_map_1833_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1833?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1833_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1833&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fdid-you-fall-for-this-scam-you-may-be-entitled-to-a-refund%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/did-you-fall-for-this-scam-you-may-be-entitled-to-a-refund/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>This Phish will Bite your Butt</title>
		<link>http://ducktoes.com/blog/alerts/rogue-antivirus-from-google-ad/</link>
		<comments>http://ducktoes.com/blog/alerts/rogue-antivirus-from-google-ad/#comments</comments>
		<pubDate>Wed, 24 Aug 2011 13:50:46 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[phish website]]></category>
		<category><![CDATA[rogue anti-virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1693</guid>
		<description><![CDATA[Here&#8217;s a youtube video from Sophos that shows how you can get infected from a Google Ad advertising Norton.  Note how on the fake Norton website the colors are yellow like Norton Antivirus or Symantec, but there&#8217;s no real name, only the word &#8220;Anti-virus,&#8221; a clue you&#8217;re not getting the real deal, but a rogue [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Here&#8217;s a youtube video from Sophos that shows how you can get infected from a Google Ad advertising Norton.  Note how on the fake Norton website the colors are yellow like Norton Antivirus or Symantec, but there&#8217;s no real name, only the word &#8220;Anti-virus,&#8221; a clue you&#8217;re not getting the real deal, but a rogue antivirus.  Be aware when going to unfamiliar sites.  In the meantime, I&#8217;ll try to let Google know this is a fraudulent website.  We call that a phish website.  Try not to go phishing, the phish ARE biting, but are biting right in the ol kazoo, meaning where it hurts most: your wallet and computer. </p>
<p>If you did buy the fake Norton from the phish website, it wouldn&#8217;t work, and would infect your computer with more viruses and spyware.</p>
<p><iframe width="560" height="345" src="http://www.youtube.com/embed/oYyx_UoaZ7E" frameborder="0" allowfullscreen></iframe></p>
<p><map name='google_ad_map_1693_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1693?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1693_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1693&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Frogue-antivirus-from-google-ad%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/rogue-antivirus-from-google-ad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to remove the hdd virus</title>
		<link>http://ducktoes.com/blog/individual-spywares/how-to-remove-the-hdd-virus/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/how-to-remove-the-hdd-virus/#comments</comments>
		<pubDate>Thu, 16 Dec 2010 13:55:48 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[HDD virus removal]]></category>
		<category><![CDATA[How to remove HDD virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1581</guid>
		<description><![CDATA[The HDD virus advertises itself as a legitimate program, a hard drive defragmenter, but it&#8217;s really malware. If you fall for their ploy while trying to defragment your hard drive, you won&#8217;t be the first, since we&#8217;re seeing many infected computers in the Ducktoes virus lab. To get rid of HDD virus: 1. Download and [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<div id="attachment_1617" class="wp-caption aligncenter" style="width: 310px"><a href="http://ducktoes.com/blog/wp-content/uploads/2010/12/hdd-defragmenter.jpg"><img class="size-medium wp-image-1617" title="hdd-defragmenter" src="http://ducktoes.com/blog/wp-content/uploads/2010/12/hdd-defragmenter-300x202.jpg" alt="" width="300" height="202" /></a><p class="wp-caption-text">This is what the HDD Virus (Malware) looks like</p></div>
<p>The HDD virus advertises itself as a legitimate program, a hard drive defragmenter, but it&#8217;s really malware. If you fall for their ploy while trying to defragment your hard drive, you won&#8217;t be the first, since we&#8217;re seeing many infected computers in the Ducktoes virus lab.</p>
<p>To get rid of HDD virus:</p>
<p>1. Download and run Malwarebytes. <a href="http://malwarebytes.org">Click here</a> to get Malwarebytes. If you have trouble downloading and installing Malwarebytes, start in Safe Mode, by tapping the F8 key while booting. Then pick &#8220;Safe Mode with Networking.&#8221; Either way, you&#8217;ll need to update and run the program. Restart the computer.</p>
