SpyFalcon still won't go away?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Synnr, May 5, 2006.

  1. Synnr

    Synnr Private E-2

    Firstly, thank you Tim for responding to my account problem (stupid email), and to anyone who reads, pardon me, I think this is the proper way listed in the faq...



    Yesterday, I came home and when I brought my computer out of idle, I noticed this odd popup in the tray. After the first dozen popups in 20 seconds, I went looking for some way to get rid of it, since spybot and avg didnt seem to sense it. After following the instructions here (which are pretty much identical to all instructions I could find) I still have the little icon in the tray that keeps popping up. It seems to be slowly eatting system resources, and I can not use any program in full screen mode, since the popup kicks it to desktop. Per the instructions, I deleted the twain/twain32 stuff, as well as the spyfalcon file, however I was unable to locate the dxmpp.ddl file, which seems to be the big problem? and ginuerep.dll


    I would really appreciate any responses I can get, and I will attempt to get any of the info. I will post the system info and what not momentarily.
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Hi and Welcome to majorgeeks :)

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    In addition run SpyFalcon Removal Procedure

    Post teh smitfiles.txt in addition to the other logs.
     
  3. Synnr

    Synnr Private E-2

    Apologies, the scans took alot longer than I had thought

    Edit: I ran the spyfalcon removal procedure as listed, however I never found many of the files listed to delete, and the tray icon ( green handicapped fellow + red circle with a slash) is still there.
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Delete the following files:
    C:\WINDOWS\SYSTEM32\Process.exe
    C:\WINDOWS\SYSTEM32\regperf.exe

    Follow the directions for the following:
    Using GetRunKey
    Running WinPfind by OldTimer

    Post the runkey.txt and winpfind.txt files.
     
  5. Synnr

    Synnr Private E-2

    I deleted the process.exe file but did not find C:\WINDOWS\SYSTEM32\regperf.exe

    I wasnt sure exactly, so i followed the instructions for the windpfind.txt and copied it from the program screen. I can add the one that was in the file as well, if needed
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    OK, neither one of those, showed what I was looking for.

    From Normal Mode:

    Download roguescanfix.exe , and save it to your desktop.
    Double click roguescanfix.exe to install it.
    Open the roguescanfix folder, and doubleclick run.bat. Make Sure you have an active internet connection!
    Your desktop and icons will disappear and then reappear again, this is normal.
    Wait till the message "Completed script execution" appears, then click OK.
    Click "Exit" to close BFU.
    Click "OK" to start the SpywareQuake/Spyfalcon uninstaller, after that click "uninstall". Please wait until it is finished.
    WARNING: You will be asked to reboot your computer. Wait until the uninstallers did their job before clicking YES.
     
  7. Synnr

    Synnr Private E-2

    you mean in add/remove programs? I did that once before and it is no longer there...


    Edit: sorry i misunderstood and i executed the script... the damned icon is still popping up
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    No, I meant that I didn't see what I expected in the registry.
     
  9. Synnr

    Synnr Private E-2

    i thought it was meant to run the uninstaller in the add/remove programs, i executed the bfu thing and the freaking icon is still in the tray. This thing is a nightmare, i cant do anything without it popping up and minimizing any window i am using
     
  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You weren't supposed to executer BFU, you were supposed to exit it; and run the uninstaller when prompted.

    Give me a screen shot of your system tray. Spy Falcon shouldn't be this hard to uninstall.
     
  11. Synnr

    Synnr Private E-2

    after i exited bfu the first time, i was not prompted with anything. I waited for a little while and nothing happened, so i thought it meant i was supposed to execute the file listed.... sorry
    Here are the pictures, i took two to show the 2 different flashes of it
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just updated the GetRunKey program! Please goto the link Shadow gave you in message number 4 and re-download the GetRunKey.Zip file again. It is now version 1.33.

    Run it and attach a new log. You may have a file named reglogs.dll hiding.
     
  13. Synnr

    Synnr Private E-2

    I did as you asked. The notepad file had reglogs.dll listed i think..

    edit: sorry misspelled
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  15. Synnr

    Synnr Private E-2

    This is the new smitfile. The spyfalcon icon in the system tray seems to be gone! I rebooted twice to see if anything magically came back, but nothing so far! Thank you so much, but can I ask how you figured it was that reglogs thing?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    I already new there was a new form out that used the reglogs.dll file. Lately, 1 or 2 new forms are coming out per week. That was why I was working on changing GetRunKey and also the SpywareQuake/SpyFalcon removal procedure. I just figure since what Shadow had been trying with you was not working that you must have the new form. Thus I figured it would be a good test of my new version of GetRunKey and also of the sticky thread removal procedure.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  17. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Thanks, chas.

    I thought that this might have been a new variant.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! I saw the opportunity to try out my new version of GetRunKey and also my new fix and took advantage of it. ;) I'm glad it worked!

    Another new version of GetRunKey will be up later tonight with some minor tweaks.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds