<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Robert L. Weiner: Nonprofit Fundraising Technology Consulting &#187; Viruses</title>
	<atom:link href="http://www.rlweiner.com/category/software/viruses/feed" rel="self" type="application/rss+xml" />
	<link>http://www.rlweiner.com</link>
	<description>Technology Advisors to Nonprofits and Educational Institutions</description>
	<lastBuildDate>Tue, 07 Feb 2012 20:00:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Lame spam of the day: I&#8217;m in trouble!</title>
		<link>http://www.rlweiner.com/lame-spam-of-the-day-im-in-trouble</link>
		<comments>http://www.rlweiner.com/lame-spam-of-the-day-im-in-trouble#comments</comments>
		<pubDate>Thu, 22 Dec 2011 18:12:16 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://www.rlweiner.com/?p=2134</guid>
		<description><![CDATA[Don't people know not to click links in weird emails from strangers?&#160; Probably not. This site says the link leads to malware. Sender: Svetlana@rlweiner.com (My domain -- no Svetlanas work at my company) Subject: Fwd: I'm in trouble! Text: I was at a party, got drunk, couldn't drive the car, somebody gave me a lift [...]]]></description>
			<content:encoded><![CDATA[<p>Don't people know not to click links in weird emails from strangers?&#160; Probably not. <a href="http://www.dataprotectioncenter.com/security/virus-help-im-in-trouble/">This site</a> says the link leads to malware.</p>
<p><strong>Sender: </strong>Svetlana@rlweiner.com <em><strong>(My domain -- no Svetlanas work at my company)</strong></em><br />
<strong>Subject:</strong> Fwd: I'm in trouble!<br />
<strong>Text:</strong><br />
I was at a party, got drunk, couldn't drive the car, somebody gave me a lift on my car, and crossed on the red light!<br />
I've just got the pictures, maybe you know him???<br />
Here is the photo <em><strong>(link leads to http://djnmusicstudio.com/wp-content/themes/classic/jhmxl.htm?I35=XL0C4D66LLT7M0662G25KRY&amp;1US0=US2I9OKK&amp;67QM=4XY6G2O9Y1R7544P2&amp;Q7C7=3S3J309789CJ95A89SS0A&amp;9SJR2Q=SQFE7ZJ6AAO&amp;YPJ=6GUM395IAJCUJ9YDF7XHTH8&amp;OWMW0=8MTL1IFTP9R8O2WTG&amp;PKC20X=J982Q0J26M9DIUB&amp;)</strong></em></p>
<p>I need to find him urgently!</p>
<p>Thank you<br />
Svetlana</p>
<p><br />
MD5 check sum: 4999b6f8af3e65c8a5c3e6f3e1d4999b</p>]]></content:encoded>
			<wfw:commentRss>http://www.rlweiner.com/lame-spam-of-the-day-im-in-trouble/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lame spam of the day: NYC traffic ticket</title>
		<link>http://www.rlweiner.com/lame-spam-of-the-day-nyc-traffic-ticket</link>
		<comments>http://www.rlweiner.com/lame-spam-of-the-day-nyc-traffic-ticket#comments</comments>
		<pubDate>Mon, 12 Dec 2011 17:43:04 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Scam]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://www.rlweiner.com/?p=2112</guid>
		<description><![CDATA[This is the first one like this I've seen -- a speeding ticket.&#160; If I'd driven in New York in October I might be curious enough to click (well, I wouldn't, but someone might).&#160; Apparently this one has been floating around for a while and delivers malware. Sender: support@rlweiner.com (me!) Subject: Fwd: Re: TRAFFIC TICKET [...]]]></description>
			<content:encoded><![CDATA[<p>This is the first one like this I've seen -- a speeding ticket.&#160; If I'd driven in New York in October I might be curious enough to click (well, I wouldn't, but someone might).&#160; Apparently this one has been <a href="https://www.google.com/search?q=nyc+speeding+ticket+spam&amp;ie=utf-8&amp;oe=utf-8&amp;aq=t&amp;rls=org.mozilla:en-US:official&amp;client=firefox-a" target="_blank">floating around for a while</a> and delivers malware.</p>
<p><strong>Sender:</strong> support@rlweiner.com (me!)<br />
<strong>Subject:</strong> Fwd: Re: TRAFFIC TICKET <br />
<strong>Text:</strong><br />
NYC — Department of Motor Vehicles<br />
TRAFFIC TICKET<br />
NYC POLICE DEPARTMENT<br />
THE PERSON CHARGED AS FOLLOWS</p>
<p>Time: 4:14 AM<br />
Date of Offense: 27/10/2011</p>