<p>2. Next download and run either <a href="http://download.cnet.com/AVG-Anti-Virus-Free-Edition-2012/3000-2239_4-10320142.html">AVG</a> or <a href="http://download.cnet.com/Avira-Free-Antivirus/3000-2239_4-10322935.html">Avira</a>. These are both excellent anti-viruses and both free for home use.</p>
<p>3. Then just to be safe, download and run <a href="http://www.superantispyware.com/download.html">Super-Anti-Spyware.</a></p>
<p>You should now be HDD Virus Free.</p>
<p>The next blog post will be about good, safe legitimate defragmenters, so stay posted.</p>
<p>If you&#8217;re having trouble removing viruses from your computer and you live in Calgary, come to our shop at 902 Centre St. NE right outside downtown or give us a call. We&#8217;re <a href="http://www.ducktoes.com">Ducktoes Calgary Computer Repair</a> and <a href="http://ducktoes.com/virus_removal.php">Virus Removal</a>.</p>
<p>Outside of Calgary, you can use Bleeping Computer to fix your computer for free.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>If you need <a href="http://ducktoes.com">computer repair click here</a> or <a href="http://ducktoes.com/business_support.php">IT business services click here.</a></p>
<p><map name='google_ad_map_1581_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1581?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1581_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1581&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fhow-to-remove-the-hdd-virus%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/how-to-remove-the-hdd-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hallmark Card Virus (Again) and the Evil AntivirusOn.com</title>
		<link>http://ducktoes.com/blog/alerts/hallmark-card-virus-again-and-antivirusoncom/</link>
		<comments>http://ducktoes.com/blog/alerts/hallmark-card-virus-again-and-antivirusoncom/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 15:44:52 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Windows XP Antivirus 2008/2009]]></category>
		<category><![CDATA[AntivirusOn.com]]></category>
		<category><![CDATA[Fix Hallmark card virus]]></category>
		<category><![CDATA[Remove Windows XP Antivirus 2008]]></category>
		<category><![CDATA[Remove Windows Xp Antivirus 2009]]></category>
		<category><![CDATA[rogue anti-virus]]></category>
		<category><![CDATA[Youtube virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1039</guid>
		<description><![CDATA[Ms. Ducktoes really feels for the readers whose computers have the Hallmark card virus. So many of you are still coming to this blog for a fix. This has been going on for months. Since so many of you are still getting infected, today I went on-line to do a more research. I was wondering [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes really feels for the readers whose computers have the Hallmark card virus.  So many of you are still coming to this blog for a fix. This has been going on for months.</p>
<p>Since so many of you are still getting infected, today I went on-line to do a more research.  I was wondering if there were any new variants etc.</p>
<p>What I found troubled me:<br />
<a href="http://ducktoes.com/myblog/wp-content/uploads/2009/01/youtubevirus.gif"><img src="http://ducktoes.com/myblog/wp-content/uploads/2009/01/youtubevirus.gif" alt="This Google search result for &quot;hallmark virus&quot; leads to a Youtube video." title="youtubevirus" width="400" height="79" class="size-full wp-image-1040" /></a></p>
<p>The links lead to a Youtube video which pretends to be a Tutorial but really is an ad for AntispywareOn.com, a rogue anti-virus site that will give you&#8211;you guessed it&#8211;more spyware and viruses.  You can play the video without getting infected but don&#8217;t go to AntivirusOn.com. The video&#8217;s not much to see; it&#8217;s mostly obscured by big letters telling you to go to AntivirusOn.com. <a href="http://www.youtube.com/watch?v=KMHHXIGQEDo">Click here to see the video.</a></p>
<p><a href="http://www.eggheadcafe.com/video.aspx?videoid=129475">Now here&#8217;s a video that&#8217;s more interesting. </a> The video maker &#8220;Video search engine&#8221; infects a virtual machine with what you get on AntivirusOn.com and makes a video of the result.  And, oh dear, the result looks surprisingly familiar:  like another variant of the Windows XP Antivirus 2008/2009!</p>
