<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PC CyberTek &#187; virus</title>
	<atom:link href="http://www.pccybertek.com/tag/virus/feed" rel="self" type="application/rss+xml" />
	<link>http://www.pccybertek.com</link>
	<description>The cyberspace visitor's information center</description>
	<lastBuildDate>Wed, 12 May 2010 21:57:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>iTunes Store &amp; DHL &amp; UPS e-mail Virus</title>
		<link>http://www.pccybertek.com/2010/05/itunes-store-dhl-ups-e-mail-virus</link>
		<comments>http://www.pccybertek.com/2010/05/itunes-store-dhl-ups-e-mail-virus#comments</comments>
		<pubDate>Fri, 07 May 2010 18:35:22 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[e-mail]]></category>
		<category><![CDATA[itunes]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[DHL]]></category>
		<category><![CDATA[UPS]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=407</guid>
		<description><![CDATA[It&#8217;s been a busy 48 hours for the e-mail virus ruffians. I suspect with Mother&#8217;s Day approaching it will only get worse. Keep an eye out for fake Mother&#8217;s Day e-cards and the like. The following examples were all received in the last 48 hours. The first one I have a feeling might trick a [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a busy 48 hours for the e-mail virus ruffians. I suspect with Mother&#8217;s Day approaching it will only get worse. Keep an eye out for fake Mother&#8217;s Day e-cards and the like. The following examples were all received in the last 48 hours.</p>
<p>The first one I have a feeling might trick a few people. It claims to be from the iTunes Store..</p>
<blockquote><p>
From: iTunes Store [certificate@itunes.com]<br />
Subject: Thank you for buying iTunes Gift Certificate!</p>
<p>Hello!</p>
<p>You have received an iTunes Gift Certificate in the amount of $50.00 You can find your certificate code in attachment  below. </p>
<p>Then you need to open iTunes. Once you verify your account, $50.00 will be credited to your account, so you can start buying music, games, video  right away.</p>
<p>iTunes Store.</p>
</blockquote>
<p>The payload is in the attachment <strong>iTunes_certificate_497.zip</strong> which contains the file <strong>iTunes_certificate_497.exe</strong><br />
ESET NOD32 identifies this as Win32/Oficla.GT trojan</p>
<p>Next up, are 3 variations of the, we missed you and couldn&#8217;t deliver something scam.</p>
<blockquote><p>
From: DHL Support Kimberly Parsons [delivery@dhl-usa.com]<br />
Subject: DHL delivery problem Nr22755.</p>
<p>Hello! </p>
<p>We were not able to deliver the postal package sent on the 8th of March in time because the addressee&#8217;s address is not correct.<br />
Please print out the invoice copy attached and collect the package at our department.</p>
<p>DHL Customer Services.
</p></blockquote>
<blockquote><p>
From: DHL Manager Javier Stratton [courier@dhl-usa.com]<br />
Subject: DHL delivery problem Nr00684.</p>
<p>Dear customer! </p>
<p>We were not able to deliver the postal package which was sent on the 21st of February in time because the addressee&#8217;s address is wrong.<br />
Please print out the invoice copy attached and collect the package at our office.</p>
<p>DHL Express Services.
</p></blockquote>
<blockquote><p>
From: Service Manager Chandra Morales [manager@ups.com]<br />
Subject: UPS Delivery Problem NR 52979.</p>
<p>Dear customer! </p>
<p>We failed to deliver postal package which was sent on the 15th of February in time because the recipient’s address is erroneous.<br />
Please print out the invoice copy attached and collect the package at our department.</p>
<p>DHL Customer Services.
