Remove SpyFalcon

Remove SpyFalcon

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Remove SpyFalcon Postman delivers 03-07-2006
Posted by Postman delivers on March 7, 2006, 10:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Removing this rouge spyware program? It has eliminated a methiod from
me to get into restore, and after removing with spybot search and
destroy, it returns.

Is there a simple solution to removing this spyware, or malware?

JR the postman



Posted by David H. Lipman on March 7, 2006, 11:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Is there a simple solution to removing this spyware, or malware?




Two part reply..

Perform Part 1 then perform Part 2.

If the first two parts don't work, perform the alternate utility.

It is suggested that you execute each tool in Normal Mode then in Safe Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE
Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0 Update 6
be installed ASAP.

http://www.java.com/en/download/manual.jsp



Part 1
-----------

Use noahdfear's SmitFraud and SpyAxe removal tool -- SmitRem.exe
http://noahdfear.geekstogo.com/click%20counter/click.php?id=1

http://www.bleepingcomputer.com/forums/topic43659.html


Part 2
-----------

Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your FireWall to enable WGET.EXE to download the needed McAfee related
files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it
will be displayed in your browser (Opera, FireFox or Internet Explorer).
However, if you are using WinXP, Win2K or Win2003 your system will be left in a
state where you will have to manually shutdown/reboot the PC. On Win9x/ME
platforms the report will not be shown in your bowser but your PC will
automatically be shutdown. It is suggested that you move the report out of
c:\mcafee before performing another scan.

It would be best to scan in both Safe Mode and in Normal Mode and save a copy of
the HTML report for each session.


ALTERNATE:

Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.

http://secured2k.home.comcast.net/tools/AntiPuper.exe

http://forums.mcafeehelp.com/viewtopic.php?t=65072


Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your reply.

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Postman delivers on March 8, 2006, 5:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
David H. Lipman expressed precisely :
>
>> Is there a simple solution to removing this spyware, or malware?
>
>
>
>
> Two part reply..
>
> Perform Part 1 then perform Part 2.
>
> If the first two parts don't work, perform the alternate utility.
>
> It is suggested that you execute each tool in Normal Mode then in Safe Mode.
>
> If you are using any version of Sun Java that is prior to JRE Version 5.0,
> then you are strongly urged to remove any/all versions that are prior to JRE
> Version 5.0. There are vulnerabilities in them and they are actively being
> exploited.
> It is possible that is how you got infected with malware.
>
> Therefore, it is highly suggested that if there are any prior versions of Sun
> Java
> to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0
> Update 6 be installed ASAP.
>
> http://www.java.com/en/download/manual.jsp
>
>
>
> Part 1
> -----------
>
> Use noahdfear's SmitFraud and SpyAxe removal tool -- SmitRem.exe
> http://noahdfear.geekstogo.com/click%20counter/click.php?id=1
>
> http://www.bleepingcomputer.com/forums/topic43659.html
>
>
> Part 2
> -----------
>
> Download SmitFraud.exe from the URL --
> http://www.ik-cs.com/programs/virtools/SmitFraud.exe
>
> Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
> Choose; Unzip
> Choose; Close
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
> through your FireWall to enable WGET.EXE to download the needed McAfee
> related files.
>
> Execute; c:\mcafee\clean.bat
> { or Double-click on 'Clean Link' in c:\mcafee }
>
> A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
> C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it
> will be displayed in your browser (Opera, FireFox or Internet Explorer).
> However, if you are using WinXP, Win2K or Win2003 your system will be left in
> a state where you will have to manually shutdown/reboot the PC. On Win9x/ME
> platforms the report will not be shown in your bowser but your PC will
> automatically be shutdown. It is suggested that you move the report out of
> c:\mcafee before performing another scan.
>
> It would be best to scan in both Safe Mode and in Normal Mode and save a copy
> of the HTML report for each session.
>
>
> ALTERNATE:
>
> Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.
>
> http://secured2k.home.comcast.net/tools/AntiPuper.exe
>
> http://forums.mcafeehelp.com/viewtopic.php?t=65072
>
>
> Please Copy and Paste the contents of the HTML Log files;
> C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your
> reply.
>
> * * * Please report back your results * * *

NO, I have also tried all of your suggestion, and the suggestions on
ad-aware and spybot searcgh and destroy forums...

It now places a false message infront of Microsoft anti-spyware
notices, and when I run ad-aware & spybot search and destroy in safe
mode the number of problems is growing, I now have 64, when it was
only 8 early in the infection.

This company or indicvidual needs to be hunted down, and skined
alive...

I have sent notes to ad-aware, and spybot search & destroy... next is
the newsgroup for bit defender/anti-spyware...

