<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Scam Detectives &#187; Virus</title>
	<atom:link href="http://www.scam-detectives.co.uk/blog/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.scam-detectives.co.uk/blog</link>
	<description>Keeping you safe online!</description>
	<lastBuildDate>Fri, 03 Feb 2012 16:50:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Has someone sent you an e-card?</title>
		<link>http://www.scam-detectives.co.uk/blog/2010/02/18/has-someone-sent-you-an-e-card/</link>
		<comments>http://www.scam-detectives.co.uk/blog/2010/02/18/has-someone-sent-you-an-e-card/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 16:28:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Viruses & Malware]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[viruses and malware]]></category>

		<guid isPermaLink="false">http://www.scam-detectives.co.uk/blog/?p=240</guid>
		<description><![CDATA[Sending someone an e-card can be a nice gesture and can be environmentally friendly There are loads of legitimate e-card sites out there, which will help you to send your e-cards without incident. Unfortunately, there&#8217;s also a load of viruses that are transmitted disguised as e-cards. We received this email a couple of minutes ago [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.scam-detectives.co.uk/blog/wp-content/uploads/2010/02/e-card.jpg"><img src="http://www.scam-detectives.co.uk/blog/wp-content/uploads/2010/02/e-card.jpg" alt="e-card" title="e-card" width="255" height="190" class="alignleft size-full wp-image-241" /></a>Sending someone an e-card can be a nice gesture and can be environmentally friendly</p>
<p>There are loads of legitimate e-card sites out there, which will help you to send your e-cards without incident.</p>
<p>Unfortunately, there&#8217;s also a load of viruses that are transmitted disguised as e-cards.</p>
<p>We received this email a couple of minutes ago</p>
<blockquote><p>
<strong> You have received an e-card</strong></p>
<p>To pick up your eCard, click on the following link (or copy &#038; paste it into your web browser):</p>
<p>http://kamien-grabica.**.**/ecard.exe (LINK DISABLED)</p>
<p>Your card will be aviailable for pick-up beginning for the next 30 days.</p></blockquote>
<p>This one links to e-card.exe, a nasty little virus which has been reported to cause some machines to display the &#8220;Blue screen of Death&#8221; and refuse to boot in anything but safe mode.</p>
<p><strong> So how do I tell if someone really has sent me an e-card?</strong></p>
<p>If there&#8217;s no name on the email and it just says &#8220;Someone sent you an e-card&#8221; then delete it. A legitimate e-card site will tell you who has sent the e-card.</p>
<p>Email your friend (using the email address in your contacts, not the one from the email)  to ask them if they really did send you an e-card. Explain nicely that you&#8217;re wary of opening e-cards because you&#8217;ve heard that some of them contain viruses. If you get a response saying &#8220;Yes, I sent it&#8221;, then you know it&#8217;s for real.  If they respond &#8220;Hey, nice to hear from you, but it wasn&#8217;t me&#8221; then you can safely delete the email without fear of offending anyone!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.scam-detectives.co.uk/blog/2010/02/18/has-someone-sent-you-an-e-card/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updated account agreement &#8211; Another facebook virus alert</title>
		<link>http://www.scam-detectives.co.uk/blog/2010/02/10/updated-account-agreement-another-facebook-virus-alert/</link>
		<comments>http://www.scam-detectives.co.uk/blog/2010/02/10/updated-account-agreement-another-facebook-virus-alert/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 19:49:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.scam-detectives.co.uk/blog/?p=206</guid>
		<description><![CDATA[Dear Facebook user, Due to Facebook policy changes, all Facebook users must submit a new, updated account agreement, regardless of their original account start date. Accounts that do not submit the updated account agreement by the deadline will have restricted. Please unzip the attached file and run “agreement.exe” by double-clicking it. Thanks, The Facebook Team [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Dear Facebook user,</p>
<p>Due to Facebook policy changes, all Facebook users must submit a new, updated account agreement, regardless of their original account start date.<br />
Accounts that do not submit the updated account agreement by the deadline will have restricted.</p>
<p>Please unzip the attached file and run “agreement.exe” by double-clicking it.</p>
<p>Thanks,<br />
The Facebook Team</p></blockquote>
<p>Once again we see a shift from the scammers trying to avoid detection. We&#8217;re wise to the &#8220;password change&#8221; email that circulated a few days ago, so now they&#8217;re trying to get us to open a new attachment &#8220;agreement.exe&#8221;. </p>
<ul>
<li><strong> Facebook would not communicate a new user agreement to you in this way</strong>. You&#8217;d be presented with it upon logging into the site.</li>
<li> <strong> Even if they did, it WOULD NOT EVER be in the form of a .exe file</strong></li>
</ul>