<p>Ms. Ducktoes wants to stamp her (web) foot, she&#8217;s so sick of the Hallmark card virus and the Windows XP Anti-virus!!!</p>
<p>If you have the Hallmark virus, don&#8217;t go to AntivirusOn.com and even get more spyware and viruses.  I&#8217;m sure some of you have already.</p>
<p>If you need to remove the Hallmark Card virus, the Windows Xp Anti-virus 2008/2009 or any other spyware, <a href="http://ducktoes.com/blog/2009/01/04/best-free-anti-spyware-of-2008/">try this first.</a></p>
<p>If you already have bad spyware problems and can&#8217;t download the anti-spyware above<a href="http://ducktoes.com/blog/2008/11/14/how-to-fix-trojanvundo-in-safe-mode/">go here for a fix.</a></p>
<p>Good luck and as always your comments are most welcome.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1039_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1039?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1039_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1039&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fhallmark-card-virus-again-and-antivirusoncom%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/hallmark-card-virus-again-and-antivirusoncom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Windows XP Antivirus 2008/2009</title>
		<link>http://ducktoes.com/blog/computer-repair-tools/how-to-get-rid-of-windows-xp-antivirus-20082009/</link>
		<comments>http://ducktoes.com/blog/computer-repair-tools/how-to-get-rid-of-windows-xp-antivirus-20082009/#comments</comments>
		<pubDate>Sat, 11 Oct 2008 18:34:38 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Computer Repair Tools]]></category>
		<category><![CDATA[Free Utilities]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[Windows XP Antivirus 2008/2009]]></category>
		<category><![CDATA[Remove Windows XP Antivirus 2008]]></category>
		<category><![CDATA[Remove Windows Xp Antivirus 2009]]></category>
		<category><![CDATA[Windows Antivirus XP 2008]]></category>
		<category><![CDATA[Windows Antivirus XP 2008 fix]]></category>
		<category><![CDATA[Windows Antivirus XP 2009]]></category>
		<category><![CDATA[Windows Antivirus XP 2009 fix]]></category>
		<category><![CDATA[Windows XP Antivirus removal]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=187</guid>
		<description><![CDATA[If you are one of the millions of people whose computers are infested with the nasty malware Windows Antivirus XP 2008/2009, don&#8217;t despair. It&#8217;s hard to remove but can be done. I&#8217;ve fixed it in four computers now. I tried many different things, but I had the greatest success with SD Fix and Malwarebytes. Download [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>If you are one of the millions of people whose computers are infested with the nasty malware Windows Antivirus XP 2008/2009, don&#8217;t despair.  It&#8217;s hard to remove but can be done.  I&#8217;ve fixed it in four computers now.   I tried many different things, but I had the greatest success with SD Fix and Malwarebytes.</p>
<p>Download SD Fix by clicking <a href="http://downloads.andymanchesta.com/RemovalTools/SDFix.exe">here.</a> Then you&#8217;ll need to reboot into Safe Mode by restarting your computer.   As the computer starts up, tap the F8 key several times. If you tap it at the right time, you&#8217;ll a screen with several options will appear.  One will be Safe Mode.  Choose Safe Mode.  Next, after a list of drivers is displayed in black and white on your screen, you&#8217;ll be asked if you want to go into Safe Mode (Y) or if you want to use System Recovery (N).  Pick Y for Safe Mode.</p>
<p>After Windows has started.  Go to My Computer and find the C: drive.  Double-click it, so it will open.  Look for a folder called SD Fix. Inside SD Fix will be a file called RunThis.bat.  Click on it.  It will run a program to clean up the Trojans.  Type Y to begin.  SD Fix will delete all the spyware or trojans it comes across.  Then you&#8217;ll be asked to type any key to restart the computer.  Do it, type a key.</p>
<p>Your computer will reboot.  As it does, it will finish cleaning up the malware it has found.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Next download <a href="http://www.malwarebytes.org/mbam.php">Malwarebytes.</a> Update it and run it. It is pretty straight-forward.</p>
<p>You may have to run the above two programs several times to finally get rid of this nasty of all nasties.</p>
