Remove SpyFalcon

  • Thread starter Thread starter Postman delivers
  • Start date Start date
P

Postman delivers

Removing this rouge spyware program? It has eliminated a methiod from
me to get into restore, and after removing with spybot search and
destroy, it returns.

Is there a simple solution to removing this spyware, or malware?

JR the postman
 
From: "Postman delivers" <[email protected]>

| Is there a simple solution to removing this spyware, or malware?




Two part reply..

Perform Part 1 then perform Part 2.

If the first two parts don't work, perform the alternate utility.

It is suggested that you execute each tool in Normal Mode then in Safe Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE
Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0 Update 6
be installed ASAP.

http://www.java.com/en/download/manual.jsp



Part 1
-----------

Use noahdfear's SmitFraud and SpyAxe removal tool -- SmitRem.exe
http://noahdfear.geekstogo.com/click counter/click.php?id=1

http://www.bleepingcomputer.com/forums/topic43659.html


Part 2
-----------

Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your FireWall to enable WGET.EXE to download the needed McAfee related
files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it
will be displayed in your browser (Opera, FireFox or Internet Explorer).
However, if you are using WinXP, Win2K or Win2003 your system will be left in a
state where you will have to manually shutdown/reboot the PC. On Win9x/ME
platforms the report will not be shown in your bowser but your PC will
automatically be shutdown. It is suggested that you move the report out of
c:\mcafee before performing another scan.

It would be best to scan in both Safe Mode and in Normal Mode and save a copy of
the HTML report for each session.


ALTERNATE:

Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.

http://secured2k.home.comcast.net/tools/AntiPuper.exe

http://forums.mcafeehelp.com/viewtopic.php?t=65072


Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your reply.

* * * Please report back your results * * *
 
David H. Lipman expressed precisely :
Two part reply..

Perform Part 1 then perform Part 2.

If the first two parts don't work, perform the alternate utility.

It is suggested that you execute each tool in Normal Mode then in Safe Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE
Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0
Update 6 be installed ASAP.

http://www.java.com/en/download/manual.jsp



Part 1
-----------

Use noahdfear's SmitFraud and SpyAxe removal tool -- SmitRem.exe
http://noahdfear.geekstogo.com/click counter/click.php?id=1

http://www.bleepingcomputer.com/forums/topic43659.html


Part 2
-----------

Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your FireWall to enable WGET.EXE to download the needed McAfee
related files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it
will be displayed in your browser (Opera, FireFox or Internet Explorer).
However, if you are using WinXP, Win2K or Win2003 your system will be left in
a state where you will have to manually shutdown/reboot the PC. On Win9x/ME
platforms the report will not be shown in your bowser but your PC will
automatically be shutdown. It is suggested that you move the report out of
c:\mcafee before performing another scan.

It would be best to scan in both Safe Mode and in Normal Mode and save a copy
of the HTML report for each session.


ALTERNATE:

Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.

http://secured2k.home.comcast.net/tools/AntiPuper.exe

http://forums.mcafeehelp.com/viewtopic.php?t=65072


Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your
reply.

* * * Please report back your results * * *

NO, I have also tried all of your suggestion, and the suggestions on
ad-aware and spybot searcgh and destroy forums...

It now places a false message infront of Microsoft anti-spyware
notices, and when I run ad-aware & spybot search and destroy in safe
mode the number of problems is growing, I now have 64, when it was
only 8 early in the infection.

This company or indicvidual needs to be hunted down, and skined
alive...

I have sent notes to ad-aware, and spybot search & destroy... next is
the newsgroup for bit defender/anti-spyware...

Must have gotten a new varient from this person...

JR the postman
 
From: "Postman delivers" <[email protected]>


|
| NO, I have also tried all of your suggestion, and the suggestions on
| ad-aware and spybot searcgh and destroy forums...
|
| It now places a false message infront of Microsoft anti-spyware
| notices, and when I run ad-aware & spybot search and destroy in safe
| mode the number of problems is growing, I now have 64, when it was
| only 8 early in the infection.
|
| This company or indicvidual needs to be hunted down, and skined
| alive...
|
| I have sent notes to ad-aware, and spybot search & destroy... next is
| the newsgroup for bit defender/anti-spyware...
|
| Must have gotten a new varient from this person...
|
| JR the postman
|

Well I am sorry to hear that there may be a new variant.
Both tools were updated recently for such a case.

The actual false messages of infection are based upon the ZLob, SmitFraud and a couple of
other Trojans. Once they are present, usually installed via via WMF Exploit, Sun Java
Exploit or Downloader Trojan, the SpyAxe, SpyFalcon, SpySheriff, SpyFighter, SpyKiller,
SpywareStrike, et al, may subsequently be installed.

Download and execute HiJack This! (HJT)
http://www.spywareinfo.com/~merijn/files/HijackThis.exe

Create a HJT log file and post it in one of the below locations...

http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://forums.spywareinfo.com/index.php?showforum=18

After you make your post to one of the above, I would appreciate it if you could provide me,
via email, the URL of your thread.
 
David H. Lipman formulated on Wednesday :
Well I am sorry to hear that there may be a new variant.
Both tools were updated recently for such a case.

