<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ducktoes Computer Repair and Spyware Blog &#187; Specific Spyware</title>
	<atom:link href="http://ducktoes.com/blog/index.php/category/specific-spyware/feed/" rel="self" type="application/rss+xml" />
	<link>http://ducktoes.com/blog</link>
	<description>Ms. Ducktoes is on her way!  Saving computers everyday!</description>
	<lastBuildDate>Thu, 26 Jan 2012 15:40:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>How to Get Rid of Virut without Reformatting</title>
		<link>http://ducktoes.com/blog/computer-repair-tools/how-to-get-rid-of-virut-without-reformatting/</link>
		<comments>http://ducktoes.com/blog/computer-repair-tools/how-to-get-rid-of-virut-without-reformatting/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 14:18:13 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Computer Repair Tools]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Virut]]></category>
		<category><![CDATA[Fix Virut]]></category>
		<category><![CDATA[How to Fix Virut]]></category>
		<category><![CDATA[How to Fix Virut without Reformatting]]></category>
		<category><![CDATA[How to Remove Virut]]></category>
		<category><![CDATA[Remove Virut]]></category>
		<category><![CDATA[Virut Virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1353</guid>
		<description><![CDATA[Ms. Ducktoes did it! I beat the dreaded Virut without reformatting. This is how I did it. The Dr. Web Cureit Live CD I spoke of in the last post didn&#8217;t work. At the beginning of the scan, it stopped everytime. So instead: I created an Ultimate Boot CD for Windows. I downloaded the image [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes did it!  I beat the dreaded Virut without reformatting. This is how I did it.</p>
<ol>
<li> The Dr. Web Cureit Live CD I spoke of in the last post didn&#8217;t work.  At the beginning of the scan, it stopped everytime. So instead:</li>
<li>I created an <a href="http://www.ubcd4win.com/">Ultimate Boot CD for Windows</a>.  I downloaded the image from the UBCD website and burned it to cd.  There are detailed instructions on the site on how to do this.</li>
<li> I booted off the cd and went on the Internet through the UBCD interface.  I downloaded <a href="http://download.cnet.com/Dr-Web-CureIt/3000-2239_4-128071.html?tag=mncol">Dr. Web Cureit</a> to the Ram drive.</li>
<li>Then from the &#8220;Run&#8221; option off the start menu I browsed to the B: Ram drive and opened  cureit.exe.</li>
<li>Dr. Web Cureit started.  I had to stop the Express scan and run the Custom scan and select the C drive or the C and D drives since I had more than one hard drive. Otherwise Dr. Web Cureit just scanned the CD.</li>
<li>I cured the files instead of deleting them.  The Virut virus changes the system files and your computer system needs them.</li>
<li>I scanned a three times this way.</li>
<li>I rebooted but the computer wouldn&#8217;t start. So I did a &#8220;repair install&#8221; with my Windows Xp cd.</li>
<li>After the Repair Install, it booted, but after the logon, the logon kept returning.  I couldn&#8217;t get past it.</li>
<li>So I booted off the UBCD and replaced the Userinit.exe file in the System32/dllcache folder.  I found another copy of it in the 1386 folder and copied and pasted.  You can search using the Windows Explorer on the UBCD disk.</li>
<li>Then I ran regedit (still off UBCD) and searched for userinit.  I found the registry keys related to userinit.  One of them was set for the logon to repeat over and over, so I changed it from &#8220;1&#8243; to &#8220;0&#8243;.</li>
<li>Then I rebooted and the computer started and the logon didn&#8217;t repeat!!</li>
<li>Immediately I went into Safe Mode and started running virus scans like crazy.  I ran Malwarebytes, AVG, SuperAntiSpyware and Dr. Web Cureit again.  And found more trojans and viruses.</li>
<li>After all the scans ran clean.  I rebooted.</li>
<li>The Virut was removed!!!  And I didn&#8217;t reformat.</li>
</ol>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1353_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1353?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1353_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1353&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fcomputer-repair-tools%2Fhow-to-get-rid-of-virut-without-reformatting%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/computer-repair-tools/how-to-get-rid-of-virut-without-reformatting/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Virus Alert:  P2Ps Spreading Dangerous Virus called Virut</title>
		<link>http://ducktoes.com/blog/alerts/virus-alert-p2ps-spreading-virut/</link>
		<comments>http://ducktoes.com/blog/alerts/virus-alert-p2ps-spreading-virut/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 14:55:53 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Peer-to-Peers]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Dangerous virus Virut]]></category>
		<category><![CDATA[Virut]]></category>
		<category><![CDATA[Warning about Virut]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1336</guid>
		<description><![CDATA[The worst virus I&#8217;ve ever seen is now making its way through Bit Torrent and Limewire and other file sharing programs. It&#8217;s called Virut. And once you have it it&#8217;s pretty much game over and time for a clean install. You&#8217;re done. At least you&#8217;re operating system is kaput. So if I were you I&#8217;d [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>The worst virus I&#8217;ve ever seen is now making its way through Bit Torrent and Limewire and other file sharing programs.  It&#8217;s called Virut.  And once you have it it&#8217;s pretty much game over and time for a clean install.  You&#8217;re done.  At least you&#8217;re operating system is kaput.  So if I were you I&#8217;d make sure your anti-virus is working and updating regularly.  And stay away from P2Ps until this settles down.  Lots of people are losing everything on their computers.  What makes Virut so nasty is that it patches itself to every executable, so everything time you run an anti-virus, it &#8220;patches itself&#8221; onto the anti-virus.  Also it changes system files, so if you &#8220;delete&#8221; instead of &#8220;cure&#8221; or &#8220;heal&#8221; them, you&#8217;ll be facing at least a Repair install.  </p>