</p></blockquote>
<p>The attachments for these were:<br />
<strong>DHL_invoice_6817.zip</strong> which is Win32/Oficla.GQ trojan<br />
<strong>DHL_invoice_2817.zip</strong> which also is Win32/Oficla.GQ trojan<br />
<strong>UPS_invoice_5978.zip</strong> &#8211; which is a variant of Win32/Injector.BNG trojan</p>
<p>Remember to keep an eye out for fake Mother&#8217;s day scams too.</p>
<!-- AdSense Now! V1.77 -->
<!-- Post[count: 2] -->
<div class="adsense adsense-leadout" style="float:right;margin: 12px;"><script type="text/javascript"><!--
google_ad_client = "pub-8003034946906995";
/* Cybertek Post Gray 180x150 */
google_ad_slot = "3953975798";
google_ad_width = 180;
google_ad_height = 150;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div>]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2010/05/itunes-store-dhl-ups-e-mail-virus/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Fake Apple Store Order E-mail</title>
		<link>http://www.pccybertek.com/2010/04/fake-apple-store-order-e-mail</link>
		<comments>http://www.pccybertek.com/2010/04/fake-apple-store-order-e-mail#comments</comments>
		<pubDate>Sun, 11 Apr 2010 05:15:36 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[e-mail]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=401</guid>
		<description><![CDATA[Time to add another fake e-mail to the long list of social engineering e-mail scams. This one looks like this. Subject 4912-3337 Apple AppStore Confirmation Sender Apple Up-To-Date Add contact Apple Store Call 1-800-MY-APPLE #4368-66525 Order Details You can also contact Apple Store Customer Service or visit online for more information. Visit the Apple Online [...]]]></description>
			<content:encoded><![CDATA[<p>Time to add another fake e-mail to the long list of social engineering e-mail scams. This one looks like this.</p>
<blockquote><p>
Subject 	4912-3337 Apple AppStore Confirmation<br />
Sender 	Apple Up-To-Date Add contact</p>
<p>Apple Store<br />
Call 1-800-MY-APPLE</p>
<p>#4368-66525<br />
<a href="http://">Order Details</a></p>
<p>You can also contact Apple Store Customer Service or visit online for more information.</p>
<p>Visit the Apple Online Store to purchase Apple hardware, software, and third-party accessories.<br />
Copyright 2010 Apple Inc. All rights reserved. </p>
</blockquote>
<p>This one wants you to click on the order details link, which I have removed, but if you look at the &#8220;Order Details&#8221; link more closely, you will see that it doesn&#8217;t go to the apple store but links to some place called goofbomb. I don&#8217;t feel like testing out my anti-virus or risk getting a 0-day virus or some malware, let&#8217;s just assume it&#8217;s a bad place. So keep your eyes out for this and other e-mails that claim you have purchased something, or missed a delivery, and gives you a link to your &#8220;order&#8221; or has an attachment for you to open. Quite a few of these going around these days.</p>
<p>Surf Safe</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2010/04/fake-apple-store-order-e-mail/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Shipping Virus E-mail</title>
		<link>http://www.pccybertek.com/2010/01/shipping-virus-e-mail</link>
		<comments>http://www.pccybertek.com/2010/01/shipping-virus-e-mail#comments</comments>
		<pubDate>Thu, 28 Jan 2010 19:57:49 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[scams]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[e-mail]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=373</guid>
		<description><![CDATA[Just a quick warning about a couple of e-mails that had a virus attachment. They are both pretending to be from U.S. Shipping companies. First we have this one from &#8220;UPS&#8221; From: UPS Manager Romeo Law [delivery@ups.com] Subject:  UPS Delivery Problem NR 08488. Dear customer! We failed to deliver the package sent on the 6th of [...]]]></description>
			<content:encoded><![CDATA[<p>Just a quick warning about a couple of e-mails that had a virus attachment. They are both pretending to be from U.S. Shipping companies.</p>
<p>First we have this one from &#8220;UPS&#8221;</p>
<blockquote><p>From: UPS Manager Romeo Law [delivery@ups.com]</p>
<p>Subject:  UPS Delivery Problem NR 08488.</p>
<div id="_mcePaste">Dear customer!</div>
<div id="_mcePaste">We failed to deliver the package sent on the 6th of January in time because the recipient’s address is incorrect.</div>
<div id="_mcePaste">Please print out the invoice copy attached and collect the package at our office.</div>
<div id="_mcePaste">United Parcel Service of America.</div>
<p>Dear customer!<br />
We failed to deliver the package sent on the 6th of January in time<br />
<span id="more-373"></span><br />
because the recipient’s address is incorrect.Please print out the invoice copy attached and collect the package at our office.<br />
United Parcel Service of America.</p>
<p>attachment: UPS_invoice_NR34587.zip</p></blockquote>
