Register   FAQ   Login  

Spyfalcon refuses to die





AddThis Social Bookmark Button AddThis Feed Button

Goto page Previous  1, 2
       2-spyware forum index -> Removal of spyware, adware and other parasites
Author Message
BigH



Joined: 07 May 2006
Posts: 2

Post Post subject: Reply with quote

Me too I got rid of it once with SmitfraudFix but this time I can't get rid of the flashing icon in the system tray or the silly popup warning sign. I hope someone comes up with something soon it's driving me potty.
Sun May 07, 2006 1:29 am
Back to top
BigH View user's profile Send private message
 
BigH



Joined: 07 May 2006
Posts: 2

Post Post subject: Reply with quote

Yes ! Got rid of it _ I read GTO's message to butterfly and found reglogs.dll in C:\WINDOWS\system32 then renamed it reglogs.dll.txt then deleted it.

Many thanks GTO Smile
Sun May 07, 2006 10:55 am
Back to top
BigH View user's profile Send private message
 
Jaxxx



Joined: 08 May 2006
Posts: 1

Post Post subject: Spy falcon & dll removal Reply with quote

On May 4, 2006 I was infected with the Spy Falcon spyware. I had a new copy of Spyware Doctor and immediately used it. It didn't clear it completely. I still had the tray wheel chair and the "about:blank" home screen. I also googled for Spy Falcon and used Tech Spot, and in turn Panda's freeware, hijackthis, and smitfraud.exe. I still had the wheel chair w/balloon warnings and the diverted home page. This morning I ran Spyware Doc again and it removed 28 more items. My e-mails to Spyware Doctor and malware report sendings were never answered. I was stilll not completely cured. I googled "about:blank" and accessed 2-Spyware.com. Boy, am I glad. I looked up all the items on your main removal page, deleted a few (easily) .exe, and .dll. Then found the called evil reglogs.dll. It was 173K and I knew he was the one. So, I followed your cmd directions and the response was very disappointing: I got a popup with a yellow triangle w/exclamation point that said:
RegSvr32
"reglogs.dll was loaded, but the DllunregisterServer entry point was not found.
This file can not be registered."

I was crestfallen ,but determined. I went into your forum until I saw a way that was recommended for someone else: killbox.exe. I followed the directions and it did the job. Then I ran Spywear Doctor again -- nothing further came up. Now I am waiting for the other shoe to drop. Question 1: Am I really clean? How can I verify this -- run hijackthis and submit it to 2-Spyware? Question 2: What did I do wrong when I could not remove the dll in the cmd function? Question 3: How do I avoid this happening again? Question 4: I doubt seriously that I will curtail my eclectic curosity anytime soon, so is it inevidable that something like this will happen to me again? Question 5: The run...commands remind me of old DOS. Is there a book that you can recommend that covers them or should I just unearth that old DOS ver. 6 book for Dummies? Thanks for the neat site, and all the help. Jaxxx
Tue May 09, 2006 3:04 am
Back to top
Jaxxx View user's profile Send private message Send e-mail
 
GTO



Joined: 15 Nov 2005
Posts: 1519

Post Post subject: Reply with quote

Hi, Jaxxx. Welcome to the 2-Spyware.com forums!

Here are the answers to your questions:

Question 1: Am I really clean? How can I verify this -- run hijackthis and submit it to 2-Spyware?

Answer: Download the HijackThis program and run a system scan. Then create a new topic in the HijackThis log analaysis section and post your log there. It will be checked by the HJT Analyzer, an automatic analyzer and forum responders.

Question 2: What did I do wrong when I could not remove the dll in the cmd function?

Answer: The unregistering procedure provided in removal instructions is not necessary. Well, even some removal steps aren't necessary too. They are provided for all possible situations. This means that if you cannot delete/terminate the file, try unregistering it. If you cannot unregister - delete or terminate it and vice versa. Furthermore, not all the files provided in removal instructions might actually be in your system. Just make sure you have none of those files.

Question 3: How do I avoid this happening again?

Answer: Use the most safest software available. Browser the Internet with Mozilla Firefox or Opera instead of Internet Explorer. Install an advanced firewall like Zone Labs ZoneAlarm. Use up-to-date antivirus and anti-spyware software. And of course, you should know how to avoid spyware infections.