<p>Some fixes for Virut run in Safe Mode, but on my client&#8217;s computer,  Safe Mode isn&#8217;t working.  I&#8217;m right now trying a method I saw on the Internet that uses <a href="http://www.youtube.com/watch?v=FGDl-IMOt1g">Dr. Web. Cure-it.</a></p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>    </p>
<p><map name='google_ad_map_1336_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1336?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1336_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1336&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fvirus-alert-p2ps-spreading-virut%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/virus-alert-p2ps-spreading-virut/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fix the &quot;Open With&quot; Virus</title>
		<link>http://ducktoes.com/blog/individual-spywares/fix-the-open-with-virus/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/fix-the-open-with-virus/#comments</comments>
		<pubDate>Mon, 07 Sep 2009 14:25:04 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Fix Open With Virus]]></category>
		<category><![CDATA[Open With Virus]]></category>
		<category><![CDATA[Remove Open With Virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1255</guid>
		<description><![CDATA[I just fixed an odd virus: the &#8220;Open With&#8221; Virus. Everything I tried to open including my usual anti-virus programs prompted a dialog box asking what I wanted to open the AVG with. Of course that&#8217;s silly, you can&#8217;t open AVG with another program like Microsoft Word or Adobe Reader. It kept me from doing [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I just fixed an odd virus: the &#8220;Open With&#8221; Virus. Everything I tried to open including my usual anti-virus programs prompted a dialog box asking what I wanted to open the AVG with. Of course that&#8217;s silly, you can&#8217;t open AVG with another program like Microsoft Word or Adobe Reader. It kept me from doing anything. That&#8217;s why it&#8217;s called the &#8220;Open With&#8221; virus. The virus asks, What would like to open that with? Oh, I think I&#8217;ll open Internet Explorer with Civilization 4 (I have sons). And I&#8217;ll open itunes with Instant Messenger. See, it doesn&#8217;t make sense, and moreover it doesn&#8217;t work, in fact nothing works, and you are stuck. You are deep in the doo doo of Malwareland.</p>
<div id="attachment_1854" class="wp-caption aligncenter" style="width: 243px"><a href="http://ducktoes.com/blog/wp-content/uploads/2009/09/deepdoodoo3.jpg"><img class=" wp-image-1854 " style="border-image: initial; margin-top: 5px; margin-bottom: 5px; border-width: 2px; border-color: black; border-style: solid;" title="Calgary computer repair" src="http://ducktoes.com/blog/wp-content/uploads/2009/09/deepdoodoo3.jpg" alt="A photo of giant turds from computer repair Calgary" width="233" height="175" /></a><p class="wp-caption-text">You&#39;re in the deep doodoo of Malwareland.</p></div>
<p>Some techs say you have to reformat if you get this virus, but Ms Ducktoes hates that word &#8220;reformat&#8221;. I&#8217;ve seen it make a grown man cry. And then when he cries, I cry, and then I get a sinus headache and my mascara runs down my cheeks. So I find it much better and less embarrassing to do this instead:</p>
<p>Right click on the program you want to run, such as AVG. From the choices displayed, click on &#8220;Run as&#8221; and pick your own user. There&#8217;s a box you have to uncheck too. I ran AVG and it quarantined the virus. Then I was able to do the usual virus clean up.</p>
<p><a href="http://ducktoes.com/blog/wp-content/uploads/2009/09/sickcomputer.jpg"><img class="size-full wp-image-1849 alignright" style="border-image: initial; border-width: 1px; border-color: black; border-style: solid; margin: 5px;" title="Computer repair Calgary" src="http://ducktoes.com/blog/wp-content/uploads/2009/09/sickcomputer.jpg" alt="A photo of infected computer from Calgary Computer repair" width="235" height="214" /></a></p>
<p>But if you don&#8217;t have an anti-virus on the computer already what do you do? Install <a href="http://malwarebytes.org">Malwarebytes</a> on another computer. You&#8217;ll get a set up icon on your desktop. Stick a flash drive (you can buy them at any electronics store) into the usb port and go to My Computer (Start &gt; My Computer, or just &#8220;Computer&#8221; on Vista) and you&#8217;ll see all your drives, your hard drive or drives, your dvd player, and now the flash drive. Click on the flash drive. A window will open. Now drag the set up icon of Malwarebytes into the flash drive&#8217;s window. Remove the flash drive.</p>
<p>Then put the flash drive into the infected computer. It will probably have to install as a drive. Go to My Computer. Find the Malwarebytes set-up icon. Right click on it and &#8220;Run As&#8221; your user. Let it install and run and do it&#8217;s thing.</p>
<p>After that go to this<span style="text-decoration: underline;"> <a href="http://ducktoes.com/blog/?p=1180">page on my blog, click these words here</a></span> and follow the rest of the instructions.</p>
<p>If you want, Ducktoes Computer Repair can fix your virus. <a href="http://ducktoes.com/remote.php">Click here to read more about our remote service.</a> <a href="http://ducktoes.com/book_online.php">Or click here to book remote appointment.</a> http://ducktoes.com/book_online.php We&#8217;ll get back to you.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1255_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1255?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1255_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1255&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Ffix-the-open-with-virus%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/fix-the-open-with-virus/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Trojan Horse Clicker &#8211; No My Friend Flicka.</title>