<p>Delete this email immediately, NEVER open .exe files sent to you in an email.</p>
<p>===============================================================================<br />
We now have a great range of <a href="http://www.scam-detectives.co.uk/store.html">PC and Home Security products </a>available in the <a href="http://www.scam-detectives.co.uk/store.html">Scam Detectives Security Supplies online store </a>(powered by Amazon).  </p>
]]></content:encoded>
			<wfw:commentRss>http://www.scam-detectives.co.uk/blog/2010/02/10/updated-account-agreement-another-facebook-virus-alert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook Password Reset Confirmation! Customer Support.</title>
		<link>http://www.scam-detectives.co.uk/blog/2010/02/08/facebook-password-reset-confirmation-customer-support/</link>
		<comments>http://www.scam-detectives.co.uk/blog/2010/02/08/facebook-password-reset-confirmation-customer-support/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 15:36:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Viruses & Malware]]></category>
		<category><![CDATA[Email Scam]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.scam-detectives.co.uk/blog/?p=187</guid>
		<description><![CDATA[Yet another attempt to trick you into downloading a virus. The attached zip file doesn&#8217;t contain a new Facebook password, it&#8217;s another virus! Delete the email immediately, do not open the attachment! Remember: If you didn&#8217;t request a password reminder from Facebook, then they would have no reason to send you one Even if you [...]]]></description>
			<content:encoded><![CDATA[<p>Yet another attempt to trick you into downloading a virus. The attached zip file doesn&#8217;t contain a new Facebook password, it&#8217;s another virus! </p>
<p>Delete the email immediately, do not open the attachment!</p>
<p>Remember:</p>
<ul>
<li> If you didn&#8217;t request a password reminder from Facebook, then they would have no reason to send you one</li>
<li> Even if you did, they wouldn&#8217;t send it as an attachment</li>
</ul>
<p>If you&#8217;ve forgotten your Facebook password, go to the Facebook home page and click &#8220;forgotten password&#8221;. They&#8217;ll send you a reset code to your registered email address that you&#8217;ll have to enter to reset your password.</p>
<blockquote><p>Dear user of facebook,</p>
<p>Because of the measures taken to provide safety to our clients, your password has been changed.<br />
You can find your new password in attached document.</p>
<p>Thanks,<br />
Your Facebook.
</p></blockquote>
<p>===============================================================================<br />
We now have a great range of <a href="http://www.scam-detectives.co.uk/store.html">PC and Home Security products </a>available in the <a href="http://www.scam-detectives.co.uk/store.html">Scam Detectives Security Supplies online store</a> (powered by Amazon). </p>
]]></content:encoded>
			<wfw:commentRss>http://www.scam-detectives.co.uk/blog/2010/02/08/facebook-password-reset-confirmation-customer-support/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Variation on DHL failed delivery virus email &#8211; Your order has been paid! Parcel NR.5256</title>
		<link>http://www.scam-detectives.co.uk/blog/2010/02/08/variation-on-dhl-failed-delivery-virus-email-your-order-has-been-paid-parcel-nr-5256/</link>
		<comments>http://www.scam-detectives.co.uk/blog/2010/02/08/variation-on-dhl-failed-delivery-virus-email-your-order-has-been-paid-parcel-nr-5256/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 13:57:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Viruses & Malware]]></category>
		<category><![CDATA[DHL]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.scam-detectives.co.uk/blog/?p=184</guid>
		<description><![CDATA[This is a variation on the &#8220;DHL Failed Delivery&#8221; but the attachment is the same &#8211; A banking Trojan designed to harvest your details. Delete the email immediately, do not open the attachment under any circumstances! Email subject: Your order has been paid! Parcel NR.5256 Goodafternoon! Thank you for shopping at our internet store! We [...]]]></description>
			<content:encoded><![CDATA[<p>This is a variation on the &#8220;DHL Failed Delivery&#8221; but the attachment is the same &#8211; A banking Trojan designed to harvest your details. Delete the email immediately, do not open the attachment under any circumstances!</p>
<p>Email subject: Your order has been paid! Parcel NR.5256</p>
<blockquote><p>Goodafternoon!</p>
<p>Thank you for shopping at our internet store!<br />
We have successfully received your payment.</p>
<p>Your order has been shipped to your billing address. </p>
<p>You have ordered &#8221; Macally ICECAM2 &#8220;</p>
<p>You can find your tracking number in attached to the e-mail  document. </p>
<p>Please print the DHL label to get your package.</p>
<p>We hope you enjoy your order!<br />
Ramblinwreckstore.com </p></blockquote>
<p>===============================================================================<br />
We now have a great range of <a href="http://www.scam-detectives.co.uk/store.html">PC and Home Security products</a> available in the <a href="http:/www.scam-detectives.co.uk/store.html">Scam Detectives Security Supplies online storeM</a> (powered by Amazon). </p>