Must have gotten a new varient from this person...

JR the postman



Posted by David H. Lipman on March 8, 2006, 6:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


|
| NO, I have also tried all of your suggestion, and the suggestions on
| ad-aware and spybot searcgh and destroy forums...
|
| It now places a false message infront of Microsoft anti-spyware
| notices, and when I run ad-aware & spybot search and destroy in safe
| mode the number of problems is growing, I now have 64, when it was
| only 8 early in the infection.
|
| This company or indicvidual needs to be hunted down, and skined
| alive...
|
| I have sent notes to ad-aware, and spybot search & destroy... next is
| the newsgroup for bit defender/anti-spyware...
|
| Must have gotten a new varient from this person...
|
| JR the postman
|

Well I am sorry to hear that there may be a new variant.
Both tools were updated recently for such a case.

The actual false messages of infection are based upon the ZLob, SmitFraud and a
couple of
other Trojans. Once they are present, usually installed via via WMF Exploit,
Sun Java
Exploit or Downloader Trojan, the SpyAxe, SpyFalcon, SpySheriff, SpyFighter,
SpyKiller,
SpywareStrike, et al, may subsequently be installed.

Download and execute HiJack This! (HJT)
http://www.spywareinfo.com/~merijn/files/HijackThis.exe

Create a HJT log file and post it in one of the below locations...

http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://forums.spywareinfo.com/index.php?showforum=18

After you make your post to one of the above, I would appreciate it if you could
provide me,
via email, the URL of your thread.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Postman delivers on March 8, 2006, 6:34 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
David H. Lipman formulated on Wednesday :
>
>
>>
>> NO, I have also tried all of your suggestion, and the suggestions on
>> ad-aware and spybot searcgh and destroy forums...
>>
>> It now places a false message infront of Microsoft anti-spyware
>> notices, and when I run ad-aware & spybot search and destroy in safe
>> mode the number of problems is growing, I now have 64, when it was
>> only 8 early in the infection.
>>
>> This company or indicvidual needs to be hunted down, and skined
>> alive...
>>
>> I have sent notes to ad-aware, and spybot search & destroy... next is
>> the newsgroup for bit defender/anti-spyware...
>>
>> Must have gotten a new varient from this person...
>>
>> JR the postman
>>
>
> Well I am sorry to hear that there may be a new variant.
> Both tools were updated recently for such a case.
>
> The actual false messages of infection are based upon the ZLob, SmitFraud and
> a couple of other Trojans. Once they are present, usually installed via via
> WMF Exploit, Sun Java Exploit or Downloader Trojan, the SpyAxe, SpyFalcon,
> SpySheriff, SpyFighter, SpyKiller, SpywareStrike, et al, may subsequently be
> installed.
>
> Download and execute HiJack This! (HJT)
> http://www.spywareinfo.com/~merijn/files/HijackThis.exe
>
> Create a HJT log file and post it in one of the below locations...
>
> http://www.bleepingcomputer.com/forums/forum22.html
> http://castlecops.com/forum67.html
> http://forums.spywareinfo.com/index.php?showforum=18
>
> After you make your post to one of the above, I would appreciate it if you
> could provide me, via email, the URL of your thread.

Dave, the machine is no-longer on line, but performing vinal signs for
race weekend, 24 hours a day currently. I will not be able to get to it
untill next tuesday to perform the hijack this procedure.

This particular infection evades all my cleaning attemps...

Also, this is the first infection of this kind I have seen there is no
way the average computer users is going to go to the trouble I have to
eliminate this malware...

I can only think it is a new varient, and hope someone locates this
individual or company rapidly.

Thanks dave I will notify you, the moment I can get in front of the
keyboard.

Could not post my info on spybot search & destroy contact page, it
would not accept any of my e-mail addresses, so I have not found a
method to contact them...

JR the postman



Similar ThreadsPosted
SpyAxe / SpywareStrike / SpyFalcon Removal Tool February 17, 2006, 8:20 am
Can't remove r.exe!!! June 24, 2005, 3:37 pm
how do I remove this? October 13, 2005, 2:37 pm
Tried KIS 6 and had to remove it September 25, 2006, 2:59 pm
How Do I Remove It? November 3, 2008, 6:23 pm
logjda.dll - how to remove? June 4, 2005, 6:27 am
WinFixer2005 - how to remove? September 26, 2005, 1:32 pm
How To Remove q5760749_disk.dll October 18, 2005, 10:39 am
how to remove ppdoor.fh December 7, 2005, 6:14 pm
cannot remove WebP2PInstaller.dll December 17, 2005, 12:19 am

The site map in XML format XML site map

Contact Us | Privacy Policy