The actual false messages of infection are based upon the ZLob, SmitFraud and
a couple of other Trojans. Once they are present, usually installed via via
WMF Exploit, Sun Java Exploit or Downloader Trojan, the SpyAxe, SpyFalcon,
SpySheriff, SpyFighter, SpyKiller, SpywareStrike, et al, may subsequently be
installed.

Download and execute HiJack This! (HJT)
http://www.spywareinfo.com/~merijn/files/HijackThis.exe

Create a HJT log file and post it in one of the below locations...

http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://forums.spywareinfo.com/index.php?showforum=18

After you make your post to one of the above, I would appreciate it if you
could provide me, via email, the URL of your thread.

Dave, the machine is no-longer on line, but performing vinal signs for
race weekend, 24 hours a day currently. I will not be able to get to it
untill next tuesday to perform the hijack this procedure.

This particular infection evades all my cleaning attemps...

Also, this is the first infection of this kind I have seen there is no
way the average computer users is going to go to the trouble I have to
eliminate this malware...

I can only think it is a new varient, and hope someone locates this
individual or company rapidly.

Thanks dave I will notify you, the moment I can get in front of the
keyboard.

Could not post my info on spybot search & destroy contact page, it
would not accept any of my e-mail addresses, so I have not found a
method to contact them...

JR the postman
 
From: "Postman delivers" <[email protected]>


|
| Dave, the machine is no-longer on line, but performing vinal signs for
| race weekend, 24 hours a day currently. I will not be able to get to it
| untill next tuesday to perform the hijack this procedure.
|
| This particular infection evades all my cleaning attemps...
|
| Also, this is the first infection of this kind I have seen there is no
| way the average computer users is going to go to the trouble I have to
| eliminate this malware...
|
| I can only think it is a new varient, and hope someone locates this
| individual or company rapidly.
|
| Thanks dave I will notify you, the moment I can get in front of the
| keyboard.
|
| Could not post my info on spybot search & destroy contact page, it
| would not accept any of my e-mail addresses, so I have not found a
| method to contact them...
|
| JR the postman
|

JR:

Whatever is done in erradication it is a catchup game. After removal instructions are
implemented and found to work, the malware writers create a new variant and the cycle begins
again.

It is only through an interactive session in an expert forum where a new course of actions
can be created or an expert is able to replicate the installation of the malware and trace
the OS changes. I know the people in the suggested forums and there are those there that
what will do what they can to help you.

I am no expert, I just do my best to get details from the experts and then try to script the
removal process.

Just realize that this class of malware is installed via vulnerabilities and you need to
make sure the affected computer has all vulnerabilities mitigated.
 
David H. Lipman expressed precisely :

NO, I have also tried all of your suggestion, and the suggestions on
ad-aware and spybot searcgh and destroy forums...

It now places a false message infront of Microsoft anti-spyware
notices, and when I run ad-aware & spybot search and destroy in safe
mode the number of problems is growing, I now have 64, when it was
only 8 early in the infection.

This company or indicvidual needs to be hunted down, and skined
alive...

I have sent notes to ad-aware, and spybot search & destroy... next is
the newsgroup for bit defender/anti-spyware...

Must have gotten a new varient from this person...

JR the postman
My father-in-law's PC picked this up. I followed the advice given in
the same pages (and elsewhere) above three times but the system tray
nag would not go and the whole damn thing just kept coming back.
Eventually I found a file in the system32 folder from around the date
of the infection called genuirep.dll which showed no company
attributes of any kind. Renamed it and the system tray nag stopped. I
then searched the registry for the same file name and found an entry
for it and deleted it but sorry, I can't remember where it was!

Next I followed the instructions at
http://www.spywaredb.com/remove-spyfalcon/ and finally seemed to have
got rid of it. I also found a load of infected java files, which is
probably where this thing got in, after various online virus scans.
Uninstalling all Java versions, deleting the infected files and
installing the latest version seems to have got shot of them but there
were a number of other trojans found on the system. Panda and
Kaspersky online scans picked these up but they needed manual removal
afterwards. Their dates suggest they all got onto the system around
the same time.

The system did have Zone Alarm but it had been uninstalled at some
point.

John
 
John was thinking very hard :
My father-in-law's PC picked this up. I followed the advice given in
the same pages (and elsewhere) above three times but the system tray
nag would not go and the whole damn thing just kept coming back.
Eventually I found a file in the system32 folder from around the date
of the infection called genuirep.dll which showed no company
attributes of any kind. Renamed it and the system tray nag stopped. I
then searched the registry for the same file name and found an entry
for it and deleted it but sorry, I can't remember where it was!

Next I followed the instructions at
http://www.spywaredb.com/remove-spyfalcon/ and finally seemed to have
got rid of it. I also found a load of infected java files, which is
probably where this thing got in, after various online virus scans.
Uninstalling all Java versions, deleting the infected files and
installing the latest version seems to have got shot of them but there
were a number of other trojans found on the system. Panda and
Kaspersky online scans picked these up but they needed manual removal
afterwards. Their dates suggest they all got onto the system around
the same time.

The system did have Zone Alarm but it had been uninstalled at some
point.

John

John,

Thanks for the info...

JR the postman
 
Back
Top