<p>SPEED OVER 90 ZONE<br />
TO PLEAD, PRINT CLICK HERE AND FILL OUT THE FORM <em><strong>(link leads to http://motorcitysports.net/kqtmh.htm?U4BPET=9VPEX8EECYK&amp;WV3S6L=161WHHX67AALE5VBIL74XG3&amp;)</strong></em></p>

<p><br />
MD5 check sum: 251eb0e983cafb0e9888304146a567dd</p>]]></content:encoded>
			<wfw:commentRss>http://www.rlweiner.com/lame-spam-of-the-day-nyc-traffic-ticket/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lame spam of the day: The variant of the contract you&#8217;ve offered has been delcined.</title>
		<link>http://www.rlweiner.com/lame-spam-of-the-day-the-variant-of-the-contract-youve-offered-has-been-delcined</link>
		<comments>http://www.rlweiner.com/lame-spam-of-the-day-the-variant-of-the-contract-youve-offered-has-been-delcined#comments</comments>
		<pubDate>Fri, 09 Dec 2011 17:36:20 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Scam]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://www.rlweiner.com/?p=2106</guid>
		<description><![CDATA[I just love the subject line in this one.&#160; Wow, very creative syntax (though the misspelling of "declined" lessens the impact).&#160; I also got a second version, but the subject was much more prosaic.&#160; This blog says the links download malware. Version 1: Sender: Argelia Vogel (SterlingGroesbeck@myexcel.com) Subject: The variant of the contract you've offered [...]]]></description>
			<content:encoded><![CDATA[<p>I just love the subject line in this one.&#160; Wow, very creative syntax (though the misspelling of "declined" lessens the impact).&#160; I also got a second version, but the subject was much more prosaic.&#160; <a href="http://blog.dynamoo.com/2011/12/variant-of-contract-youve-offered-has.html" target="_blank">This blog </a>says the links download malware.</p>
<p><strong>Version 1:</strong><br />
<strong>Sender:</strong> Argelia Vogel (SterlingGroesbeck@myexcel.com)<br />
<strong>Subject:</strong> The variant of the contract you've offered has been delcined.<br />
<strong>Text:<br />
</strong>After our legal department studied this contract carefully, they've noticed the following mismatches with our previous arrangements. We've composed a preliminary variant of the new contract, please study it and make sure that all the issues are matching your interests<br />
Contract.doc 84kb <em><strong>(link leads to http://dsdinternational.net/images/dsrwk.htm?FMCGCYP=MH82W31MC&amp;089=1RY6NFZN&amp;YYA66YM=I2CU1XELWV0YSTMK632IUWPT4&amp;HJEL=UQPI4T3&amp;CAB4RT4=51LIGZMZ29T80052AXHWBSA9&amp;04KZQW4=QK5T9UA8C8AXGGHZ8J&amp;)</strong></em></p>
<p>Best Wishes<br />
Argelia Vogel</p>

<p>Fingerprint: 172d59c7-2d5b834b </p>
<p><strong>Version 2:</strong><br />
<strong>Sender: </strong>Catharine Padgett (NiamhStabler@visi.net)<br />
<strong>Subject: </strong>We're breaking the contract<br />
<strong>Text:<br />
</strong>According to the violation of the paragraph §11.6.7 of our contract, we're obliged to inform you that we're breaking the contract with you. You can find the original letter with signatures and stamps attached as well as the legal basis for this step after you follow this link.</p>
<p>Contract.doc 119kb <em><strong>(link leads to http://pokerlogic.ca/forum/kysgw.htm?0JDH0=LXZKAZNARHOSCT&amp;WHC=8JTSQ4KRSFYL&amp;SGY=WKE20ZCFAN9K8HBUU1J9P2R&amp;F82L6SE=L05FZB1O9DLWJ9DS3TJ16K3U&amp;BVAGK=A8XB9J4T25TR6BP&amp;Q8M7LF=IE342QA6JD4&amp;J8Y=I8E58E20NMTR&amp;)</strong></em></p>
<p>Best Wishes<br />
Catharine Padgett</p>
<p><br />
Fingerprint: c0372849-28e1116b<br />
&#160;</p>]]></content:encoded>
			<wfw:commentRss>http://www.rlweiner.com/lame-spam-of-the-day-the-variant-of-the-contract-youve-offered-has-been-delcined/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Lame spam of the day: BBB service Re: Case # (various numbers)</title>
		<link>http://www.rlweiner.com/lame-spam-of-the-day-bbb-service-re-case-various-numbers</link>
		<comments>http://www.rlweiner.com/lame-spam-of-the-day-bbb-service-re-case-various-numbers#comments</comments>