<p>If, after removal you find you&#8217;re missing your screensaver tab, you can go to my <a href="http://ducktoes.com/blog/2008/10/05/missing-screensaver-tab/">this post</a> to fix it.  To see if you&#8217;re missing your screensaver tab, go to Control Panel, Display.  One of the tabs should be Screensaver.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>If you were unfortunate enough to buy this rogue antispyware, you need to call your bank and get a new credit card number.  Also you should stop payment on your purchase.</p>
<p>If you want help, and your computer still has the ability go on the Internet. I can fix your computer remotely.  Call 403-483-0105 during the day (Mountain Standard Time.)</p>
<p><script type="text/javascript" language="javascript" src="http://www.dpbolvw.net/2666u0xmoqt-xpq2BFEEHIJC?target=_blank&mouseover=Y"></script></p>
<p><map name='google_ad_map_187_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/187?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_187_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=187&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fcomputer-repair-tools%2Fhow-to-get-rid-of-windows-xp-antivirus-20082009%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/computer-repair-tools/how-to-get-rid-of-windows-xp-antivirus-20082009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Ad Agent BN</title>
		<link>http://ducktoes.com/blog/alerts/ad-agent-bn/</link>
		<comments>http://ducktoes.com/blog/alerts/ad-agent-bn/#comments</comments>
		<pubDate>Sun, 28 Sep 2008 14:58:59 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Ad Agent BN]]></category>
		<category><![CDATA[Free AVG 8]]></category>
		<category><![CDATA[Purchase Spyware Doctor]]></category>
		<category><![CDATA[Remove Ad Agent BN]]></category>
		<category><![CDATA[Remove anti-spyware]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=118</guid>
		<description><![CDATA[Ms. Ducktoes now has eat her words, and take back what she said about Grisoft&#8217;s free AVG 8 in her last blog. AVG has proved to be a real trooper (a State Trooper even or an RCMP Mountie!) against the criminal and fraudulent Ad Agent BN. This week the malware has been extremely difficutl to [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes now has eat her words, and take back what she said about Grisoft&#8217;s free AVG 8 in her last blog. AVG has proved to be a real trooper (a State Trooper even or an RCMP Mountie!) against the criminal and fraudulent Ad Agent BN.</p>
<p>This week the malware has been extremely difficutl to get rid of.  Ad Agent BN has been one of the worst.  </p>
<p>Ad Agent BN was on a client&#8217;s computer, along with several other related Trojans.  The client, a friendly twenty-something young man named Matt, had somehow gotten this rogue anti-spyware on his computer.  At first the rogue program ran fake warning pop-ups on his desktop saying the computer had spyware.  But much worse it then locked up the Matt&#8217;s Control Panel, Start menu, and Windows Explorer.  Also Run and Search were not accessible. </p>
<p>Matt, a student, needed to turn in his assignments.  They were not backed up.  The computer was going down fast along with Matt&#8217;s marks.  I took out the hard drive of his computer and connected it to another computer and ran Spy Sweeper, Avira, and Avast! on the mounted disk.  They found several viruses and trojan horses.  I also ran regedit by mounting the hive of the harddrive and deleted some infected keys.  However when I reconnected the hard drive to Matt&#8217;s computer, the spyware and viruses were still there.  And they were active!!</p>
<p>Ms. Ducktoes, now in a tizzy about Matt&#8217;s marks, not to mention his photos and music, had to do something more.  Ducktoes to the rescue!  </p>
<p>This is what worked.  You can do it too:</p>
<p>1. Boot into Safe Mode with Networking.  To do this: Restart the computer.  Tap the the F8 key several times while the computer boots up. When you get to the screen with several booting options select Safe Mode with Networking.  </p>
<p>2. After Windows starts, then download PC Tools Spyware Doctor, purchase, update it, and run the scan.  </p>
<p><img src="http://www.lduhtrp.net/image-3158811-10540127" alt="" border="0" height="40" width="150" /></a></p>
<p>3. Restart the computer, let it boot into regular mode several times, restart it after each scan as Spyware Doctor recommends.  <a href="http://www.anrdoezrs.net/click-3158811-10540127" target="_top"</a></p>
<p>4. Boot back into Safe Mode with Networking. Download AVG free.<a href="http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html"> Download AVG 8 free</a> for home users.   </p>
<p>5. AVG doesn&#8217;t update in Safe Mode.  So restart the computer into regular mode.  Update AVG.  Now run Spyware Doctor.  While Spyware Doctor is running the Avg Shields will kick into effect and remove the processes.  Using the two programs together will get rid of the Ad Agent BN.  </p>
<p>I know that the programs during install tell you that it&#8217;s not good to have two anti-viruses running at the same time but it worked!!</p>
<p>So I&#8217;m now using free AVG 8 again for all my clients.  </p>
<p>Let me know&#8211;click the Comments link below&#8211; if this works for you.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_118_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/118?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_118_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=118&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fad-agent-bn%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/ad-agent-bn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Make Sure your Anti-virus is Working</title>
		<link>http://ducktoes.com/blog/how-to-speed-up-your-computer/make-sure-your-anti-virus-is-working/</link>
		<comments>http://ducktoes.com/blog/how-to-speed-up-your-computer/make-sure-your-anti-virus-is-working/#comments</comments>
		<pubDate>Mon, 05 May 2008 08:45:25 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[How to Speed up your Computer]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/2008/05/05/make-sure-your-anti-virus-is-working-2/</guid>
		<description><![CDATA[Now Ms. Ducktoes wants you to be a get all your ducks in a row and make sure your anti-virus software is working, or if you&#8217;re too much of a newbie to understand or know what you&#8217;re doing yet, get a friend or co-worker to help you. And to train you. Or hire a techie [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Now Ms. Ducktoes wants you to be a get all your ducks in a row and make sure your anti-virus software is working, or if you&#8217;re too much of a newbie to understand or know what you&#8217;re doing yet, get a friend or co-worker to help you.  And to train you.  Or hire a techie to check it and train.  Ignorance is not bliss when it comes to computers.</p>
<p>1. Make sure your anti-virus is downloading updates regularly and running scans automatically and that if it is a paid subscription, that you have paid on time. Don&#8217;t be without working anti-virus software for one nano-second.  It is like tossing your computer out a second story window.  The result&#8217;s not pretty. If you are fond of your computer or what is on it, take charge.  </p>
<p>Also a reader of this blog who really knows his stuff has recommended <a target="_blank" href="http://www.free-av.com/">Avira</a> for an excellent anti-virus software. Here&#8217;s the link.  I used it on a client&#8217;s computer and it worked well.  It found and removed viruses and didn&#8217;t use up all the computer&#8217;s resources.  That&#8217;s called having a small footprint. And it&#8217;s free for personal, home use.   Don&#8217;t put it off.  Here&#8217;s a link to his <a href="http://ducktoes.com/blog/2008/04/27/opera-is-better-reader-claims/trackback/">comments</a> (you&#8217;ll have to scroll down).</p>
<p>2. Also use a different browser besides Internet Explorer.  Use <a href="http://www.mozilla.com/en-US/firefox/">Firefox</a> or <a href="http://www.opera.com/">Opera.</a></p>
<p>3. And after you have done all that, get anti-spyware too.  Click here to see how to do that.</p>
<p>Anti-virus, anti-spyware, <a href="http://www.mozilla.com/en-US/firefox/">Firefox</a> or <a href="http://www.opera.com/">Opera</a>, and you&#8217;ve protected your computer, your wallet, your identity.</p>
<p>For more information click <a href="http://ducktoes.com/blog/how-to-protect-yourself-from-spyware-and-viruses-2/">here.</a>
</p>
<p>For you techies among my readers, always make sure the client has working and up-to-date anti-virus and anti-spyware.  Do this check as part of your routine.  Tell them where they are amiss and install both if necessary. I recommend both manual anti-spyware such as Spybot and Ad-aware SE and one that runs in real time.  Read the next post on this blog for more hints for techies.</p>
<p>As always <a href="http://www.ducktoes.com">Ducktoes</a> to the rescue!!  If you live in the Calgary area give us a shout or even if you don&#8217;t.
