<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoGeekLeftBehind.com &#187; Malware</title>
	<atom:link href="http://www.nogeekleftbehind.com/category/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nogeekleftbehind.com</link>
	<description>"Building Better Geeks"</description>
	<lastBuildDate>Fri, 20 Jan 2012 16:32:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Old School Malware Attack</title>
		<link>http://www.nogeekleftbehind.com/2011/09/08/old-school-malware-attack/</link>
		<comments>http://www.nogeekleftbehind.com/2011/09/08/old-school-malware-attack/#comments</comments>
		<pubDate>Thu, 08 Sep 2011 17:25:22 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2011/09/08/old-school-malware-attack/</guid>
		<description><![CDATA[This little gem came in via email today. This is the kind of stuff that trips up users all of the time. Note: Just because an email looks like Plain Text doesn’t mean that it is.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2011%2F09%2F08%2Fold-school-malware-attack%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2011%2F09%2F08%2Fold-school-malware-attack%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>This little gem came in via email today. This is the kind of stuff that trips up users all of the time.</p>
<p><a href="http://www.nogeekleftbehind.com/Old-School-Malware_BBD1/image.png" rel="thumbnail"><img style="border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="Fake UPS email with link to malware" border="0" alt="Fake UPS email with link to malware" src="http://www.nogeekleftbehind.com/Old-School-Malware_BBD1/image_thumb.png" width="516" height="315" /></a></p>
<blockquote><p>Note: Just because an email <strong>looks</strong> like Plain Text doesn’t mean that it is. </p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2011/09/08/old-school-malware-attack/feed/</wfw:commentRss>
		<slash:comments>1117</slash:comments>
		</item>
		<item>
		<title>Have U Rebooted Yet &#8211; 045 &#8211; Mac Malware</title>
		<link>http://www.nogeekleftbehind.com/2011/05/25/have-u-rebooted-yet-045-mac-malware/</link>
		<comments>http://www.nogeekleftbehind.com/2011/05/25/have-u-rebooted-yet-045-mac-malware/#comments</comments>
		<pubDate>Wed, 25 May 2011 13:27:02 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Comics]]></category>
		<category><![CDATA[Have U Rebooted Yet]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2011/05/25/have-u-rebooted-yet-045-mac-malware/</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2011%2F05%2F25%2Fhave-u-rebooted-yet-045-mac-malware%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2011%2F05%2F25%2Fhave-u-rebooted-yet-045-mac-malware%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nogeekleftbehind.com/Have-U-Rebooted-Yet--045--Mac-Malware_8463/haveurebootedyet_045.jpg" rel="thumbnail"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="Have U Rebooted Yet - 045 - Mac Malware" border="0" alt="Have U Rebooted Yet - 045 - Mac Malware" src="http://www.nogeekleftbehind.com/Have-U-Rebooted-Yet--045--Mac-Malware_8463/haveurebootedyet_045_thumb.jpg" width="514" height="404" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2011/05/25/have-u-rebooted-yet-045-mac-malware/feed/</wfw:commentRss>
		<slash:comments>774</slash:comments>
		</item>
		<item>
		<title>How To Spot Fake AV Malware</title>
		<link>http://www.nogeekleftbehind.com/2010/10/01/how-to-spot-fake-av-malware/</link>
		<comments>http://www.nogeekleftbehind.com/2010/10/01/how-to-spot-fake-av-malware/#comments</comments>
		<pubDate>Sat, 02 Oct 2010 00:33:10 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Crazy Screen Shots]]></category>
		<category><![CDATA[Helpdesk]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2010/10/01/how-to-spot-fake-av-malware/</guid>
		<description><![CDATA[So you’re surfing the internet, minding your own business, and suddenly a message pops up that warns “you’re infected”. It is true? Sometimes. Unfortunately, these days the fake AV software looks more real than ever. Here’s a good example of some fake AV that looks fairly convincing: At first glance, a lot of people see [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2010%2F10%2F01%2Fhow-to-spot-fake-av-malware%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2010%2F10%2F01%2Fhow-to-spot-fake-av-malware%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>So you’re surfing the internet, minding your own business, and suddenly a message pops up that warns “<strong>you’re infected</strong>”. It is true? Sometimes. Unfortunately, these days the fake AV software looks more real than ever.</p>
<p>Here’s a good example of some fake AV that looks fairly convincing:</p>
<p><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb.png" width="514" height="366" /></a> </p>
<p>At first glance, a lot of people see this and believe they’re actually infected. </p>
<p>To make matters worse, even if you don’t click on the “Erase infected” button, after a few moments another window pops up:</p>
<p><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_3.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_3.png" width="502" height="351" /></a> </p>
<p>Sadly, many users click “Yes, protect my PC now” and then it’s too late.</p>
<p><strong>How Can You Tell It’s Fake?</strong></p>
<p>Other than the obvious (knowing the name of the <em>REAL</em> antivirus software you have installed and knowing what it looks like), there are numerous ways to spot the fake AV…</p>
<p><strong>Browser version:</strong>     <br />(This machine has IE8, Fake AV says IE7)     <br /><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_4.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Wrong browser version reported" border="0" alt="Wrong browser version reported" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_4.png" width="241" height="67" /></a>&#160; </p>
<p><strong>Number of drives / letters:</strong>     <br />(This machine doesn’t have a D: drive)     <br /><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_5.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Reporting infections on drives that don&#39;t exist." border="0" alt="Reporting infections on drives that don&#39;t exist." src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_5.png" width="225" height="76" /></a> </p>
<p><strong>Incorrect navigation bars:      <br /></strong>(Fake AV displays a modified Vista navigation bar on Windows 7 machine)</p>
<table border="0" cellspacing="0" cellpadding="2" width="514">
<tbody>
<tr>
<td valign="top" width="514">
<p align="center"><strong>Fake AV</strong></p>
</td>
</tr>
<tr>
<td valign="top" width="514"><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_6.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Fake AV menu" border="0" alt="Fake AV menu" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_6.png" width="504" height="71" /></a> </td>
</tr>
<tr>
<td valign="top" width="514">
<p align="center"><strong>&#160; <br />Real Windows Vista</strong></p>
</td>
</tr>
<tr>
<td valign="top" width="514"><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_7.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Real Vista menu" border="0" alt="Real Vista menu" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_7.png" width="504" height="58" /></a> </td>
</tr>
<tr>
<td valign="top" width="514">
<p align="center"><strong>&#160; <br />Real Windows 7</strong></p>
</td>
</tr>
<tr>
<td valign="top" width="514"><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_8.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Real Windows 7 menu" border="0" alt="Real Windows 7 menu" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_8.png" width="504" height="79" /></a> </td>
</tr>
</tbody>
</table>
<p>&#160;</p>
<p><strong>Typos or incorrect punctuation:</strong>     <br />(Apostrophes pointed the wrong way) </p>
<p><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_9.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Typos in dialog boxes are a clue that the software isn&#39;t legit." border="0" alt="Typos in dialog boxes are a clue that the software isn&#39;t legit." src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_9.png" width="430" height="145" /></a>&#160;</p>
<p><strong>Virus warnings that are displayed in a web page:</strong></p>
<p><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_10.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Web page pretending to be virus warnings" border="0" alt="Web page pretending to be virus warnings" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_10.png" width="504" height="71" /></a> </p>
<p><strong>Solution:</strong></p>
<p>Train your users by showing them what the <em>REAL</em> AV software looks like, and show examples what the fake software looks like. </p>
<p>The best way to show the real software in action is to trigger an actual virus alert. Then you can screenshot your current AV software. But instead of using a real virus to trip the alert, you can use the <a href="http://www.eicar.org/anti_virus_test_file.htm" target="_blank">EICAR test file</a>. </p>
<p>The EICAR is a harmless file that is available in several different file formats:    <br /><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_11.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="EICAR virus test file" border="0" alt="EICAR virus test file" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_11.png" width="418" height="143" /></a> </p>
<p>Here’s what it looks like inside the eicar.com.txt file:    <br /><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_12.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Inside the EICAR file" border="0" alt="Inside the EICAR file" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_12.png" width="504" height="135" /></a> </p>
<p>You can use the EICAR file to generate end-user documentation on what your real AV software screens look like.</p>
<p><strong>Example: Microsoft Security Essentials</strong></p>
<p>1) Initial “infection” (triggered by clicking on the eicar.com.txt file)</p>
<p><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_13.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Microsoft Security Essentials - Virus found" border="0" alt="Microsoft Security Essentials - Virus found" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_13.png" width="385" height="174" /></a> </p>
<p>2) After clicking <strong>Show details</strong></p>
<p><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_14.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Microsoft Security Essentials - Show Details" border="0" alt="Microsoft Security Essentials - Show Details" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_14.png" width="504" height="273" /></a>     </p>
<p>3) After clicking <strong>Clean computer</strong></p>
<p><a href="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_15.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Microsoft Security Essentials - Virus removed" border="0" alt="Microsoft Security Essentials - Virus removed" src="http://www.nogeekleftbehind.com/images/HowToSpotFakeAVMalware_1206D/image_thumb_15.png" width="504" height="273" /></a>     </p>
<p>You can create a one-sheet “Virus Response Document” to print out and give to your users and include your phone number on the bottom. A little education up front can save lots of lost time and expense cleaning up after an infection or fake AV software removal battle.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2010/10/01/how-to-spot-fake-av-malware/feed/</wfw:commentRss>
		<slash:comments>91</slash:comments>
		</item>
		<item>
		<title>Have U Rebooted Yet &#8211; 022 &#8211; Malware</title>
		<link>http://www.nogeekleftbehind.com/2010/07/07/have-u-rebooted-yet-022-malware/</link>
		<comments>http://www.nogeekleftbehind.com/2010/07/07/have-u-rebooted-yet-022-malware/#comments</comments>
		<pubDate>Wed, 07 Jul 2010 13:17:00 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Comics]]></category>
		<category><![CDATA[Have U Rebooted Yet]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2010/07/07/have-u-rebooted-yet-022-malware/</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2010%2F07%2F07%2Fhave-u-rebooted-yet-022-malware%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2010%2F07%2F07%2Fhave-u-rebooted-yet-022-malware%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nogeekleftbehind.com/images/HaveURebootedYet_977/haveurebootedyet_022.jpg" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" class="wlDisabledImage" title="Have U Rebooted Yet 021 - Malware (it&#39;s only funny if it doesn&#39;t happen to you)" border="0" alt="Have U Rebooted Yet 021 - Malware (it&#39;s only funny if it doesn&#39;t happen to you)" src="http://www.nogeekleftbehind.com/images/HaveURebootedYet_977/haveurebootedyet_022_thumb.jpg" width="514" height="186" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2010/07/07/have-u-rebooted-yet-022-malware/feed/</wfw:commentRss>
		<slash:comments>633</slash:comments>
		</item>
		<item>
		<title>Have U Rebooted Yet &#8211; 010</title>
		<link>http://www.nogeekleftbehind.com/2010/05/12/have-u-rebooted-yet-010/</link>
		<comments>http://www.nogeekleftbehind.com/2010/05/12/have-u-rebooted-yet-010/#comments</comments>
		<pubDate>Wed, 12 May 2010 16:04:20 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Comics]]></category>