		<pubDate>Wed, 07 Dec 2011 18:11:30 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Scam]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://www.rlweiner.com/?p=2088</guid>
		<description><![CDATA[I got 7 versions of this today, at 2 different email addresses.&#160; They included an attachment called bbb_logo.jpg but no graphics in the message body.&#160; A friend posted about them on a listserve and said that clicking the link downloads a virus. This scam has been around for a while.&#160; Here's an article about a [...]]]></description>
			<content:encoded><![CDATA[<p>I got 7 versions of this today, at 2 different email addresses.&#160; They included an attachment called bbb_logo.jpg but no graphics in the message body.&#160; A friend posted about them on a listserve and said that clicking the link downloads a virus.</p>
<p>This scam has been around for a while.&#160; <a target="_blank" href="http://www.bbb.org/us/article/bbb-issues-alert-for-phishing-attack-targeting-thousands-of-businesses-and-consumers-688">Here's an article</a> about a similar batch in 2007.</p>
<p><strong>Version 1:</strong></p>
<p><strong>Sender:</strong> ::Better Business Bureau:: (support@bbb.org)<br />
<strong>Subject:</strong> BBB service Re: Case # 87348414</p>
<p><strong>Text:</strong> Attn: Owner/Manager<br />
The Better Business Bureau has been sent the above mentioned complaint from one of your associates on the subject of their business relations with you.<br />
The details of the consumer's concern are included in attached file.<br />
Please examine this issue and notify us of your opinion.<br />
Please click here to respond this complaint. (<em><strong>The "click here</strong></em>" <em><strong>link leads to </strong></em><strong>http://38.106.32.183/09d78c/index.html</strong>) <br />
<br />
We look forward to your prompt reply. <br />
<br />
Sincerely,<br />
Roland Dani<br />
Better Business Bureau<br />
________________________________________<br />
Council of Better Business Bureaus<br />
4200 Wilson Blvd, Suite 800<br />
Arlington, VA 22203-1838<br />
Phone: 1 (703) 276.0100<br />
Fax: 1 (703) 525.8277</p>
<p><strong>Version 2:</strong></p>
<p>Same sender</p>
<p><strong>Subject:</strong> Re: BBB Case # 31889235</p>
<p><strong>Text:</strong><br />
Attn: Owner/Manager<br />
The Better Business Bureau has been filed the above mentioned complaint from one of your associates in respect of their dealings with you.<br />
The details of the consumer's concern are included in enclosed file.<br />
Please give attention to this case and advise us of your standpoint.<br />
We kindly ask you to click here to answer this complaint. (<strong><em>The "click here</em></strong>" <em><strong>link leads to the same link as above - http://38.106.32.183/09d78c/index.html</strong></em>). <br />
<br />
We look forward to your prompt response. <br />
<br />
Sincerely yours,<br />
Louis Gerald<br />
Better Business Bureau<br />
________________________________________<br />
Council of Better Business Bureaus<br />
4200 Wilson Blvd, Suite 800<br />
Arlington, VA 22203-1838<br />
Phone: 1 (703) 276.0100<br />
Fax: 1 (703) 525.8277<br />
<br />
<strong>Version 3:</strong></p>
<p>same sender</p>
<p><strong>Subject:</strong> Re: Case # 23378891<br />
Text:<br />
Attn: Owner/Manager<br />
The Better Business Bureau has received the above-referenced complaint from one of your customers on the subject of their dealings with you.<br />
The details of the consumer's concern are presented in enclosed document.<br />
Please examine this problem and let us know about your point of view.<br />
We kindly ask you to click here to reply this complaint. (<strong><em>The "click here" link leads to </em></strong> <em><strong>http://rashidyounus.com/a40d6b/index.html</strong></em>). <br />
<br />
We look forward to your urgent reply.<br />
<br />
Sincerely yours,<br />
Stacie Nieves<br />
Better Business Bureau<br />
________________________________________<br />
Council of Better Business Bureaus<br />
4200 Wilson Blvd, Suite 800<br />
Arlington, VA 22203-1838<br />
Phone: 1 (703) 276.0100<br />
Fax: 1 (703) 525.8277</p>
<p><strong>Version 4:</strong></p>
<p>same sender again, but a different subject</p>
<p><strong>Subject:</strong> BBB Complaint activity report<br />
<strong>Text:</strong><br />
Hello,<br />
The Better Business Bureau has got the above-referenced complaint from one of your clients in respect of their dealings with you.<br />
The detailed information about the consumer's concern is explained in attached document.<br />
Please review this problem and notify us of your standpoint.<br />
We kindly ask you to click here to answer this complaint. <em><strong>(The</strong></em> <strong><em>"click here" link leads to http://queplacer.com/393304/index.html)</em></strong><br />
<br />
We look forward to your prompt attention to this matter.<br />
<br />
Faithfully yours,<br />
Louis Gerald<br />
Better Business Bureau<br />
________________________________________<br />
<br />
Council of Better Business Bureaus<br />
4200 Wilson Blvd, Suite 800<br />
Arlington, VA 22203-1838<br />
Phone: 1 (703) 276.0100<br />
Fax: 1 (703) 525.8277</p>
<p><strong>Version 5:</strong><br />
<strong>Sender:</strong> ::Better Business Bureau:: (info@bbb.org)<br />
<strong>Subject:</strong> BBB Complaint activity report<br />
<strong>Text:</strong><br />
Dear Sirs,<br />
The Better Business Bureau has received the above mentioned complaint from one of your customers on the subject of their business relations with you.<br />
The details of the consumer's concern are presented in enclosed file.<br />
Please review this question and notify us of your opinion.<br />
Please click here to answer this complaint. <strong><em>(The "click here" link leads to http://38.106.32.183/09d78c/index.html)</em></strong><br />
<br />
We look forward to your prompt reply.<br />
<br />
Sincerely yours,<br />
Paula Tap<br />
Better Business Bureau<br />
________________________________________<br />
<br />
Council of Better Business Bureaus<br />
4200 Wilson Blvd, Suite 800<br />
Arlington, VA 22203-1838<br />
Phone: 1 (703) 276.0100<br />
Fax: 1 (703) 525.8277</p>
<p><strong>Version 6:</strong><br />
<strong>Sender:</strong> ::Better Business Bureau::(manager@bbb.org)<br />
<strong>Subject: </strong>Re: Case # 29354013<br />
<strong>Text:</strong><br />
Attn: Owner/Manager<br />
The Better Business Bureau has been sent the above mentioned complaint from one of your associates on the subject of their business relations with you.<br />
The details of the consumer's concern are contained in enclosed document.<br />
Please give attention to this problem and notify us of your point of view.<br />
We kindly ask you to click here to reply this complaint. <em><strong>(</strong></em><strong><em>The</em></strong> <em><strong>"click here" link leads to http://rcegroup.net/34100d/index.html)<br />
</strong></em><br />
We look forward to your urgent reply.<br />
<br />
Yours faithfully,<br />
Anita Emil<br />
Better Business Bureau<br />
________________________________________<br />
<br />
Council of Better Business Bureaus<br />
4200 Wilson Blvd, Suite 800<br />
Arlington, VA 22203-1838<br />
Phone: 1 (703) 276.0100<br />
Fax: 1 (703) 525.8277</p>
<p><strong>Version 7:</strong></p>
<p><strong>Sender: </strong>::Better Business Bureau:: (alerts@bbb.org)<br />
Subject: Your customer’s complaint<br />
Text:<br />
Dear Sirs,<br />
The Better Business Bureau has received the above mentioned complaint from one of your associates regarding their dealings with you.<br />
The detailed information about the consumer's concern is included in attached document.<br />
Please review this matter and inform us about your standpoint.<br />
Please click here to reply this complaint. <strong><em>(The "click here" link leads to http://38.106.32.183/09d78c/index.html)</em></strong></p>
<p>We look forward to your prompt reply.</p>
<p>Sincerely,<br />
Paula Tap<br />
Better Business Bureau<br />
________________________________________</p>
<p>Council of Better Business Bureaus<br />