]]></content:encoded>
			<wfw:commentRss>http://www.scam-detectives.co.uk/blog/2010/02/08/variation-on-dhl-failed-delivery-virus-email-your-order-has-been-paid-parcel-nr-5256/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Has &#8220;Some Jerk&#8221; posted your picture online? No! It&#8217;s a virus!</title>
		<link>http://www.scam-detectives.co.uk/blog/2010/02/03/has-some-jerk-posted-your-picture-online-no-its-a-virus/</link>
		<comments>http://www.scam-detectives.co.uk/blog/2010/02/03/has-some-jerk-posted-your-picture-online-no-its-a-virus/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 14:30:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Viruses & Malware]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[scam awareness]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.scam-detectives.co.uk/blog/?p=160</guid>
		<description><![CDATA[This arrived in the Scam Detectives email box this afternoon. No, nobody has posted our picture online. It&#8217;s a ruse to get you to download the Trojan ZBot virus, which is a keylogger designed to harvest your login information for online banking websites. ***VERY IMPORTANT NOTE &#8211; MANY ANTIVIRUS PROGRAMS WILL NOT PICK THIS UP*** [...]]]></description>
			<content:encoded><![CDATA[<p>This arrived in the Scam Detectives email box this afternoon.</p>
<p>No, nobody has posted our picture online. It&#8217;s a ruse to get you to download the <a href="http://www.f-secure.com/v-descs/trojan-spy_w32_zbot.shtml"> Trojan ZBot</a> virus, which is a keylogger designed to harvest your login information for online banking websites.</p>
<p><strong>***VERY IMPORTANT NOTE &#8211; MANY ANTIVIRUS PROGRAMS WILL NOT PICK THIS UP***</strong></p>
<blockquote><p>Hey, some jerk has posted your pictures (u understand what kind of pictures are there) and sent a link of them to all ur friends. I have already replied back. Said, that he is an idiot. See the link:</p>
<p>LINK REMOVED</p>
<p>Lizzie Mcnally</p></blockquote>
<p>This is a screenshot from the website the link leads to.</p>
<p><img src="http://www.scam-detectives.co.uk/blog/wp-content/uploads/2010/02/photoarchive.jpg" alt="photoarchive" title="photoarchive" width="550" height="481" class="aligncenter size-full wp-image-161" /></p>
<p>We&#8217;ll keep saying it &#8211; If you receive an email of this nature DELETE IT IMMEDIATELY. Do not click on the link, it WILL infect your PC and many antivirus programs will not pick this up, even if they are fully up to date.</p>
<p>===============================================================================<br />
We now have a great range of <a href="http://www.scam-detectives.co.uk/store.html">PC and Home Security products</a> available in the <a href="http://www.scam-detectives.co.uk/store.html">Scam Detectives Security Supplies online store</a> (powered by Amazon). </p>
]]></content:encoded>
			<wfw:commentRss>http://www.scam-detectives.co.uk/blog/2010/02/03/has-some-jerk-posted-your-picture-online-no-its-a-virus/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DHL failed delivery  (also UPS/TNT/ParcelForce)</title>
		<link>http://www.scam-detectives.co.uk/blog/2010/01/19/dhl-failed-delivery/</link>
		<comments>http://www.scam-detectives.co.uk/blog/2010/01/19/dhl-failed-delivery/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 12:04:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Viruses & Malware]]></category>
		<category><![CDATA[Courier]]></category>
		<category><![CDATA[DHL]]></category>
		<category><![CDATA[Email Scam]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.scam-detectives.co.uk/blog/?p=35</guid>
		<description><![CDATA[Have you had an email like this? Dear customer! The courier company was not able to deliver your parcel by your address. Cause: Error in shipping address. You may pickup the parcel at our post office personaly. Please attention! The shipping label is attached to this e-mail. Print this label to get this package at [...]]]></description>
			<content:encoded><![CDATA[<p>Have you had an email like this?<br />
<em><br />
Dear customer!</p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</p>
<p>You may pickup the parcel at our post office personaly.</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</em></p>
<p>The attached &#8220;shipping label&#8221; is actually a virus. Don&#8217;t open the attachment and delete the email immediately.</p>
<p>If you open the file inside the attachment you will be infected by a &#8220;backdoor Trojan horse&#8221;, which will attempt to take control of your PC.</p>
<p>If you think that you should have received a delivery and haven&#8217;t, contact your local courier depot, who will be able to advise you as to the status of your delivery, or use the official DHL website to track your parcel online. </p>
<p>We now have a great range of <a href="http://www.scam-detectives.co.uk/store.html">PC and Home Security products</a> available in the <a href="http://www.scam-detectives.co.uk/store.html">Scam Detectives Security Supplies online store</a> (powered by Amazon). </p>
]]></content:encoded>
			<wfw:commentRss>http://www.scam-detectives.co.uk/blog/2010/01/19/dhl-failed-delivery/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
	</channel>
</rss>