<p>NOD32 identifies the virus in this attachment as virus <strong>Win32/Oficla.CX trojan</strong>. A couple of ways you can tell this is fake, besides the attached virus are; why would UPS wait a couple of weeks to notify you of this? Do they really sign their e-mail United Parcel Service of America? They tell you to pick it up at the office but there is no address or contact info for the office. Just thought I&#8217;d point this out.</p>
<p>Next we have one from DHL:</p>
<blockquote><p>From: Manager Gabrielle Bird [customer@dhl.com]</p>
<p>Subject:  DHL Office. Get your parcel NR.4486</p>
<p>Hello!</p>
<p>The courier service was not able to deliver your parcel at your address.</p>
<p>Cause: Mistake in address</p>
<p>You may pickup the parcel at our post office personally.</p>
<p>The delivery advice is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
DHL Global Forwarding Services.</p>
<p>attachments: DHL_label_Nr2385.zip &gt; ZIP &gt; DHL_label_Nr2385.exe</p></blockquote>
<p>ESET-NOD32 Identifies the virus in this attachment as <strong>Win32/TrojanDownloader.Bredolab.BE trojan</strong></p>
<p>In case you don&#8217;t know this already, never run an .exe file you get in e-mail. Nothing good ever comes from running an .exe you received in e-mail.</p>
<p>Watch out for these or variants of them.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2010/01/shipping-virus-e-mail/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>E-Card Virus Warning</title>
		<link>http://www.pccybertek.com/2009/12/e-card-virus-warning</link>
		<comments>http://www.pccybertek.com/2009/12/e-card-virus-warning#comments</comments>
		<pubDate>Wed, 16 Dec 2009 17:20:54 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/2009/12/e-card-virus-warning</guid>
		<description><![CDATA[Just got an e-mail that says it&#8217;s from e-cards@hallmark.com with the subject: You have received A Hallmark E-Card! It had an attachment called Postcard.zip which was identified by my antivirus, I use NOD32 by E-Set __________ ESET NOD32 Antivirus warning, version of virus signature database 4693 (20091216) __________ Warning, ESET NOD32 Antivirus found the following [...]]]></description>
			<content:encoded><![CDATA[<p>Just got an e-mail that says it&#8217;s from e-cards@hallmark.com with the subject: You have received A Hallmark E-Card! It had an attachment called Postcard.zip which was identified by my antivirus, I use NOD32 by E-Set</p>
<blockquote><p>__________ ESET NOD32 Antivirus warning, version of virus signature database 4693 (20091216) __________</p>
<p>Warning, ESET NOD32 Antivirus found the following threats in the message:</p>
<p>Postcard.zip &#8211; probably a variant of Win32/Merond.AA worm &#8211; deleted<br />
Postcard.zip > ZIP > document.chm .exe &#8211; probably a variant of Win32/Merond.AA worm &#8211; was a part of the deleted object</p></blockquote>
<p>This came from one of my works TV affiliates mailing list. So I am guessing it is one that goes through your address book and sends itself to everyone on there. </p>
<p>Figured this was also a good time to remind people to be careful with any &#8220;e-cards&#8221; they get. Watch out for infected attachments, as was the case with this one, and watch for links that send you to websites designed to infect you or steal your identity / information.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2009/12/e-card-virus-warning/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spyware Protect 2009 is a Virus</title>
		<link>http://www.pccybertek.com/2009/06/spyware-protect-2009-is-a-virus</link>
		<comments>http://www.pccybertek.com/2009/06/spyware-protect-2009-is-a-virus#comments</comments>
		<pubDate>Sun, 14 Jun 2009 02:52:09 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[botnets]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[free software]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=146</guid>
		<description><![CDATA[I&#8217;m sure you have all seen this before. Your surfing along, when all of a sudden, you get a pop-up that alerts you that your computer is infected! YIKES! What to do!??! Ah, you can just download a &#8220;free&#8221; program that will fix it for you. I&#8217;d hope you already know, this is a scam. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://pccybertek.moesarts.com/wp-content/uploads/2009/06/ConfickerFakeAV-300x214.png" alt="ConfickerFakeAV" title="ConfickerFakeAV" width="300" height="214" class="alignleft size-medium wp-image-147" />  I&#8217;m sure you have all seen this before. Your surfing along, when all of a sudden, you get a pop-up that alerts you that your computer is infected! YIKES! What to do!??! Ah, you can just download a &#8220;free&#8221; program that will fix it for you. I&#8217;d hope you already know, this is a scam. It&#8217;s one of two things. You can either download a legit program that will scan your computer, tell you how badly infected it is and you can purchase a full version of the program to remove all your &#8220;infections.&#8221; Just in case your not really infected, these programs will increase your infection count by adding your cookies to the list. Pretty good way to jack up the numbers, but I wouldn&#8217;t call cookies an infection. And I sure don&#8217;t have to buy any program to remove them. The other thing that could happen, and probably will is, you will download a program that will then install it&#8217;s own addware. Turns out they have a name for this stuff now, and that name is Scareware.</p>
