Hi Lily - SpyFalcon can be difficult to remove. If you're computer astute
or have access to someone who is, you can try it by yourself using the
following procedure. Otherwise you may want to get some assistance at one
of the HJT forums (See the HiJackThis info following this):
Courtesy of MVP "PA Bear":
"SpyFalcon
Oh, yes. Here's the tried & true removal procedure:
http://www.bleepingcomputer.com/forums/topic43659.html (NG:
C:\Windows\System32\ginuerep.dll was only identified in the past week, a
signature of very recent SpyFalcon infections).
Follow up:
1. Delete the files found by Panda Active Scan which it couldn't disinfect;
2. Reboot into Safe Mode;
3. Use HijackThis to "fix" any remaining Bad Guys;
4. Delete unwanted folders containing the files in Step 1.
5. Reboot into Windows.
6. Delete TIF, TEMP & XP Prefetch in all User Profiles;
7. "Flush" System Restore (WinXP, WinME)
8. Run another Active Scan, for safety's sake."
Here's the HijackThis info you may need:
Download HijackThis, free, here:
http://www.merijn.org/files/hijackthis.zip (Always download a new
fresh copy of HijackThis [and CWShredder also] - It's UPDATED frequently.)
You may also get it here if that link is blocked:
http://www.majorgeeks.com/downloadget.php?id=3155&file=3&evp=3304750663b552982a8baee6434cfc13
There's a good "How-to-Use" tutorial here:
http://computercops.biz/HijackThis.html
In Windows Explorer, click on Tools|Folder Options|View and check "Show
hidden files and folders" and uncheck "Hide protected operating system
files". (You may want to restore these when you're all finished with
HijackThis.)
Place HijackThis.exe or unzip HijackThis.zip into its own dedicated folder
at the root level such as C:\HijackThis (NOT in a Temp folder or on your
Desktop), reboot to Safe mode, start HT then press Scan. Click on SaveLog
when it's finished which will create hijackthis.log. Now click the Config
button, then Misc Tools and click on Generate StartupList.log which will
create Startuplist.txt
Then go to one of the following forums:
Spyware and Hijackware Removal Support, here:
http://forums.spywareinfo.com/
or Jim Eshelman's site here:
http://forum.aumha.org/
or Bleepingcomputer here:
http://www.bleepingcomputer.com/
or Computer Cops here:
http://www.computercops.biz/forums.html
or Tom Coyote here:
http://forums.tomcoyote.org/index.php?act=idx
or Net-Integration here:
http://net-integration.us/forums/index.php
Register if necessary, then sign in and READ THE DIRECTIONS at the beginning
of the particular site's HiJackThis forum, then copy and paste both files
into a message asking for assistance, Someone will answer with detailed
instructions for the removal of your parasite(s). Be sure you include at
the beginning of your post a description of "What specific
problem(s)/symptoms you're trying to solve" and "What steps you've already
taken."