		<link>http://ducktoes.com/blog/uncategorized/trojan-horse-clicker-no-friend-flicker/</link>
		<comments>http://ducktoes.com/blog/uncategorized/trojan-horse-clicker-no-friend-flicker/#comments</comments>
		<pubDate>Sun, 30 Aug 2009 01:27:13 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[Calgary computer repair]]></category>
		<category><![CDATA[Combofix]]></category>
		<category><![CDATA[Grisoft]]></category>
		<category><![CDATA[Malwarebytes]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[Trojan horse Clicker]]></category>
		<category><![CDATA[trojan horses]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1252</guid>
		<description><![CDATA[I just cleaned up a computer, an Acer laptop, that had tons of spyware and among them was Trojan Horse Clicker. To get rid of it and the rest of the spyware I did the usual: 1.First I ran Combofix. (I did this in Safe Mode with Networking.) To get into Safe Mode, I had [...]]]></description>
			<content:encoded><![CDATA[<p>I just cleaned up a computer, an Acer laptop, that had tons of spyware and among them was Trojan Horse Clicker.   To get rid of it and the rest of the spyware I did the usual:</p>
<p>1.First I ran Combofix.  (I did this in Safe Mode with Networking.)</p>
<p>To get into Safe Mode, I had to tap F8 as the computer booted.  If you tap at just the right time, a list of options in black and white is displayed on your screen.  If you get the usual Windows boot up, you&#8217;ve missed Safe Mode so you&#8217;ll have to restart and tap again.</p>
<p>Pick <em>Safe Mode with Networking</em>.  Then you&#8217;ll see a message asking if you&#8217;re sure you want to go into Safe Mode or if you&#8217;d rather use System Restore.  Click <em>yes</em> you do want to go into Safe Mode.  In Safe Mode you can then download and run Combofix.</p>
<p>When you get to the page, you&#8217;ll have to scroll down.  I usually pick the Bleeping Computer link.. you&#8217;ll have to scroll down.  It looks like this.</p>
<div id="attachment_1260" class="wp-caption aligncenter" style="width: 433px"><a href="http://ducktoes.com/myblog/wp-content/uploads/2009/08/combofix.gif"><img class="size-medium wp-image-1260" title="combofix" src="http://ducktoes.com/blog/wp-content/uploads/2009/08/combofix-300x164.gif" alt="" width="423" height="231" /></a><p class="wp-caption-text">This is a photo of the Bleeping Computer website where you download Combofix.</p></div>
<p>Download Combofix <a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix">here.</a></p>
<p>If you can&#8217;t download or run Combofix then you have very serious virus problems so see <a href="http://ducktoes.com/blog/2008/12/17/when-spyware-gets-really-bad-what-to-do-when-you-cant-do-anything/">this post</a>.</p>
<p>After I ran Combofix, enough spyware had been removed so that I could do the following in regular Windows mode.</p>
<p>2. Downloaded and installed AVG.</p>
<p>3. Downloaded and installed Malwarebytes.</p>
<p>4. Ran Malwarebytes.  Malwarebytes caught quite a few Trojans.  Also when I ran Malwarebytes, AVG&#8217;s residential shield caught a few more things that Malwarebytes going through the files seemed to stir up.</p>
<p>4.  Ran a full scan of AVG.  The AVG is what caught our friend Trojan Horse Clicker.</p>
<p><map name='google_ad_map_1252_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1252?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1252_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1252&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Funcategorized%2Ftrojan-horse-clicker-no-friend-flicker%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/uncategorized/trojan-horse-clicker-no-friend-flicker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Virus w32/ w32 Removal Tool</title>
		<link>http://ducktoes.com/blog/specific-spyware/how-to-remove-w32-or-virus-w32/</link>
		<comments>http://ducktoes.com/blog/specific-spyware/how-to-remove-w32-or-virus-w32/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 15:20:37 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[w32]]></category>
		<category><![CDATA[w32 Removal Tool]]></category>
		<category><![CDATA[remove w32]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[w32 fasec]]></category>
		<category><![CDATA[w32 patched-kg]]></category>
		<category><![CDATA[w32 spyware]]></category>
		<category><![CDATA[w32 virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1236</guid>
		<description><![CDATA[I&#8217;ve removed viruses with W32 in their names, on hundreds of computers, and they&#8217;ve all been difficult to remove. W32 Fasec and W32-Patched kg are two of the most common and stubborn. Usually w32 are video codec or flash drive viruses. That means you got it from downloading a video codec or from an infected [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I&#8217;ve removed viruses with W32 in their names, on hundreds of computers, and they&#8217;ve all been difficult to remove. W32 Fasec and W32-Patched kg are two of the most common and stubborn.  Usually w32 are video codec or flash drive viruses.  That means you got it from downloading a video codec or from an infected flash drive or stick.  W32 means they are rootkits, embedded in the root in the system32 section of Windows, as the name w32 implies.  They aggressively disarm anti-viruses and anti-spyware by not allowing the anti-malware to run even in Safe Mode.</p>
<p>I&#8217;ve been able to run Avast in Safe Mode to make the first inroad to removal.  Then I zap them with Combofix and Malwarebytes.  That usually does it.</p>