		<category><![CDATA[Have U Rebooted Yet]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2010/05/12/have-u-rebooted-yet-010/</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2010%2F05%2F12%2Fhave-u-rebooted-yet-010%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2010%2F05%2F12%2Fhave-u-rebooted-yet-010%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nogeekleftbehind.com/images/HaveURebootedYet010_7647/haveurebootedyet_010.jpg" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Have U Rebooted Yet? 010 - Don&#39;t torrent LOST, that&#39;s what Hulu is for." border="0" alt="Have U Rebooted Yet? 010 - Don&#39;t torrent LOST, that&#39;s what Hulu is for." src="http://www.nogeekleftbehind.com/images/HaveURebootedYet010_7647/haveurebootedyet_010_thumb.jpg" width="514" height="186" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2010/05/12/have-u-rebooted-yet-010/feed/</wfw:commentRss>
		<slash:comments>757</slash:comments>
		</item>
		<item>
		<title>Free Event &#8211; Trend Micro in Cincinnati May 22, 2010</title>
		<link>http://www.nogeekleftbehind.com/2010/05/07/free-event-trend-micro-in-cincinnati-may-22-2010/</link>
		<comments>http://www.nogeekleftbehind.com/2010/05/07/free-event-trend-micro-in-cincinnati-may-22-2010/#comments</comments>
		<pubDate>Fri, 07 May 2010 18:42:44 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[Live Events]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2010/05/07/free-event-trend-micro-in-cincinnati-may-22-2010/</guid>
		<description><![CDATA[Bill Kam of Trend Micro is coming to Cincinnati to give a FREE live in-person training on Trend&#8217;s Worry Free products &#8211; best practices for install/configure and how to protect from things like “fakeav”, and new tools for the partner/IT Pro to use as well.&#160; He may cover some of the Worry Free 7 info [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2010%2F05%2F07%2Ffree-event-trend-micro-in-cincinnati-may-22-2010%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2010%2F05%2F07%2Ffree-event-trend-micro-in-cincinnati-may-22-2010%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nogeekleftbehind.com/images/FreeEventTrendMicroinCincinnatiMay222010_CEA9/image.png" rel="thumbnail"><img style="border-bottom: 0px; border-left: 0px; display: inline; margin-left: 0px; border-top: 0px; margin-right: 0px; border-right: 0px" title="image" border="0" alt="image" align="right" src="http://www.nogeekleftbehind.com/images/FreeEventTrendMicroinCincinnatiMay222010_CEA9/image_thumb.png" width="159" height="63" /></a> Bill Kam of <a href="http://us.trendmicro.com/us/home/" target="_blank">Trend Micro</a> is coming to Cincinnati to give a FREE live in-person training on Trend&#8217;s Worry Free products &#8211; best practices for install/configure and how to protect from things like “fakeav”, and new tools for the partner/IT Pro to use as well.&#160; He may cover some of the Worry Free 7 info shown recently in Taipei.&#160; There are some PPT&#8217;s comparing Trend with the competition on a level playing field showing memory and CPU utilization that he will go over.&#160; Bill will talk about all the features in Worry Free (some that many probably are not aware of).&#160; </p>
<p>After the class, you can go online and take a “Certification” test (FREE) and with passing, you can get some benefits like showing up in a search on their site for a reseller in the area, website badges and marketing materials (think SBSC program).&#160; Good stuff!</p>
<p>Lunch is included for this event!</p>
<p>Event: <strong>Cincinnati SBS SIG &#8211; Trend Micro Live Training</strong>    <br />Date: Saturday May 22, 2010    <br />Time: 9:00 AM – 4:00 PM EDT    <br />Venue: Max Technical Training     <br />4900 Parkway Drive, #160    <br />Mason, OH 45040    <br />Registration URL: <a title="http://cinpa20100522.eventbrite.com/" href="http://cinpa20100522.eventbrite.com/">http://cinpa20100522.eventbrite.com/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2010/05/07/free-event-trend-micro-in-cincinnati-may-22-2010/feed/</wfw:commentRss>
		<slash:comments>535</slash:comments>
		</item>
		<item>
		<title>Windows Black Screen Of Death (KSOD)</title>
		<link>http://www.nogeekleftbehind.com/2009/12/02/windows-black-screen-of-death-ksod/</link>
		<comments>http://www.nogeekleftbehind.com/2009/12/02/windows-black-screen-of-death-ksod/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 21:45:26 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Helpdesk]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2009/12/02/windows-black-screen-of-death-ksod/</guid>
		<description><![CDATA[The news rags are online pointing fingers about who is to blame for the latest Windows issue nicknamed the blacK Screen Of Death (KSOD). Microsoft says it’s not a patch issue, Prevx apologized for initially blaming a patch. All I know for sure is that people want it fixed. Oddly enough, about 10 minutes after [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2009%2F12%2F02%2Fwindows-black-screen-of-death-ksod%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2009%2F12%2F02%2Fwindows-black-screen-of-death-ksod%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/image.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; margin-left: 0px; border-left-width: 0px; margin-right: 0px" title="Black Screen Of Death (KSOD)" border="0" alt="Black Screen Of Death (KSOD)" align="right" src="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/image_thumb.png" width="141" height="110" /></a> The news rags are online pointing fingers about <a href="http://www.computerworld.com/s/article/9141670/Security_firm_retracts_black_screen_claims_apologizes_to_Microsoft?taxonomyId=17" target="_blank">who is to blame for the latest Windows issue nicknamed the blacK Screen Of Death (KSOD).</a> Microsoft says it’s not a patch issue, Prevx apologized for initially blaming a patch. All I know for sure is that people want it fixed. </p>
<p>Oddly enough, about 10 minutes after reading the news I got a call from a client about a workstation exhibiting similar problems:</p>
<ul>
<li>No desktop icons </li>
<li>No taskbar or start menu </li>
<li>Solid background (no wallpaper) </li>
</ul>
<p>I’m not 100% certain that this is the same issue in the KSOD reports in the news, but it sounds similar.</p>
<p><strong>WHAT <em>DIDN’T</em> WORK FOR ME</strong></p>
<ul>
<li>Launching Explorer.exe from the Task Manager </li>
<li>System Restore </li>
</ul>
<p><strong>WHAT <em>DID</em> WORK FOR ME</strong></p>
<ol>
<li>Rebooted the PC in normal mode and logged in as Administrator      </li>
<li><strong>Ctrl-Alt-Del</strong> / <strong>Task Manager        <br /></strong>      <br /><a href="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/image_3.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Launch Task Manager from Ctrl-Alt-Del" border="0" alt="Launch Task Manager from Ctrl-Alt-Del" src="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/image_thumb_3.png" width="244" height="178" /></a> </li>
<li><strong>File</strong> | <strong>New Task (Run)</strong>
<p><a href="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/image_4.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="File / Run" border="0" alt="File / Run" src="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/image_thumb_4.png" width="168" height="88" /></a> </li>
<li>Click Browse and browse to:      <br /><strong>&quot;C:\Program Files\Internet Explorer\iexplore.exe&quot;        <br /></strong>Click <strong>OK</strong>
<p><a href="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/image_5.png" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="&quot;C:\Program Files\Internet Explorer\iexplore.exe&quot;" border="0" alt="&quot;C:\Program Files\Internet Explorer\iexplore.exe&quot;" src="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/image_thumb_5.png" width="244" height="129" /></a>       </li>
<li>When Internet Explorer opened, went to the following URL and downloaded SuperAntiSpyware:      <br /><a title="http://www.superantispyware.com/" href="http://www.superantispyware.com/"><strong>http://www.superantispyware.com/</strong></a><strong>&#160; <br /></strong></li>
<li>Installed SuperAntiSpyware, ran a scan and it found the following results:
<p><a href="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/clip_image002.jpg" rel="thumbnail"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Trojan.SVCHost/Fake" border="0" alt="Trojan.SVCHost/Fake" src="http://www.nogeekleftbehind.com/images/WindowsBlackScreenOfDeathKSOD_EB6E/clip_image002_thumb.jpg" width="358" height="83" /></a>       </li>
<li>I let SuperAntiSpyware remove that trojan, rebooted, logged back in and the desktop icons, start menu and taskbar were working again. </li>
</ol>
</p>
<p>&#160;</p>
<blockquote><p>Here is the item that SuperAntiSpyware quarantined:</p>
<p>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe (Debugger &#8211; C:\Program Files\Microsoft Common\svchost.exe)</p>
</blockquote>
<p>Again, I’m <u>not</u> saying for certain that this is the same issue others are reporting, but I wanted to pass&#160; along what I found in case others see similar issues. This is what worked for me &#8211; your mileage may vary.</p>