4200 Wilson Blvd, Suite 800<br />
Arlington, VA 22203-1838<br />
Phone: 1 (703) 276.0100<br />
Fax: 1 (703) 525.8277</p>]]></content:encoded>
			<wfw:commentRss>http://www.rlweiner.com/lame-spam-of-the-day-bbb-service-re-case-various-numbers/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Downadup Worm on the Rampage</title>
		<link>http://www.rlweiner.com/downadup-worm-on-the-rampage</link>
		<comments>http://www.rlweiner.com/downadup-worm-on-the-rampage#comments</comments>
		<pubDate>Sat, 24 Jan 2009 03:59:02 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[TechSoup]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://www.rlweiner.com/downadup-worm-on-the-rampage</guid>
		<description><![CDATA[Internet security firm F-Secure has estimated that more than 3.5 million computers have been infected with the Downadup worm, a malicious program. The worm, also known as Conficker, uses a major flaw that Microsoft patched in October to remotely compromise computers running unpatched versions of Windows. Infected computers become members of a worldwide botnet. F-Secure [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://farm4.static.flickr.com/3081/2332199662_c146d8cec4_m.jpg" border="0" alt="Daniel Piedra" hspace="5" vspace="5" align="right" />Internet security firm F-Secure has estimated that <a href="http://www.f-secure.com/weblog/archives/00001580.html">more than 3.5 million computers have been infected with the Downadup worm</a>, a malicious program. The worm, also known as Conficker, uses a major flaw that Microsoft patched in October to remotely compromise computers running unpatched versions of Windows.</p>

<p>Infected computers become members of a worldwide <a href="http://en.wikipedia.org/wiki/Botnet">botnet</a>. F-Secure predicts that the <a href="http://www.f-secure.com/weblog/archives/00001579.html">botnet could be huge</a>, "giving the malware gang a free hand to do whatever they want with all of the  infected machines."</p>

<p>According to the <a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2009/01/21/BUEU15DOK1.DTL">San Francisco Chronicle</a>:</p>


<blockquote><p>Security vendors haven't figured out what payload the Downadup/Conficker worm plans to deliver, but it's not good. "This could be the biggest infection we've ever seen," said David Perry, global director of education at Trend Micro in Cupertino. "We know they're intentionally infecting a mass audience."</p></blockquote>


<p>Perry offered the following advice to secure your machines:</p>

<p><a href="http://blog.techsoup.org/node/659">read more</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.rlweiner.com/downadup-worm-on-the-rampage/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CNN Top 10 Virus</title>
		<link>http://www.rlweiner.com/cnn-top-10-virus</link>
		<comments>http://www.rlweiner.com/cnn-top-10-virus#comments</comments>
		<pubDate>Thu, 07 Aug 2008 00:36:34 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://www.rlweiner.com/?p=176</guid>
		<description><![CDATA[A new virus is circulating in the form of a CNN Daily Top 10 newsletter (my brother was an unfortunate victim).  A description was posted at http://blog.mxlab.be/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/.  Postings on that site say that the AntiVir free antivirus and ComboFix will remove it.   ]]></description>
			<content:encoded><![CDATA[<p>A new virus is circulating in the form of a CNN Daily Top 10 newsletter (my brother was an unfortunate victim).  A description was posted at <a href="http://blog.mxlab.be/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/">http://blog.mxlab.be/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/</a>.  Postings on that site say that the <a href="http://www.free-av.com/">AntiVir free antivirus </a>and <a href="http://www.forospyware.com/sUBs/ComboFix.exe">ComboFix</a> will remove it.   </p>]]></content:encoded>
			<wfw:commentRss>http://www.rlweiner.com/cnn-top-10-virus/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