<p>I imagine most techs reformat the hard drives of the computers infected with this virus, since a repair install doesn&#8217;t remove it. Reformatting isn&#8217;t necessary and hard on the client (that means you).  However if your tech insists, ask him or her to back up your data before reformatting. Then immediately install Malwarebytes and either AVG or AVAST on your clean install. If he won&#8217;t save your data, get a different tech and show him or her this post.  You don&#8217;t have to lose everything, really, you don&#8217;t.</p>
<p>This is what I do with anything spyware or virus w32. The w32 action plan! The W32 Removal tool! Ta da.  I boot into Safe Mode by tapping the F8 key as the computer boots up.  You have to tap at the right point or else you&#8217;ll just boot back into the normal mode, so try again if that happens.  You should get a black and white screen with several boot options.   Pick Safe Mode with Networking.  &#8220;<i lang="">With Networking</i>&#8221; means your internet will work.  (In regular plain old Safe Mode it doesn&#8217;t.)  Then you&#8217;ll get a question about whether you really want to go into Safe Mode or if you want to use System Restore.  Yes, you do want Safe Mode.  While in Safe Mode go on the Internet.  Type &#8220;avast.com&#8221; into the address bar.</p>
<p><a href="http://ducktoes.com/myblog/wp-content/uploads/2009/06/picture-12.jpg"><img src="http://ducktoes.com/blog/wp-content/uploads/2009/06/picture-12-300x46.jpg" alt="This photo shows the address bar of the Firefox browser.<br />
 Whatever browser you have, type &quot;avast.com&quot; into the address bar." title="picture-12" width="300" height="46" class="size-medium wp-image-1238" /></a> Or click <a href="http://avast.com">here</a>.  After downloading Avast, run it.  It may ask you to do a boot scan.  Say yes.  Otherwise let it startup and you&#8217;ll get the funny silver-looking interface, which looks like a radio to me. Click the update button.  The update button looks like Harry Potter&#8217;s scar or a lightening strike. After updating run Avast again.  You may have to keep going back into Safe Mode.</p>
<p>After Avast runs and gets rid of some of the w32, then download and run <a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix">ComboFix</a> and Malwarebytes.</p>
<p>With <a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix">ComboFix</a>, just follow the prompts and ignore all the dire warnings about using it without a helper, I&#8217;ve used it hundreds of times without one bad incident.  If you can&#8217;t disable your antivirus as ComboFix suggests or don&#8217;t know how to disable it (has anyone tried to disable Norton or Mcafee single-handedly?  Good luck, they&#8217;re impossible to disable especially if you&#8217;re infected with a virus) just go ahead anyway.  I do, all the time.  Your computer is terminal anyway if you don&#8217;t use ComboFix at this point and it can only help.  While Combofix runs it will install Recovery console, scan for viruses, reboot your computer and create a log file.</p>
<p>After ComboFix, use <a href="http://malwarebytes.org">Malwarebytes</a>.  I find it easy to run.  Install it, then go to the Update button, then to the Scan.  Do a quick scan first.  Then a full scan.</p>
<p>Now you&#8217;re safely on your way home from the dangerous wilds of the w32 wilderness.  You&#8217;ve fought off the w32 beast!! You&#8217;re a Ducktoes hero.  Your on your way home, your way home.</p>
<p>Let me know how it goes.</p>
<p>Ms. Da toes<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1236_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1236?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1236_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1236&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fspecific-spyware%2Fhow-to-remove-w32-or-virus-w32%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/specific-spyware/how-to-remove-w32-or-virus-w32/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Remove Starware</title>
		<link>http://ducktoes.com/blog/individual-spywares/how-to-remove-starware/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/how-to-remove-starware/#comments</comments>
		<pubDate>Sun, 21 Jun 2009 13:10:53 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Toobars]]></category>
		<category><![CDATA[how to fix Starware]]></category>
		<category><![CDATA[How to remove Starware]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[toolbars. How to remove the toolbar Starware]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1225</guid>
		<description><![CDATA[I removed Starware from a photographer&#8217;s computer this week. The computer was oppressively slow and Outlook was crashing a lot. My client couldn&#8217;t work efficiently, since the interruptions slowed down the work he could do in a day. He was sooo frustrated. Starware took a tenacious hold of the operating system. It&#8217;d installed hundreds of [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>I removed Starware from a photographer&#8217;s computer this week.  The computer was oppressively slow and Outlook was crashing a lot.  My client couldn&#8217;t work efficiently, since the interruptions slowed down the work he could do in a day. He was sooo frustrated.</p>
<p>Starware took a tenacious hold of the operating system. It&#8217;d installed hundreds of registry keys, files, and applications. The apps were running in the background, making the compute insufferably slow.  All for one harmless-looking toolbar.</p>
<p>If you must have a toolbar cluttering up your browser, use Google&#8217;s or Yahoo&#8217;s.  And indeed, it seems you must have both of them, since they are omni-present, appearing out of nowhere onto your browser with one mindless click of the mouse. It&#8217;s hard not to have them, whether you want them or not. But I digress..</p>
<p>After removing Starware, the computer acted normally and Outlook worked again.  The photographer could get on with his business.</p>
<p>Starware is a good name, since it was designed by someone much like a character out of Star Wars, not a hero like Hans Solo, but a Darth Vader who callously likes to muck up people&#8217;s lives and businesses by damaging their computers.  Someone who&#8217;s sold out to the dark side.</p>
<p>To remove Starware, I used <a href="http://malwarebytes.org">Malwarebytes</a>.  To download Malwarebytes, click <a href="http://malwarebytes.org">here</a>.  Or go there by typing http://malwarebytes.org in your browser&#8217;s address bar.  Be sure to update before you scan.</p>
<p>And take care out there.</p>
<p>Oh, baby, baby it&#8217;s a wild web.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1225_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1225?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1225_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1225&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fhow-to-remove-starware%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/how-to-remove-starware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Fix Sysguard, Win32 Patched-Kg, and Malware Alerts</title>
		<link>http://ducktoes.com/blog/specific-spyware/how-to-fix-sysguard-win32-patched-kg-and-malware-alerts/</link>
		<comments>http://ducktoes.com/blog/specific-spyware/how-to-fix-sysguard-win32-patched-kg-and-malware-alerts/#comments</comments>
		<pubDate>Mon, 18 May 2009 15:56:17 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[difficult spyware]]></category>
		<category><![CDATA[difficult virus]]></category>
		<category><![CDATA[Fix Malware Alerts]]></category>
		<category><![CDATA[fix sysguard]]></category>
		<category><![CDATA[Fix Win32 Patched Kg]]></category>
		<category><![CDATA[Remove Malware Alerts]]></category>
		<category><![CDATA[remove sysguard]]></category>
		<category><![CDATA[remove Win 32 Patched-kg]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1180</guid>
		<description><![CDATA[This week I found a new type of virus: Sysguard, Win32 Patched-Kg, and Malware Alerts difficult to remove. The usual ways of removal didn&#8217;t work since these spyware/viruses suppress ComboFix and Malwarebytes and keep them from running. I had to run Avast first. The boot scanner in Avast made the first dent in the viruses [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>This week I found a new type of virus: Sysguard, Win32 Patched-Kg, and Malware Alerts difficult to remove.   The usual ways of removal didn&#8217;t work since these spyware/viruses suppress ComboFix and Malwarebytes and keep them from running.  I had to run Avast first.  The boot scanner in Avast made the first dent in the viruses armor.  After that I could run the other programs.    I&#8217;ve been using Avast all week, for the first time on a regular basis, and am grateful for it&#8217;s effectiveness.  Avast will probably help in all viruses that suppress installation or running of anti-spyware or anti-viruses.</p>
<p>So if you have a difficult virus, follow these steps:<br />
1. Download <a href="http://www.avast.com/eng/avast_4_home.html" target="_blank")>Avast</a>.  Install and run it. It will run automatically and usually, if you have Sysguard, Win 32 Patched-Kg, or Malware Alerts, it&#8217;ll find a virus right away.  Then it will want to run a bootscan.  Let it.  The bootscan should remove enough of the virus that you can now update Avast and run it again. So make sure you Update Avast.  Click the button that looks like a lightening strike or Harry Potter&#8217;s forehead.</p>
<p>2. After updating and running Avast again, you can now download and run <a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" target="_blank")>ComboFix</a>. It will automatically delete some bad virus files.</p>
<p>3. Then download, run, and update <a href="http://malwarebytes.org/" target="_blank">Malwarebytes</a>.</p>
<p>Let me know if this works for you or if you have another suggestion or comment.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1180_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1180?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1180_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1180&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fspecific-spyware%2Fhow-to-fix-sysguard-win32-patched-kg-and-malware-alerts%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/specific-spyware/how-to-fix-sysguard-win32-patched-kg-and-malware-alerts/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>How to Remove Privacy Center</title>
		<link>http://ducktoes.com/blog/specific-spyware/how-to-remove-privacy-center/</link>
		<comments>http://ducktoes.com/blog/specific-spyware/how-to-remove-privacy-center/#comments</comments>
		<pubDate>Wed, 13 May 2009 12:45:51 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Windows XP Antivirus 2008/2009]]></category>
		<category><![CDATA[Fix Privacy Center]]></category>
		<category><![CDATA[Malwarebytes]]></category>
		<category><![CDATA[Privacy Center rogue anti-spyware]]></category>
		<category><![CDATA[Remove Privacy Center]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1173</guid>
		<description><![CDATA[The other day I fixed a computer infected with Privacy Center. The name made me laugh since the privacy offered by this rogue program is like walking naked downtown and handing out your credit card numbers, e-mail address, and cell phone number at the same time. Malwarebytes cleaned it up quite easily. All you have [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>The other day I fixed a computer infected with Privacy Center.  The name made me laugh since the privacy offered by this rogue program is like walking naked downtown and handing out your credit card numbers, e-mail address, and cell phone number at the same time.  <a href="http://malwarebytes.org">Malwarebytes</a> cleaned it up quite easily.  All you have to do is download, save, and run <a href="http://malwarebytes.org"><strong>Malwarebytes</strong></a>.  It should update automatically the first time you use it but after that you&#8217;ll need to click the Update tab manually to get the updated malware definitions.  Run Malwarebytes once a week or more to protect yourself.</p>
<p>And as always your <strong><a href="http://ducktoes.com/blog/2009/05/13/how-to-remove-privacy-center/#comments">comments</a></strong> are very welcome.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1173_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1173?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1173_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1173&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fspecific-spyware%2Fhow-to-remove-privacy-center%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/specific-spyware/how-to-remove-privacy-center/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Downandup or Conficker USB Worm Prevention and Removal</title>
		<link>http://ducktoes.com/blog/alerts/downandup-or-conficker-usb-worm-prevention-and-removal/</link>
		<comments>http://ducktoes.com/blog/alerts/downandup-or-conficker-usb-worm-prevention-and-removal/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 21:05:22 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Conficker worm]]></category>
		<category><![CDATA[Fix Conficker worm]]></category>
		<category><![CDATA[Prevent Conficker worm]]></category>
		<category><![CDATA[remove Conficker worm]]></category>
		<category><![CDATA[stop Autoruns]]></category>
		<category><![CDATA[USB worm]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1058</guid>
		<description><![CDATA[Ms. Ducktoes is really busy removing spyware and replacing power supplies today, but I&#8217;ve noticed an influx of this new worm. So I thought I should warn you. It&#8217;s called the Downandup/Conficker worm. Millions of computers are infected. To avoid getting it, turn off Autoruns on your computer. Click here to learn how to turn [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes is really busy removing spyware and replacing power supplies today,  but I&#8217;ve noticed an influx of this new worm.  So I thought I should warn you. It&#8217;s called the Downandup/Conficker worm. Millions of computers are infected.  To avoid getting it, turn off Autoruns on your computer. <a href="http://ducktoes.com/blog/2009/01/14/how-to-prevent-usb-worm/">Click here to learn how to turn off Autoruns.</a></p>
<p>To fix or remove Downandup or Conficker worm, there are these free removal tools:<br />
<a href="ftp://ftp.f-secure.com/anti-virus/tools/beta/fsmrt.zip">ftp://ftp.f-secure.com/anti-virus/tools/beta/fsmrt.zip</a><br />
<a href="ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip">ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip</a></p>
<p>Then run <a href="http://ducktoes.com/blog/2009/01/04/best-free-anti-spyware-of-2008/">the usual Malwarebytes et al as in this post on Free Anti-spyware</a> just to get rid of any remaining spyware.  More later, my chickadees.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1058_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1058?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1058_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1058&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fdownandup-or-conficker-usb-worm-prevention-and-removal%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/downandup-or-conficker-usb-worm-prevention-and-removal/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Hallmark Card Virus (Again) and the Evil AntivirusOn.com</title>
		<link>http://ducktoes.com/blog/alerts/hallmark-card-virus-again-and-antivirusoncom/</link>
		<comments>http://ducktoes.com/blog/alerts/hallmark-card-virus-again-and-antivirusoncom/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 15:44:52 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Hallmark Card Virus]]></category>
		<category><![CDATA[Rogue Anti-spyware]]></category>
		<category><![CDATA[Specific Spyware]]></category>
		<category><![CDATA[Windows XP Antivirus 2008/2009]]></category>
		<category><![CDATA[AntivirusOn.com]]></category>
		<category><![CDATA[Fix Hallmark card virus]]></category>
		<category><![CDATA[Remove Windows XP Antivirus 2008]]></category>
		<category><![CDATA[Remove Windows Xp Antivirus 2009]]></category>
		<category><![CDATA[rogue anti-virus]]></category>
		<category><![CDATA[Youtube virus]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1039</guid>
		<description><![CDATA[Ms. Ducktoes really feels for the readers whose computers have the Hallmark card virus. So many of you are still coming to this blog for a fix. This has been going on for months. Since so many of you are still getting infected, today I went on-line to do a more research. I was wondering [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Ms. Ducktoes really feels for the readers whose computers have the Hallmark card virus.  So many of you are still coming to this blog for a fix. This has been going on for months.</p>
<p>Since so many of you are still getting infected, today I went on-line to do a more research.  I was wondering if there were any new variants etc.</p>
<p>What I found troubled me:<br />
<a href="http://ducktoes.com/myblog/wp-content/uploads/2009/01/youtubevirus.gif"><img src="http://ducktoes.com/myblog/wp-content/uploads/2009/01/youtubevirus.gif" alt="This Google search result for &quot;hallmark virus&quot; leads to a Youtube video." title="youtubevirus" width="400" height="79" class="size-full wp-image-1040" /></a></p>
<p>The links lead to a Youtube video which pretends to be a Tutorial but really is an ad for AntispywareOn.com, a rogue anti-virus site that will give you&#8211;you guessed it&#8211;more spyware and viruses.  You can play the video without getting infected but don&#8217;t go to AntivirusOn.com. The video&#8217;s not much to see; it&#8217;s mostly obscured by big letters telling you to go to AntivirusOn.com. <a href="http://www.youtube.com/watch?v=KMHHXIGQEDo">Click here to see the video.</a></p>
<p><a href="http://www.eggheadcafe.com/video.aspx?videoid=129475">Now here&#8217;s a video that&#8217;s more interesting. </a> The video maker &#8220;Video search engine&#8221; infects a virtual machine with what you get on AntivirusOn.com and makes a video of the result.  And, oh dear, the result looks surprisingly familiar:  like another variant of the Windows XP Antivirus 2008/2009!</p>
<p>Ms. Ducktoes wants to stamp her (web) foot, she&#8217;s so sick of the Hallmark card virus and the Windows XP Anti-virus!!!</p>
<p>If you have the Hallmark virus, don&#8217;t go to AntivirusOn.com and even get more spyware and viruses.  I&#8217;m sure some of you have already.</p>
<p>If you need to remove the Hallmark Card virus, the Windows Xp Anti-virus 2008/2009 or any other spyware, <a href="http://ducktoes.com/blog/2009/01/04/best-free-anti-spyware-of-2008/">try this first.</a></p>
<p>If you already have bad spyware problems and can&#8217;t download the anti-spyware above<a href="http://ducktoes.com/blog/2008/11/14/how-to-fix-trojanvundo-in-safe-mode/">go here for a fix.</a></p>
<p>Good luck and as always your comments are most welcome.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1039_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1039?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1039_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1039&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Falerts%2Fhallmark-card-virus-again-and-antivirusoncom%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/alerts/hallmark-card-virus-again-and-antivirusoncom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spying on Spouses or Lovers with Keyloggers</title>
		<link>http://ducktoes.com/blog/individual-spywares/spying-on-spouses-with-keyloggers/</link>
		<comments>http://ducktoes.com/blog/individual-spywares/spying-on-spouses-with-keyloggers/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 18:47:25 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Individual Spywares]]></category>
		<category><![CDATA[Keyloggers]]></category>
		<category><![CDATA[adultery and keyloggers]]></category>
		<category><![CDATA[affairs]]></category>
		<category><![CDATA[anti-spyware]]></category>
		<category><![CDATA[infidelity]]></category>
		<category><![CDATA[Infidelity and keyloggers]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[marriage]]></category>
		<category><![CDATA[marriage counseling]]></category>
		<category><![CDATA[recovering from an affair]]></category>
		<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[spying]]></category>
		<category><![CDATA[spying on spouses]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[stop the affair]]></category>
		<category><![CDATA[stopping adultery]]></category>
		<category><![CDATA[using keyloggers secretly]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1002</guid>
		<description><![CDATA[Sometimes computer repair jobs turn into something else. Sometimes Ms. Ducktoes is sitting quietly, concentrating on a computer and the client starts to talk, and before Ms. Ducktoes can say, &#8220;I think your hard drive is going bad,&#8221; she finds herself in the middle of a sensitive personal disclosure. Other times people request services that [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Sometimes computer repair jobs turn into something else.  Sometimes Ms. Ducktoes is sitting quietly, concentrating on a computer and the client starts to talk, and before Ms. Ducktoes can say, &#8220;I think your hard drive is going bad,&#8221; she finds herself in the middle of a sensitive personal disclosure.</p>
<p>Other times people request services that Ms. Ducktoes doesn&#8217;t do.  Like installing spyware.</p>
<p>Yesterday, Friday, a man called Ms. Ducktoes.  I&#8217;ll call him Henry.  Henry said he was worried about spyware on his computer.  But when I arrived at his door, it turned out what Henry really wanted was a program that would secretly track everything done on his computer, all e-mail, all websites visited, all Instant Messenger chats.  So he&#8217;d have a backup, he said.</p>
<p>I stared.  &#8220;You want a keylogger for a backup?&#8221;</p>
<p>Henry, probably hearing the incredulity in my voice, turned pale.  &#8220;What&#8217;s a keylogger?&#8221; he said.</p>
<p> &#8220;A keylogger is a type of spyware that records every keystroke typed on the keyboard and sometimes take screenshots of websites visited and e-mails viewed.&#8221;</p>
<p>He said, &#8220;Yes, that&#8217;s it, a keylogger.&#8221;</p>
<p>When I sat down in front of his computer, the screen displayed only one user: Naomi. &#8220;Who&#8217;s Naomi?&#8221; I asked.</p>
<p>&#8220;My wife.  It&#8217;s her computer.&#8221;</p>
<p>&#8220;Does Naomi know you&#8217;re making a backup of everything she does on-line?&#8221;</p>
<p>His voice came out shaky. &#8220;Yes,&#8221; he said.</p>
<p>&#8220;Okay,&#8221; I said, &#8220;but. it can&#8217;t be secret.  It has to give Naomi a warning the keylogger is recording her every keystroke.&#8221;  I sat up straigher.  &#8220;Otherwise it&#8217;s spyware.&#8221;</p>
<p>Henry raised his voice. &#8220;But I need to see what -.&#8221;  He screwed up his face like he might cry.</p>
<p>&#8220;You need to see what she&#8217;s doing?&#8221;</p>
<p>He nodded and started to cry into his hands.  &#8220;I think she&#8217;s seeing someone.  Having an affair. She instant messages until late at night.  She takes long lunches and is really distant.  But she denies it so I need proof.&#8221;</p>
<p>I patted his shoulder.  &#8220;Oh, I&#8217;m so sorry, Henry, but surely that&#8217;s not the best way.&#8221;</p>
<p>&#8220;I&#8217;m in so much pain,&#8221; he said.</p>
<p>&#8220;Yes, I&#8217;m sure you are. That&#8217;s a terrible thing to go through.&#8221;</p>
<p>He looked up, surprised.</p>
<p>&#8220;I&#8217;ve been down a road or two,&#8221; I said.  &#8220;Or three.  But can I tell you something I&#8217;ve learned from lots of counseling?&#8221;</p>
<p>Henry nodded.</p>
<p>&#8220;Spying isn&#8217;t going to relieve your pain or solve your problems. Spying just makes you a victim, too needy, too wrapped-up in Naomi&#8217;s activities, and too desperate. You need to do something positive, something for you. Something to raise yourself out of the emotional muck.  Something to give you your dignity back.&#8221;</p>