<p><strong>UPDATE 12/2/2009:      <br /></strong>Here is the link to the Prevx KSOD cleanup tool (I haven’t tried it though):    <br /><a title="http://www.prevx.com/blog/140/Black-Screen-woes-could-affect-millions-on-Windows--Vista-and-XP.html" href="http://www.prevx.com/blog/140/Black-Screen-woes-could-affect-millions-on-Windows--Vista-and-XP.html">http://www.prevx.com/blog/140/Black-Screen-woes-could-affect-millions-on-Windows&#8211;Vista-and-XP.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2009/12/02/windows-black-screen-of-death-ksod/feed/</wfw:commentRss>
		<slash:comments>776</slash:comments>
		</item>
		<item>
		<title>Another IM Virus</title>
		<link>http://www.nogeekleftbehind.com/2009/04/09/another-im-virus/</link>
		<comments>http://www.nogeekleftbehind.com/2009/04/09/another-im-virus/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 16:30:00 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2009/04/09/another-im-virus/</guid>
		<description><![CDATA[I saw this IM virus for the first time today: WARNING&#160;– Don’t go to the URLs listed in this post, due to possible malware and NSFW content. Followed a few minutes later by: That’s from one of my sisters (so I see some phone support in my future.) She’s not signed in, so that’s a [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2009%2F04%2F09%2Fanother-im-virus%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2009%2F04%2F09%2Fanother-im-virus%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>I saw this IM virus for the first time today:</p>
<blockquote><p><font color="#ff0000"><strong>WARNING</strong>&#160;</font><font color="#000000">– Don’t go to the URLs listed in this post, due to possible malware and NSFW content.</font></p>
</blockquote>
<p><a href="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image.png" rel="thumbnail"><img title="Another IM virus on Windows Live Messenger" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="171" alt="Another IM virus on Windows Live Messenger" src="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image_thumb.png" width="372" border="0" /></a> </p>
<p>Followed a few minutes later by:   <br /><a href="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image_3.png" rel="thumbnail"><img title="image" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="61" alt="image" src="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image_thumb_3.png" width="374" border="0" /></a> </p>
<p>That’s from one of my sisters (so I see some phone support in my future.) She’s not signed in, so that’s a dead-giveaway right there.</p>
<p>At any rate, the domain information for “undelivered-emails.com” is cloaked:</p>
</p>
<p><a href="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image_4.png" rel="thumbnail"><img title="WHOIS lookup from DNSStuff.com" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="468" alt="WHOIS lookup from DNSStuff.com" src="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image_thumb_4.png" width="387" border="0" /></a> </p>
<p>Pinging either domain name resolves to IP address is 121.127.225.137, which is in Hong Kong:</p>
<p><a href="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image_5.png" rel="thumbnail"><img title="IP address lookup from DNSStuff.com" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="376" alt="IP address lookup from DNSStuff.com" src="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image_thumb_5.png" width="389" border="0" /></a> </p>
<p>As a test, I used a canary virtual machine to see if AVG Free 8.5 would block either of these sites – it didn’t. </p>
<p><strong>BOTTOM LINE     <br /></strong>Protection is necessary, but you can’t patch for everything. It comes down to end-user education. If you’re responsible for the computers in your company (or in your home if you’re a parent) you need to let folks know about IM vectors of infection and other threats. Spend the time educating, or spend a lot more time afterwards cleaning up.</p>
<p><strong>TIP     <br /></strong>One thing I do to encourage end users to “Call Before Clicking” centers around recognizing them when they make smart web surfing decisions. Example &#8211; picking up the phone immediately when getting a “your computer is infected with xyz” pop-ups instead of trying to close the windows.</p>
<p>To assist with this, I have a Microsoft Word document that I can edit called the “<em>Safe Computing Award</em>”. I customize it with the name of the client / employee and send it to them via email when they do something that avoids getting their computer infected. Sample below:</p>
<p><a href="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image_6.png" rel="thumbnail"><img title="Safe Computing Award" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="190" alt="Safe Computing Award" src="http://www.nogeekleftbehind.com/images/AnotherIMVirus_A154/image_thumb_6.png" width="244" border="0" /></a> </p>
<p>It just takes a minute or two to update the Word doc, PDF it and email it to the customer, and they have always been well received. </p>
<p>A little positive reinforcement goes a long way. <img src='http://www.nogeekleftbehind.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2009/04/09/another-im-virus/feed/</wfw:commentRss>
		<slash:comments>61</slash:comments>
		</item>
		<item>
		<title>Conficker Redux</title>
		<link>http://www.nogeekleftbehind.com/2009/03/31/conficker-redux/</link>
		<comments>http://www.nogeekleftbehind.com/2009/03/31/conficker-redux/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 20:40:06 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2009/03/31/conficker-redux/</guid>
		<description><![CDATA[Everybody is all excited about the return of Conficker on April 1, 2009, and the news media is whipping the general public up into a froth about it. Even my mom called me to ask about it. Here’s the low-down… PREVENTION: Apply the security update associated with MS08-067 (Windows 2000, XP, Vista &#38; 2008). Make [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2009%2F03%2F31%2Fconficker-redux%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2009%2F03%2F31%2Fconficker-redux%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nogeekleftbehind.com/images/ConfickerRedux_EA5C/image.png" rel="thumbnail"><img title="Conficker is gonna steal ur dataz and eat ur house!" style="border-right: 0px; border-top: 0px; display: inline; margin-left: 0px; border-left: 0px; margin-right: 0px; border-bottom: 0px" height="165" alt="Conficker is gonna steal ur dataz and eat ur house!" src="http://www.nogeekleftbehind.com/images/ConfickerRedux_EA5C/image_thumb.png" width="244" align="right" border="0" /></a> Everybody is all excited about the return of <a href="http://en.wikipedia.org/wiki/Conficker" target="_blank">Conficker</a> on April 1, 2009, and the news media is whipping the general public up into a froth about it. Even my mom called me to ask about it.</p>
<p>Here’s the low-down…</p>
<p><strong>PREVENTION:</strong></p>
<ol>
<li>Apply the security update associated with <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">MS08-067</a> (Windows 2000, XP, Vista &amp; 2008). </li>
<li>Make sure you are running up-to-date antivirus software. </li>
<li>Check for updated protections for security software or devices, such as antivirus, network-based intrusion detection systems, or host-based intrusion prevention systems. The Microsoft Active Protection Program (MAPP) provides partners with early access to Microsoft vulnerability information. For a list of partners and links to their active protections, please visit the <a href="http://www.microsoft.com/security/msrc/mapp/partners.mspx">MAPP Partners</a> page. </li>
<li>Isolate legacy systems using the methods outlined in the <a href="http://technet.microsoft.com/library/cc751251.aspx">Microsoft Windows NT 4.0 and Windows 98 Threat Mitigation Guide</a>. </li>
<li>Implement strong passwords as outlined in the <a href="http://technet.microsoft.com/library/cc736605.aspx">Creating a Strong Password Policy whitepaper</a>. </li>
<li>Disable the AutoPlay feature through the registry or using Group Policies as discussed in <a href="http://support.microsoft.com/kb/967715">Microsoft Knowledge Base Article 967715</a>.
<p>Microsoft released <a href="http://www.microsoft.com/technet/security/advisory/967940.mspx">Security Advisory 967940</a> to notify users that the updates to allow users to disable AutoPlay/AutoRun capabilities have been deployed via automatic updating channels.      </p>
<p><strong>NOTE:</strong> Windows 2000, Windows XP, and Windows Server 2003 customers must deploy the update associated with <a href="http://support.microsoft.com/kb/967715">Microsoft Knowledge Base Article 967715</a> to be able to successfully disable the AutoRun feature. Windows Vista and Windows Server 2008 customers must deploy the security update associated with Microsoft <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-038.mspx">Security Bulletin MS08-038</a> to be able to successfully disable the AutoRun feature.</li>
</ol>
<p><strong>CLEANING INFECTED SYSTEMS:</strong></p>
<ul>
<li>Use the Microsoft Windows <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&amp;displaylang=en" target="_blank">Malicious Software Removal Tool</a> (MSRT)</li>