<p>Turns out many people are still falling for this scam. I had to clean my parents computer up, from one of these. Try doing it over VNC, and you may have your patience tested like I did. Anyways, the old folks aren&#8217;t the only ones falling for this, and now their is a new variation. Spware Protect 2009, is the new breed of scareware. Not only does it con you by getting you to install it, it actually does damage to get you to &#8220;purchase&#8221; it for $49.99 and install a trojan downloader. Meanwhile it increases the pop ups telling you how infected your computer is. So you order the program with your credit card and guess what, you just gave them your credit card number, no hacking needed. A local electronics store, with the initials RS, got hit by it and from what I could get out of them, sounds like the whole corp has been infected through their network.</p>
<p>Since I first found out about this last week, I&#8217;ve found out that it&#8217;s now also being installed by the conficker virus. At first I was thinking, wouldn&#8217;t people be suspicious if there was a new piece of software, on their computer? I sure as hell would. Then I started thinking about it, in a corporate situation. Some poor schmuck, in accounting or where ever, could think it was installed by their IT Dept. So the keylogger installed would run until the computer crashed. The one good thing is, the domain that was selling Spyware Protect 2009 is gone. Keep an eye out for variations with new names and the same or slightly modified interface.</p>
<p>-Your friendly neighborhood PC Cybertek</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2009/06/spyware-protect-2009-is-a-virus/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trustworthy Conficker Resources</title>
		<link>http://www.pccybertek.com/2009/03/trustworthy-conficker-resources</link>
		<comments>http://www.pccybertek.com/2009/03/trustworthy-conficker-resources#comments</comments>
		<pubDate>Tue, 31 Mar 2009 19:35:04 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[blog support]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[free software]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[video games]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=118</guid>
		<description><![CDATA[With all the media hype about conficker, I thought you might like a good collection of trustworthy resources. Beware of websites that have recently registered as &#8220;conficker help.&#8221; In fact, just avoid them all together. There&#8217;s also reports of malicious software masquerading as detection and cleaning tools for Conficker-infected computers, as well as spam offering [...]]]></description>
			<content:encoded><![CDATA[<p>With all the media hype about conficker, I thought you might like a good collection of trustworthy resources. Beware of websites that have recently registered as &#8220;conficker help.&#8221; In fact, just avoid them all together. There&#8217;s also reports of malicious software masquerading as detection and cleaning tools for Conficker-infected computers, as well as spam offering the same.</p>
<p><img class="alignleft size-thumbnail wp-image-122" title="computer-virus" src="http://pccybertek.moesarts.com/wp-content/uploads/2009/03/computer-virus-150x150.jpg" alt="computer-virus" width="150" height="150" />There&#8217;s no need to try and figure out what&#8217;s safe or real and what has more sinister plans in mind. The good folks at <a href="http://www.dshield.org/indexd.html" target="_blank">dshield.org</a> have been keeping an updated list of <a href="http://www.dshield.org/diary.html?storyid=5860" target="_blank">third party information on conficker</a>. Here you can find plenty of free conficker detection and removal tools, general information and the microsoft patch. That should help keep you updated, safe and informed.</p>
<p>I&#8217;ve also found out about one other real neat way of detecting it, but it&#8217;s for more advanced users, so I&#8217;m going to make a seperate post about it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2009/03/trustworthy-conficker-resources/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<img style='margin:0;padding:0;border:0;' width='1px' height='1px' src="http://pccybertek.moesarts.com/wp-content/plugins/mystat/mystat.php?act=time_load&id=181478&rnd=920391925" /></channel>
</rss>