</p>
<p>Ta ta for now.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_80_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/80?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_80_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=80&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fhow-to-speed-up-your-computer%2Fmake-sure-your-anti-virus-is-working%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/how-to-speed-up-your-computer/make-sure-your-anti-virus-is-working/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win32.Renos</title>
		<link>http://ducktoes.com/blog/rogue-anti-spyware/win32renos/</link>
		<comments>http://ducktoes.com/blog/rogue-anti-spyware/win32renos/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 14:03:26 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[Safestarts]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Spyware Doctor]]></category>
		<category><![CDATA[Win32 Renos]]></category>
		<category><![CDATA[Zlob download]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/2008/03/10/57/</guid>
		<description><![CDATA[Today I&#8217;m removing (from an Acer laptop) a trojan called Win32.Renos. It causes false alerts on the desktop purporting to be from Windows. If you click on the alert, the trojan then downloads a rogue anti-spyware called Win SpyControl, AntiSpy Kit, and Virus Ranger. The alert looks like this or some other warning: The rogue [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 110x32, created 1/21/08 */
google_ad_slot = "9211795734";
google_ad_width = 110;
google_ad_height = 32;
google_cpa_choice = ""; // on file
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Today I&#8217;m removing (from an Acer laptop) a trojan called Win32.Renos.  It causes false alerts on the desktop purporting to be from Windows.  If you click on the alert, the trojan then  downloads a rogue anti-spyware called Win SpyControl, AntiSpy Kit, and Virus Ranger.</p>
<p>The alert looks like this or some other warning:  <div id="attachment_107" class="wp-caption aligncenter" style="width: 414px"><a href="http://ducktoes.com/myblog/wp-content/uploads/2008/09/winrenos.jpg"><img src="http://ducktoes.com/myblog/wp-content/uploads/2008/09/winrenos.jpg" alt="This is a photo of the alert that Win32 Renos causes to pop-up on your desktop." title="winrenos" width="404" height="197" class="size-full wp-image-107" /></a><p class="wp-caption-text">This is a photo of the alert that Win32 Renos causes to pop-up on your desktop.</p></div></p>
<p>The rogue anti-spyware seems to be associated with the Zlob download trojan too and a web address  http://www.safestarts.com/test/?c=440785. (Warning, don&#8217;t go to that site!!)</p>
<p>I removed it using <a href="http://ducktoes.com/blog/how-to-protect-yourself-from-spyware-and-viruses-2/">Spy bot and Spyware Doctor.</a></p>
<p><a href="http://www.microsoft.com/security/encyclopedia/details.aspx?name=Win32%2fRenos">Here&#8217;s</a> what Microsoft says about this spyware.  Microsoft associates Win32.renos with SpySheriff group of rogue anti-spyware products.</p>
<p>Whichever rogue anti-spyware Win32.renos is linked to, they all do the same thing.  They attempt to get you to download and pay for bogus anti-spyware that is really spyware itself.  This is fraud. It also infests your computer with lots of dangerous spyware.</p>
<p><a href="http://www.ducktoes.com">Ducktoes</a> to the rescue!! Please leave a comment if you have more to add about this problem or any questions.</p>
<div id="attachment_107" class="wp-caption aligncenter" style="width: 414px"><a href="http://ducktoes.com/myblog/wp-content/uploads/2008/09/winrenos.jpg"><img src="http://ducktoes.com/myblog/wp-content/uploads/2008/09/winrenos.jpg" alt="This is a photo of the alert that Win32 Renos causes to pop-up on your desktop." title="winrenos" width="404" height="197" class="size-full wp-image-107" /></a><p class="wp-caption-text">This is a photo of the alert that Win32 Renos causes to pop-up on your desktop.</p></div>
<p><map name='google_ad_map_57_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/57?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_57_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=57&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Frogue-anti-spyware%2Fwin32renos%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/rogue-anti-spyware/win32renos/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>An Excellent Spyware Reference</title>
		<link>http://ducktoes.com/blog/computer-repair-tools/an-excellent-spyware-reference/</link>
		<comments>http://ducktoes.com/blog/computer-repair-tools/an-excellent-spyware-reference/#comments</comments>
		<pubDate>Tue, 26 Feb 2008 16:08:59 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Computer Repair Tools]]></category>
		<category><![CDATA[Definition of Spyware]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/2008/02/26/an-excellent-spyware-reference/</guid>
		<description><![CDATA[I&#8217;m excited!! I&#8217;ve been reading the article on Spyware in Wikipedia. It&#8217;s excellent. If you want in depth knowledge about what malware is and does, read it. The photo on the page shows a browser overloaded with toolbars. If you have unwanted toolbars on your browser window then that is one indication you have spyware. [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script><br />
I&#8217;m excited!! I&#8217;ve been reading the article on <a href="http://en.wikipedia.org/wiki/Spyware">Spyware</a> in Wikipedia.  It&#8217;s excellent.  If you want in depth knowledge about what malware is and does, read it.</p>
<p>The photo on the page shows a browser overloaded with toolbars.  If you have unwanted toolbars on your browser window then that is one indication you have spyware. See <a href="http://ducktoes.com/blog/about/">here</a> how to get rid of it.<br />
Or if you live in Calgary, <a href="http://www.ducktoes.com">Ducktoes</a> can help.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_52_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/52?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_52_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=52&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fcomputer-repair-tools%2Fan-excellent-spyware-reference%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/computer-repair-tools/an-excellent-spyware-reference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You are NOT my Sunshine, my Only Sunshine</title>
		<link>http://ducktoes.com/blog/rogue-anti-spyware/you-are-not-my-sunshine-my-only-sunshine/</link>
		<comments>http://ducktoes.com/blog/rogue-anti-spyware/you-are-not-my-sunshine-my-only-sunshine/#comments</comments>
		<pubDate>Fri, 26 Oct 2007 14:24:29 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Rogue Anti-spyware]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/2007/10/26/you-are-not-my-sunshine-my-only-sunshine/</guid>
		<description><![CDATA[A new rogue anti-spyware has just crested over the cyber-horizon. By rogue anti-spyware, I mean a program that is supposed to get rid of spyware, but is actually spyware and malware itself. SunshineSpy is this decidedly unsunshiny program. SunshineSpy gives you fake infection warnings and dire security alerts and uses rootkits to hide its dastardly [...]]]></description>
			<content:encoded><![CDATA[<p>A new rogue anti-spyware has just crested over the cyber-horizon.  By rogue anti-spyware, I mean a program that is supposed to get rid of spyware, but is actually spyware and malware itself.  SunshineSpy is this decidedly unsunshiny program.</p>
<p>SunshineSpy gives you fake infection warnings and dire security alerts and uses rootkits to hide its dastardly and fraudulent doings from legitimate anti-spyware programs.  It preys on the newbie and untrained computer user.</p>
<p>It is surprisingly easy to get rid of, however.  Just go to your green start button on the bottom left of your computer screen.  From there go to Control Panel and then to:  Add and Remove Programs. From the list of programs that will eventually appear find SunshineSpy, and click the button to remove it.  Restart your computer.</p>
<p><map name='google_ad_map_31_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/31?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_31_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=31&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Frogue-anti-spyware%2Fyou-are-not-my-sunshine-my-only-sunshine%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/rogue-anti-spyware/you-are-not-my-sunshine-my-only-sunshine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&quot;Rogue and Suspect&quot; Anti-Spyware</title>
		<link>http://ducktoes.com/blog/rogue-anti-spyware/rogue-and-suspect-anti-spyware-2/</link>
		<comments>http://ducktoes.com/blog/rogue-anti-spyware/rogue-and-suspect-anti-spyware-2/#comments</comments>
		<pubDate>Mon, 04 Dec 2006 15:54:09 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Rogue Anti-spyware]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/2006/12/04/rogue-and-suspect-anti-spyware-2/</guid>
		<description><![CDATA[All anti-spyware is not equal. Many do not remove spyware reliably. Some show false positives and push their products in a high pressure way. A few actually come bundled with spyware or malware. The Spyware Warrior Website has a list of rogue, suspect anti-spyware and websites. Check it out before you purchase and download any [...]]]></description>
			<content:encoded><![CDATA[<p>All anti-spyware is not equal. Many do not remove spyware reliably. Some show false positives and push their products in a high pressure way. A few actually come bundled with spyware or malware. The <a href="http://spywarewarrior.com/rogue_anti-spyware.htm#ss_note">Spyware Warrior Website</a> has a list of rogue, suspect anti-spyware and websites. Check it out before you purchase and download any anti-spyware.</p>
<p>There are some excellent anti-spyware programs that are free for home users. See other postings in this blog. If you want help, Ducktoes will provide the anti-spyware for your computer(s). We make on-site visits to Calgary area homes and businesses. Call (403)287-0105 or <a href="mailto:admin@ducktoes.com">e-mail</a> me.</p>
<p><map name='google_ad_map_18_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/18?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_18_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=18&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Frogue-anti-spyware%2Frogue-and-suspect-anti-spyware-2%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/rogue-anti-spyware/rogue-and-suspect-anti-spyware-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.850 seconds -->