<li>or <a href="http://www.malwarebytes.org/" target="_blank">Malwarebytes</a></li>
<li>or <a href="http://www.superantispyware.com" target="_blank">SuperAntiSpyware</a></li>
</ul>
<p>Source: <a title="http://technet.microsoft.com/en-us/security/dd452420.aspx" href="http://technet.microsoft.com/en-us/security/dd452420.aspx">http://technet.microsoft.com/en-us/security/dd452420.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2009/03/31/conficker-redux/feed/</wfw:commentRss>
		<slash:comments>852</slash:comments>
		</item>
		<item>
		<title>Antivirus XP now Antivirus Plus</title>
		<link>http://www.nogeekleftbehind.com/2008/12/08/antivirus-xp-now-antivirus-plus/</link>
		<comments>http://www.nogeekleftbehind.com/2008/12/08/antivirus-xp-now-antivirus-plus/#comments</comments>
		<pubDate>Mon, 08 Dec 2008 20:30:30 +0000</pubDate>
		<dc:creator>timbarrett</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.nogeekleftbehind.com/2008/12/08/antivirus-xp-now-antivirus-plus/</guid>
		<description><![CDATA[Like a big catfish going after a dough ball, folks are snapping up malware like it’s a $20 bill blowing across a parking lot. Specifically, we’re talking about the old “Antivirus XP”, which is now making the rounds re-branded as “Antivirus Plus”. Behold… System Tray Desktop Icon Fake Infection Alert And I’d be willing to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2008%2F12%2F08%2Fantivirus-xp-now-antivirus-plus%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nogeekleftbehind.com%2F2008%2F12%2F08%2Fantivirus-xp-now-antivirus-plus%2F&amp;style=compact&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>Like a big catfish going after a dough ball, folks are snapping up malware like it’s a $20 bill blowing across a parking lot. Specifically, we’re talking about the old “<a href="http://www.nogeekleftbehind.com/2008/08/14/spyware-antivirus-xp-2008/" target="_blank">Antivirus XP</a>”, which is now making the rounds re-branded as “Antivirus Plus”. </p>
<p>Behold…</p>
<p><em>System Tray</em></p>
<p><a href="http://www.nogeekleftbehind.com/images/AntivirusXPnowAntivirusPlus_DA0E/IMAG0047.jpg" rel="thumbnail"><img title="Antivirus Plus system tray message" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="187" alt="Antivirus Plus system tray message" src="http://www.nogeekleftbehind.com/images/AntivirusXPnowAntivirusPlus_DA0E/IMAG0047_thumb.jpg" width="471" border="0" /></a> </p>
<p><em>Desktop Icon</em></p>
<p><a href="http://www.nogeekleftbehind.com/images/AntivirusXPnowAntivirusPlus_DA0E/IMAG0048.jpg" rel="thumbnail"><img title="If you&#39;re smart, you won&#39;t run this program" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="164" alt="If you&#39;re smart, you won&#39;t run this program" src="http://www.nogeekleftbehind.com/images/AntivirusXPnowAntivirusPlus_DA0E/IMAG0048_thumb.jpg" width="202" border="0" /></a> </p>
<p><em>Fake Infection Alert</em></p>
<p><a href="http://www.nogeekleftbehind.com/images/AntivirusXPnowAntivirusPlus_DA0E/IMAG0049.jpg" rel="thumbnail"><img title="The only &#39;malicious software&#39; that needs to be removed in this picture is Antivirus Plus itself!" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="366" alt="The only &#39;malicious software&#39; that needs to be removed in this picture is Antivirus Plus itself!" src="http://www.nogeekleftbehind.com/images/AntivirusXPnowAntivirusPlus_DA0E/IMAG0049_thumb.jpg" width="487" border="0" /></a></p>
<p>And I’d be willing to bet there are entries in the Quick Launch bar and start menu as well. </p>
<blockquote><p><strong>ATTENTION PLANET EARTH!</strong></p>
<p><strong>** Antivirus XP 2008, 2009 and Antivirus Plus are SPYWARE! **</strong></p>
<p><strong>They are not helpful programs, and you certainly shouldn’t give these folks your credit card number, OK?? </strong></p>
<p><strong>Scroll down for removal instructions. Thank you! <img src='http://www.nogeekleftbehind.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </strong></p>
</blockquote>
<p>Props to Kevin Royalty [SBS-MVP] for snapping these pics on his camera phone.    </p>
<p><strong>REMOVAL     <br /></strong>According to Kevin, our old pal <a href="http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html" target="_blank">Malwarebytes</a> still gets rid of this nasty. Thanks for the heads-up Kev!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nogeekleftbehind.com/2008/12/08/antivirus-xp-now-antivirus-plus/feed/</wfw:commentRss>
		<slash:comments>1265</slash:comments>
		</item>
	</channel>
</rss>