<p>Henry nodded solemnly. &#8220;Like what?&#8221;  he said.</p>
<p>&#8220;Well, you could exercise, and get buff, or take a class in something you like, or take a trip.  Maybe get counseling.&#8221;</p>
<p>&#8220;I don&#8217;t feel like doing anything,&#8221; Henry said.</p>
<p>&#8220;No, probably not.  But doing something fun or positive would relieve your obsession about your wife a bit.  Would make you more attractive.&#8221;</p>
<p>&#8220;To Naomi?&#8221;</p>
<p>&#8220;To yourself. To heck with Naomi.&#8221;</p>
<p>He looked farway.  &#8220;Maybe I&#8217;ll go skiing for the weekend.  By myself.&#8221;</p>
<p>&#8220;Good idea,&#8221; I said.  &#8220;Now give me some computer work to do.&#8221;</p>
<p>&#8220;Why?&#8221;</p>
<p>&#8220;Because I have to charge you my minimum charge anyway.&#8221;</p>
<p>So I took Henry&#8217;s own computer back to the shop and removed 259 spyware and viruses from it and really sped up its boot time.  Then I called his cell.  He didn&#8217;t answer but he did eventually call back from a hot tub in the mountains.  His voice sounded quite serene.  He said that his wife kept calling but he wasn&#8217;t returning her calls yet.</p>
<p>I know how tempting it can be to spy on your spouse&#8217;s or partner&#8217;s computer if they seem to be straying from you and the marriage.  But its not an action that will help.  If a marriage isn&#8217;t working for you don&#8217;t need spyware to act.  Act from your own needs and desires.  Do something to enhance your interest and joy in life and the world.  Something positive and life-affirming.  Your new outlook will be attractive to others.</p>
<p>You don&#8217;t need to buy spyware to save your marriage.  An alternative might be the wonderful newsletter from <a href="http://keepyourmarriage.com/">the &#8220;Keep your Marriage&#8221;  website.</a>  I&#8217;ve found it quite helpful and interesting.  Their book was good too.  It really helped me in making it through a bad time in my marriage and life.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><map name='google_ad_map_1002_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1002?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1002_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1002&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Findividual-spywares%2Fspying-on-spouses-with-keyloggers%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/individual-spywares/spying-on-spouses-with-keyloggers/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Are you feeling like a Zombie? Then remove that Botnet!</title>
		<link>http://ducktoes.com/blog/computer-repair-tools/are-you-feeling-like-a-zombie-remove-a-botnet/</link>
		<comments>http://ducktoes.com/blog/computer-repair-tools/are-you-feeling-like-a-zombie-remove-a-botnet/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 16:57:40 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Computer Repair Tools]]></category>
		<category><![CDATA[Free Utilities]]></category>
		<category><![CDATA[Windows XP Antivirus 2008/2009]]></category>
		<category><![CDATA[fix botnet]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[free botnet tool]]></category>
		<category><![CDATA[free spyware tool]]></category>
		<category><![CDATA[free your zombie computer]]></category>
		<category><![CDATA[Remove botnet]]></category>
		<category><![CDATA[remove botnet spyware]]></category>
		<category><![CDATA[zombie]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://ducktoes.com/blog/?p=1006</guid>
		<description><![CDATA[A botnet uses spyware and malware to lure you into being one of its zombie computers. And then uses your computer for spamming, storing credit card numbers and other personal data such as passwords and account numbers, distributing illegal types of porn, and creating a its own captive and huge search and advertising network. If [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-9846570799170925";
/* 468x60, created 4/24/08 */
google_ad_slot = "2993043083";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>A botnet uses spyware and malware to lure you into being one of its zombie computers.  And then uses your computer for spamming, storing credit card numbers and other personal data such as passwords and account numbers, distributing illegal types of porn, and creating a its own captive and huge search and advertising network.  If you are part of that type of botnet, you can&#8217;t search on Google or Yahoo or other legitimate search site, you are captive to that botnet&#8217;s search engine and their dedicated services and ads.</p>
<p>Also as a zombie your computer will be strange and slow.  You&#8217;ll be forced to use a bogus search engine and ads you don&#8217;t want.  It will seem as if something has taken over your computer.  It has.  A botnet!</p>
<p>Here&#8217;s a free tool <a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/rubotted">RuBotted</a> from Trend Micro that will remove your computer from the botnet, and the botnet from your computer.</p>
<p>Ms. Ducktoes used it on a computer that was so slow it took 20 minutes to boot.   And found and removed a botnet from Russia caused by Windows XP Antivirus 2008!</p>
<p>So try it out and let me know if you discover a botnet on your computer.  <a href="http://ducktoes.com/blog/2009/01/17/are-you-feeling-like-a-zombie-remove-a-botnet/#comments">Click here to leave a comment.</a> Ms. Ducktoes wants to hear from you.</p>
<p></p>
<p><map name='google_ad_map_1006_84e23a39a0a90197'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/1006?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_1006_84e23a39a0a90197' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=1006&amp;url= http%3A%2F%2Fducktoes.com%2Fblog%2Fcomputer-repair-tools%2Fare-you-feeling-like-a-zombie-remove-a-botnet%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://ducktoes.com/blog/computer-repair-tools/are-you-feeling-like-a-zombie-remove-a-botnet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.952 seconds -->