Question 4: I doubt seriously that I will curtail my eclectic curosity anytime soon, so is it inevidable that something like this will happen to me again?

See the answer to Question 3.

Question 5: The run...commands remind me of old DOS. Is there a book that you can recommend that covers them or should I just unearth that old DOS ver. 6 book for Dummies?

The Command Prompt understands the same old commands that was used under the MS-DOS 6 environment. The book you have is more than enough.
Tue May 09, 2006 10:30 am
Back to top
GTO View user's profile Send private message
 
readersdigest



Joined: 13 May 2006
Posts: 6

Post Post subject: Re: fixed Reply with quote

prodigal wrote:
my AVG Free edition anti virus software updated this morning and has removed the little fella all happy Smile


really ? Confused my avg doesnt find very much atall. and yes i have updated it. all the time.

im in the same boat as most other poeple here, still got the icon in the system tray. ima try doing that renaming thing in a sec, read BigH's post:

Yes ! Got rid of it _ I read GTO's message to butterfly and found reglogs.dll in C:\WINDOWS\system32 then renamed it reglogs.dll.txt then deleted it.

Many thanks GTO


well if that doesnt work then i guess im screwed.

really good way of getting money though. you can find his phone number and address somewhere on the net, why not prank him Wink or even send him a letter bomb. anyways ima go do what bigh did.
Sat May 13, 2006 12:09 pm
Back to top
readersdigest View user's profile Send private message
 
r0an



Joined: 13 May 2006
Posts: 4

Post Post subject: Reply with quote

Hi guys

Seems im in the same boat. Tried all the above to noavail. Tried system restore, but it wont allow me. Got to the stage where I thought I would reinstall but I get this stop msg:

Quote:
a problem has been detected and windows has been shut down to prevent damage to your computer.

if this is the first time you have seen this stop error screen, restart your computer. if this screen appears again, follow these steps

check for viruses on your computer. remove any newly installed hard drives or hard drive controllers. check your hard drive to make sure it is properly configured and terminated.

run CHKDSK /F to check for hard drive corruption, and then restart your computer.

***STOP: 0x0000007B (0xF7C7A524, 0xC0000034, 0x00000000, 0x00000000)


cant get chkdsk to run, have tried avg, cant find reglogs.dll....

any help very much appreciated, I only want to reinstall now

thx
Sat May 13, 2006 3:37 pm
Back to top
r0an View user's profile Send private message
 
readersdigest



Joined: 13 May 2006
Posts: 6

Post Post subject: Reply with quote

WgaTray.exe, a process in task manager

anyone else have that ? i end it and it keeps poping up again. was thinking that it might be somehting to do with it............this is begining to annoy me now.

i hope some gets back to this soon.
Sat May 13, 2006 11:24 pm
Back to top
readersdigest View user's profile Send private message
 
GTO



Joined: 15 Nov 2005
Posts: 1519

Post Post subject: Reply with quote

Hi, readersdigest.

The wgatray.exe file is a legitimate system component. It is a part of Windows Genuine Advantage Notification, a special tool that checks whether your copy of Windows is genuine, or pirated. You shouldn't terminate this process.
Sun May 14, 2006 10:55 am
Back to top
GTO View user's profile Send private message
 
       2-spyware forum index -> Removal of spyware, adware and other parasites All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




Recommended software:
Spyware Doctor
(91/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and easy-to-manage...
Malwarebytes Anti Malware
(89/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t have many features. One such...
Spy Sweeper
(85/100)
Spy Sweeper is one of the most powerful and effective spyware removers available today. This Webroot Software's product uses unique, patent-pending parasite detection and removal...
Windows Defender
(80/100)
Windows Defender is a free anti-spyware program made by the leading software company to add native spyware protection to its most popular product - the Microsoft Windows operating...
SUPERAntiSpyware
(75/100)
SUPERAntiSpyware is a powerful, highly effective spyware remover introducing advanced parasite detection and removal features along with reliable real-time protection. The program is not...
Encyclopedia of parasites: