Title: SpyFalcon
Type: Trojans

Remove SpyFalcon. Removal instructions


 
Also known as: Spy Falcon
Severity scale:SpyFalcon severity is 70  (70 / 100)
 
SpyFalcon is a trojan that displays an icon in the system tray. This icon shows a message, which says that the compromised computer is infected with dangerous spyware parasites and asks the user to download and install a removal program, which actually is Spy Falcon, corrupt illegally distributed spyware remover. Once the user clicks on such message, the trojan opens a web site distributing SpyFalcon. It may also try to download the application. The trojan is able to change the Internet Explorer default home page and redirect the web browser to malicious web sites. SpyFalcon automatically runs on every Windows startup.

SpyFalcon properties:
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic SpyFalcon removal:

SpyHunter is recommended remover to uninstall SpyFalcon. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manul removal instructions below.

If you failed to remove SpyFalcon using SpyHunter please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
STOPzilla
We are testing STOPzilla's efficiency at removing SpyFalcon (2006-09-17 05:46:25)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing SpyFalcon (2006-09-17 05:46:25)
Spyware Doctor
We are testing Spyware Doctor's efficiency at removing SpyFalcon (2006-09-17 05:46:25)
XoftSpySE Anti Spyware

SpyFalcon manual removal:

Kill processes:
atmclk.exe, dcomcfg.exe, dfrgsrv.exe, mscornet.exe, mssearchnet.exe, nvctrl.exe, spyfalcon.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpyFalcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D}
HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{244B730E-D899-4E38-9428-03D1143242E0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SpyFalcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyFalcon
Unregister DLLs:
appmagr.dll, bolnyz.dll, dxmpp.dll, fyhhxw.dll, ginuerep.dll, higjxe.dll, htey.dll, iqzv.dll, oerucu.dll, oqipt.dll, reglogs.dll, sbnudh.dll, twain32.dll, ulztc.dll

Delete files:
atmclk.exe, dcomcfg.exe, dfrgsrv.exe, mscornet.exe, mssearchnet.exe, nvctrl.exe, spyfalcon.exe, appmagr.dll, bolnyz.dll, dxmpp.dll, fyhhxw.dll, ginuerep.dll, higjxe.dll, htey.dll, iqzv.dll, oerucu.dll, oqipt.dll, reglogs.dll, sbnudh.dll, twain32.dll, ulztc.dll, sf.ini, hp[X].tmp, ld[X].tmp
Delete directories:
C:\Program Files\SpyFalcon
C:\Documents and Settings\[Current User]\Start Menu\Programs\SpyFalcon
Misc:
[X] is a combination of four random characters.

Exact file location:
spyfalcon.exe, sf.ini - C:\Program Files\SpyFalcon
atmclk.exe, dcomcfg.exe, dfrgsrv.exe, mscornet.exe, mssearchnet.exe, nvctrl.exe, hp[X].tmp, ld[X].tmp, appmagr.dll, bolnyz.dll, dxmpp.dll, fyhhxw.dll, ginuerep.dll, higjxe.dll, htey.dll, iqzv.dll, oerucu.dll, oqipt.dll, reglogs.dll, sbnudh.dll, twain32.dll, ulztc.dll - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Domain Name: SPYFALCON.COM (195.225.176.79)
Registrant:
SunShine Ltd
David Taylor
U-12 Gamma Commercial Complex # 47
Rizal Highway cor. Manila Ave Subic Bay
Olongapo City
null, 98101, PH
Tel. +206.9543154

Other domains at the same IP address:
Spyfalconupdate.com
Updateyourwindows.com

AVOID THESE DOMAINS AND THESE IPs! Better block it in your hosts File.
Information added: 2006-02-09 11:58:02
Information updated: 2006-09-17 03:09:10

Additional resources related to SpyFalcon:

Attention: If you know or you have a website or page about SpyFalcon removal, feel free to add a link to this list: add url

more resources
0
0
Guest
Thank you Thank you Thank you, this document helped me get rid of a real PITA spyware.
0
0
Guest
thanks for all the help.
0
0
Guest
many thanks for all the help - been trying to remove this and spywarestrike from a friends laptop for 2 days - these pages got rid of both of them in minutes.
0
0
Guest
spyfalcon is dead! a nasty one that was. thanks for helping me remove it! thank you indeed!!
0
0
Guest
Thank you, thank you, thank you ! ! !

The manual removal instructions made it!

all spyware programs will not update and communicate on the net as Spyfalcon, blocks just about everything you want to do ...

Next step is to find out what f-secure is really worth!!!

Used to have Zone Labs and after I installed spy and ad ware I never ever had any troubles on the net, although with my printer ...

Cheers
0
0
Guest
from switzerland
thank you twice
keep going on
0
0
Guest
holy crap thanks.

this is the worst spy/adware/virus ive ever had and it sucks. and why is this company not shut down?!?!?!

thanks al fixed
0
0
Guest
From: The Heart of the South, USA

Endless thanks to you.
I feel confident enough in my meager computer skills to tinker with the inner workings of Windows, but without this, I would have been lost without knowing where to start.

This spyware is a Cancer. Without caution in "surgery," so to speak, it will grow back.

Several recomendations I would like to make:

SpyFalcon is a disease that fights back, so cut to the chase. Restart and go into safe mode. (I selected "Administrator" at the welcome screen, allowing me to access all users.) Doing so will allow you to "sneek up on it" unawares, and catch it with its guard down. Start the step to "Kill Processes," but in Safe Mode, it is unlikely that any of them will be active.

Under the step "Unregister DLLs," perform a Windows search for "dxmpp.dll" first. The results will give you the path extention to look for.

During the "Delete Files" step I thought it might be problematic to find the hp[X].tmp and the ld[X].tmp files since they have variable entry names. I performed a Windows search again, but I entered the file type (.tmp) in the text box which brought up all entries with the .tmp extention. This, I found, served two purposes. First, it made it easier to find them, but secondly, also I found multiple iterations of both files! (Likely the result of my initial unsuccessfull attempts at its removal.)

Lastly, during the "Delete Directories" step, I checked all the users, not just the [Current User]. I found nothing in the others, but there is no telling what may occur in other computers and infections. (Having enabled "Show Hidden Files and Folders," I found that there were other hidden "Users." Probably just a functionality aspect of Windows, not real users, but I checked them anyway.)

Good luck to everyone who has suffered this problem. You can get through it.
0
0
Guest
thank you followed steps and spyware is gone...had to boot in safe mode to delete dxmpp.dll but its gone now without format thank you
0
0
Guest
thank you followed steps and spyware is gone...had to boot in safe mode to delete dxmpp.dll but its gone now without format thank you
0
0
Guest
Thanks a million. I called Norton, they wanted to charge me $40.00 to remove the spy falcon over the phone. You saved my computer. THANKS!!
0
0
Guest
I used the software to kill spyfalcon but i still have a virus alert in my sys tray. cant get rid of it
0
0
Guest
After running 4 major antispyware programs... in safe mode... without sytem restore active... and seeing "Files Removed Successfuilly" I still had the Spy Falcon program.

Win XP
I started in SAFE MODE with COMMAND PROMPT
I went to the PROGRAM FILES folder where SPY FALCON resides

I took a peek at the contents of the Spy Falcon folder and found that there were several more files listed than what appears in normal Windows mode. Including a couple of DLLs and a 54kb txt blacklist text file.

Step back to the PROGRAM FILES folder if you were curious enough to take a peek at the contents.

REMDIR SPYFALCON /S

This REMoves the DIRectory and all Subfolders.

Thats it.. over and done with. The two DLLs listed came up with mixed results
- Yahoo programs
- Microsoft necessary files
- Spy Axe, Spy Falcon, Backdoor trojan DLL

The key factor is WHERE these files are located.

I hope this helps speed along someone elses recovery.
0
0
Guest
is there any spyware remover that is free
0
0
Guest
i have removed all files except for ld(X).tmp. I remove it in safe mode, but it keeps reappearing after full start. Spybot also keeps catvhing a vcodec file called ncompat.tlb. Is there a relationship between these two files?
0
0
Guest
Thank YOU Very Much! EveryThing Is SoFar so Good! Be Blessed With Thy Works!:)
0
0
Guest
I hate these people. How dare they, I think they should be flogged in the public square. Thanks to you guys. I installed Spydoctor and got my moneys worth, it found numerous spyware stuff and got rid of this cancer in 4 minutes flat. It now runs in the background watching vigilantly for this kind of creepy stuff.
0
0
Guest
This worked for me great!! Thx
0
0
Guest
thankyou thankyou thankyou. This one was driving me nuts. I hate these kind of companies. you guys are the very best!
0
0
Guest
1-800-753-4183 support@psbill.biz authorized Payment Service Provider

The above is the payment service provoder for SpyFalcon, seems to me if everyone called the 800 number several times a day without ordering then the phone bill would eventually cause them to stop supporting SpyFalcons efforst also if you flood the mail box with nasty letters then some of this crap might stop... to me it would be worth paying the assalt charge to find these jerks that developed SpyFalcon and give them a real virus that would land them in a real hospital...
0
0
Guest
Ok, this worked just fine in getting rid of the SpyFalcon parasite, and those annoying Virus Alert! messages. Thank you, thank you.

However, whenever I delete ld[X].tmp in Safe Mode, it reappears after I restart, with a new random 4-character string. I guess this means that there iss still something on my system that keeps creating this file.

Does anyone know how to stop this file from reappearing? I have to go to bed.
0
0
Guest
A litte amendment to the previous post: BOTH ncompat.tld AND ld[X].tmp keep reappearing after system restart.

It doesnt seem to happen if you restart back into Safe Mode, so there must be something in the startup sequence that can be disabled to prevent these two files from cropping up again.
0
0
Guest
Thank you so much for the guidelines to remove Spyfalcon. You saved me money had I contacted Microsoft.
Boy this damn trojan causes dialer to start up and disconnect when trying to download scan engines and Task Manager window has no X at right top to close it. Only way to close TM is in the tray. Also, the dialer disconnects when activated. This is a hell of a problem until one can safely remove this program, then my computer runs normally. By the way, Netscape did not default to Spyfalcon web page, only IE.
Thanks Again
0
0
Guest
I think i have succeeded in removing spyfalcon (all spyfalcon registry keys, files, etc gone) but still it shows the icon in system tray. Also, it doesnt try to download itself anymore, eventhough i turn firewall off. Also spyware doctor doesnt find it anymore. Am i free of spyfalcon? is the icon in system tray something i just have to live with? (the icon can be hidden in XP)
0
0
Guest
ok hey thanks you so much i followed this
Win XP
I started in SAFE MODE with COMMAND PROMPT
I went to the PROGRAM FILES folder where SPY FALCON resides

I took a peek at the contents of the Spy Falcon folder and found that there were several more files listed than what appears in normal Windows mode. Including a couple of DLLs and a 54kb txt blacklist text file.

Step back to the PROGRAM FILES folder if you were curious enough to take a peek at the contents.

REMDIR SPYFALCON /S

This REMoves the DIRectory and all Subfolders.

Thats it.. over and done with. The two DLLs listed came up with mixed results
- Yahoo programs
- Microsoft necessary files
- Spy Axe, Spy Falcon, Backdoor trojan DLL

The key factor is WHERE these files are located.

I hope this helps speed along someone elses recovery.







and didnt grab any virus removal programs but i still got the windows world and that red X popping up do you know how i can remove it it keeps pooping up with messages
0
0
Guest
"I think i have succeeded in removing spyfalcon (all spyfalcon registry keys, files, etc gone) but still it shows the icon in system tray. Also, it doesnt try to download itself anymore, eventhough i turn firewall off. Also spyware doctor doesnt find it anymore. Am i free of spyfalcon? is the icon in system tray something i just have to live with? (the icon can be hidden in XP)"

Edit: The icon is gone... i dont know how and why but its gone... im so 1337 :D
0
0
Guest
I have cleaned my PC of all the above files, checked several times, and the flashing icon still remains... Hmm...I do hope it just disapears like the other guys did...
0
0
Guest
This is a real pain in the neck Spy -Ware i had it on my system for some time removing it in add remove programmes only to find it getting back in and restarting and those annoying icons in the system tray as well as those pop ups which contain dummy files of websites you have visited. The persons who are responsible for this threat should be reported to the Police or your ISP as they are breaking the Law and are stealing information from you.
I have however finally removed this rubbish from my P.C and no longer have those annoying icons in the system tray popping up every now and again.
0
0
Guest
Restart P.C in safe mode Delete SF in Add/Remove programmes. Then go to C:programmes find file for SF delete it if its there. then go to C;Windows/ system 32 and find this file dxmpp.dll delete it. If you cannot delete it Log Out and Log in on administrator find the file again and delete it. Before coming out or restarting your P.C click all programmes/Accessories/ System tools/Disc Clean Up. Allow the programmes to work depending on the size of your drive and files upon it. Once done restart P.C and you should find now SF is gone as well as those icons in system tray.
0
0
Guest
Some of the names of the fils in the index appear to have been changed. I could not locate several of them.
0
0
Guest
Hey I found that if you delete ginuerep.dll
that will get rid of that stupid red dot wirh the x thing in the tray. do not forget to do this in safe mode.
Cheers
0
0
Guest
Thank you. I had SpyFalcon. it made me mad .
Thank you.
0
0
Guest
i cant get rid of the red x it keeps alerting me of a virus how can i delete this i tryed to delete the fiole ginuerep.dll but it wouldnt let me someone please help
0
0
Guest
Sign on as administrator then delete ginuerep.dll. Worked for me, too.
0
0
Guest
thanks a lot.
0
0
Guest
Can not locate the dxmpp.dll file!
0
0
Guest
I did not have dxmpp.dll either, only ginuerep.dll. I never clicked the red x to d/l the Spyfalcon program and had no dxmpp.dll, any of the other files or registry changes.
0
0
Guest
Call the 800 number from a payphone, it costs them 80 cents per call. After it connects, dial again. Repeat for every time you had to reboot!
0
0
Guest
If you were a woman i would definitely kiss you! Thank you thank you thank you!
0
0
Guest
well here is what I have so far, I did the manual removal, and cleared my system, however, it came back the very next day... well after watching the started and seeing where what programs load into, I found that all these files load into explorer.exe so I opened taskman and closed explorer, and did not reopen it. Then I startedto remove the files, to no avail, they just came back.
0
0
Guest
I was able to fix my version with the following
- boot to safe mode
- use process explorer (sysinternals) to kill the thread module running in "explorer.exe" called
ginuerep.dll, this process is the one that keeps rewriting the registry keys. just locate it on the threads tab and push the kill button for the module.

- delete all files listed above, would not delete ginuerep.dll, delted all *.tmp from system32
- follow all instructions above and delete all instances of "ginuerep.dll" in the registry
- denied everyone full control to the file ginuerep.dll with NTFS (got error, but it worked)
- reboot to safe mode again and now I was able to delete ginuerep.dll. after that reboot normally and it should be gone

- also go to control panelinternet options and change the home page back
- then in XP SP2 or higher, go to "manage add ons" and disable the security toolbar

you may also want to check the default search settings or other possible redirection
0
0
Guest
Managed to delete SpyFalcon after much frustration and many tries. Norton Antivirus (Symantec), Windows Defender – Beta 2 (Microsoft), and Ad Aware (Lavasoft) all seemed to work about equally well. All left ginuerep.dll untouched. The latter two are free. IMPORTANT: The computer must be in the COMMAND PROMPT version of Safe mode to delete ginuerep.dll, since the file continues to run in the GUI versions and cannot be deleted. ginuerep.dll cannot be unregistered because it is not registered.
0
0
Guest
I finally got rid of this nasty pest. Started up in safe mode and used "search" in the start menu to locate each program, file and folder and delete them one by one. You will not be able to remove the ginuerep.dll file. This little terd is in the Windows/system 32 folder. I renamed this to a new genirc name and re started the computer in normal road. It could not locate this dll file any longer since I renamed it and everything seems ok now. I then went to windows/system 32 and smoked the generic file and it deleted with no problem.
0
0
Guest
Thankyou so much. I love you. It has finally gone
0
0
Guest
Thank you very much for all this great removal information. I had SpyFalcon on my computer for four days and now I am finally rid of it! You all are great, including the guests that wrote in what they did! Thank you all so very much!
0
0
Guest
hi after reading all the posts i downloaded and paid for webroot spysweeper and i worked
i have just run thru the reg keys and they are not there..
thanks for all the help.........................giles mackay qld
0
0
Guest
thankyou so much, right now i'm trying ewido and i'll be trying this next!
0
0
Guest
Steps to clean your system (just like the others said actually):
1. go to safe mode (run>msconfig>boot.ini> check /safeboot) reboot.
2. read above SpyFalcon manual removal. take out all the files like they say.
you will not be able to remove ginuerep.dll just yet. if you can't find some of
the things they tell you to remove no big deal.
3. once you erased all the junk, reboot in safe mode again, now go to c:winntsystem32
and erase the evil file ginuerep.dll.
4. great, you're set. to boot in normal mode, go back to boot.ini and uncheck /safeboot. then
reboot.

hooray.
0
0
Guest
I have had this problem bofore with a program called "Spyaxe" as well, basicly it is just a reskinned copy of the exact same program. Last time it happened my dad ended up fixing it before I even tryed (It was late when I got the trojan, and I knew exactly what it was the second I got it so I just went to bed knowing that it would be too much of a hassle to figure out at the time.) I am assuming that its pretty much exactly the same and shoud work on any "version" of the program (ie. Spyfalcon, Spyaxe ect... I know there are more out there)
0
0
Guest
Thank you very much for this removeal instruction
0
0
Guest
thnx for the help of this website that parasite was becoming a pest making my computer slow down everything but its off now
0
0
Guest
Is there a way we can sue companies like this for all this pain? Thanks this really helped me remove these files.
0
0
Guest
I have XP and did a system restore to a day prior to spy falcon infecting the computer, and all was fixed within five minutes!
0
0
Guest
I folowed these steps but even after that was still infected. I used safe boots and clean boots, and even on a clean boot which should not start processes, spy falcon started runnung before I even had a chance to start Windows Exp;orer. A few componen were already in use and could not be deleted. They were not even flagged for deletion on the next startup.
0
0
Guest
Thanks for the info - managed to get rid of SpyFalcon in a few hours. The key was the suggestion to rename ginuerep.dll in safe mode, then delete the renamed file on next start up.
Also, when you run msconfig, go to the Startup tab and uncheck SpyFalcon. This reduces the number of files you have to delete.
0
0
Guest
Good site, however, I usd smitRem to remove this nasty little tosser from a Win2000 infected machine. The user of this machine (a friend of mine) had Norton installed. I would not recommend ANYONE using Norton. 1) its a systems hog and (2) it doesnt pick this little blighter up!

Also, Trojan Hunter V4.0 does not pick this up.

Wht the hell do we allow programs like this onto the market! These people who distribute malicious code should be locked up!
0
0
Guest
ok you have to pay for spydoctor? because its saying for me athat i have to and this is really bad.
0
0
Guest
Can anyone tell an average Joe how to remove this BS SpyFalcon program? All the posts sound very helpful below but I am worried about doing permanent damage. Can this be explained for dummies like me?

Already something I have done (I htink something I quarantined when I used spydoctor) has screwed up my computer when I turn it on. It says "C:/ not found". Not good.

Also, the address for Spy Falcon is listed above. Is that the real address? Can we go there in the Philippines and destroy this company and the guy listed above?

Cheers.
0
0
Guest
Can anyone help I have tried to download Spyfaalcon removal tool but I am getting an error message -Error while creating script: A script engine for the specified language can not be created

Any suggestions
0
0
Guest
spy falcon is a con which messes up your computer, saying it just deletes spyware traces on your computer, but all it does is open a backdoor to all other viruses and is a real horror to delete off your computer. i have deleted it at least 20 times but it just appears again on start up. help. what can i do
0
0
Guest
Had a right job trying to get rid of this and despite trying various anti-virus etc software it always came back. Drove me mad !! Followed the advice given below about finding and deleting all of the spy falcon files and then renaming the ginuerep.dll file and trashing it after re-start. It worked ! Had no problems since. Thanks for the help. Jez
0
0
Guest
It worked in the end- if you want to get rid of this thing without buying spyware doctor then follow these instructions:
1- download and install the free spyware doctor and run it.
2- when finished open the log of infected files and save it (I had 80 in total)
3- restart your computer in safe mode (which disables all the memory applications associated with spyfalcon)
4- manually remove registry entries, unregister .dll files associated with spyfalcon then delete the .ddl files and remove all traces of the program
5- run spyware doctor again and if there are some you missed (which not all can be picked up first time) remove them again and repeat as necessary.
It took me about an hour and 15 mins but there are no more traces of the bloody thing in my system AT ALL and all you have done is saved 30 bucks by doing the removal manually. If you dont know how to do any of this then this site has some instructions about unregistering .dlls and removing registry files.
0
0
Guest
I have tryed everything to get rid of this problem but all i have cum up with after running a full version and up to date version of spy docter and trend micro fully updated service pack 2 system restore turned off and of course searching registry and files listed in the forum in safe mode for manual deleation. if any one can help me PLEASE!! contact me on edward_power2003@yahoo.com.au ill be in debt to u if any 1 can help me. Thanks again eddie
0
0
Guest
I also had Spy Falcon on my PC, sorry that I did not know the site, it could have helped me.
My system are Windows XP 100% updated, and Norton Internet Security 2006 100% updated
The attack was only on Windows Internet Browser, but did not attack the Browser that I dayly
use Slimbrowser from Flashpeak.com
I tryed to get help from Norton, but they wanted money to help me, and still I have about
230 days left from my licence
Bent Pedersen Denmark
0
0
Guest
I also had that nasty virus.My Nortons didn't detect it either.But my wonderful sister showed me how to configure nortons to detect it, I ran a full scan, and it showed that I had 3 infected.I clicked on the "remove" and so long spyfalcon!
0
0
Guest
We are seeing more and more clients with this spyfalcon and spyaxe, we remove at least one a day, and use this site for the fix, I recommend that people follow the instructions to the letter on here and use the experience of this site for removal of unwanted programs/adware
Thankyou guys for all the information you supplied to our business.
And just a footnote, Norton doesn’t help in any way and we are finding it also a pain in the arse with being to big and using all resources of ones computer, it doesn’t do its job any way, where is it known that you have to find a program to uninstall a program, specially with the Norton security,
Regards to the techs on this site.
Clickatec.com.au
0
0
Guest
Ok I did all that and guess what? I still have that annoying little symbol beside the clock that pops up and tells me my computer is infected, and tries to take to the spyfalcon website. . . NOW WHAT???????

Please help, this is getting way too annoying.
0
0
Guest
System restore in safe mode only, worked.
0
0
Guest
I may have found another way to get rid of that stupid little blikcing icon in the task manager. I have windows XP running both an administrator and user (with admninistrator abilities) on my computer. I did not have any of the dlls or registry keys listed above but still had the stupid ICON blinking. I noticed that since I have two accounts on the computer, one was infected while the other was not. Downloaded the two files that EVERYONE tell me to download. (one was a register key and the other is a cleaning program. NOT the one listed above). Here are the steps i did. Shut off System Restore. Did (run>msconfig>boot.ini> check /safeboot) reboot. The machine rebooted and the icon appeared even in safe mode. I Double clicked to update the registry. then I chose Start, Logoff, switch user. I then logged in as Administrator. Disconnected the infected user. Then chose Start, Logoff, switch user. Then ran the program (remslit or some folder) before the icon could appear. After that was complete, I hit Alt + Ctrl + Delete and shut off explorer.exe for my infected user in the process tab. this shut down my start option for XP as well as my Desktop. I then moved over to the users tab and selected administrator and connected. Shut down the computer through the administrator option. restarted in selective startup mode. then saved my settings and restarted in Normal mode. I believe the trick is that you ahve to shut down Explorer.exe in order to run the regkey/.bat option.

i got the programs from http://www.schrockinnovations.com/removespyfalcon.php and followed the instructions but modified the user,
there is probabaly a shorter way to edit the explorer.exe file and just delete the icon from startup but I'm not that clever with computers. I stumbled onto this solution after a day and a half.
0
0
Guest
I set system restore to 1 day before the icon appeared, worked like a charm... no more spyfalcon!
0
0
Guest
but you have to pay for spyware doctor to be able to remove it-------- bollocks
0
0
Guest
My Nortons wouldn't detect this virus either.So I reconfigured nortons to find it. When I ran a scan, it detected 3 infections. hit REMOVE and spyfalcon was gone, That was a few weeks ago and I still haven't seen the darn thing around
0
0
Guest
I didn't have to run the spyware doctor. But after I got rid of spyfalcon,the doctor keeps me from entering sites that are infected with it.

I wrote next message too.
0
0
Guest
Hey attention everyone!!!!!! SYSTEM RESTORE WORKS AMAZINGLY!!!!!!!

I STRONGLY RECOMMEND THAT YOU TRY IT BEFORE ATTEMPTING ANYTHING ELSE. I had a system checkpoint last night, which worked totally fine and you won't lose any work after the checkpoint(documents, saved games, that type of things). I lost a few programs that I installed afterwards but it's even better because they were all for this darn Spyfalcon!!!

SO YEAH, IF YOU HAVEN'T TURNED OFF YOUR SYSTEM RESTORE IT WILL DEFINITELY WORK FOR YOU!
0
0
Guest
If these instrustions arent working because the little bugger wont end the process well try the above in safe mode!!!!!
0
0
Guest
Another file associated is: windows/system32/reglogs.dll
It took me three hours to fix and Spy Doctor could not find it.
0
0
Guest
WTF... MY COMPUTER HAS CANCER!
0
0
Guest
I removed all files but the icon still appears in the system tray! Can any kind soul teach me how to fix this annoying problem? Thanks in advance!
0
0
Guest
SAFE MODE
0
0
Guest
ya i have removed all items but the icon the green guy in the wheelchair, very frusterating if anyone knows a way to get rid of it please help asap
0
0
Guest
I work in a computer repair shop in Lincoln, Nebraska and we have seen a sudden up tick in the number of people infected with a new variant of the SpyFalcon spyware infection. While the basic infection is the same, there are a few new files to worry about.

We have a free removal tutorial posted at http://www.schrockinnovations.com/removespyfalcon.php, but suddenly people started reporting that upon restarting their computers they were becoming reinfected. We have since found that two additional files are being installed now that were not before. We updated the fixsf.zip removal tool in the tutorial to include these files.

Good luck and please post back here and let us know if you have any problems getting it removed.

http://www.schrockinnovations.com
http://www.thorschrock.com
0
0
Guest
I have found reglogs.dll and atmclk.exe but i am not having any lock unregestering the dll or deleting the exe. Do you have any addititional tips?

thanks

byron
0
0
Guest
I have tried the suggestion of using schrockinnovations,com posted as 15/05. I had previously used spyware doctor.
spyware doctor removed all the files but I am still
pestered by the icon in the task bar

anybody got ideas to remove

thanks
0
0
Guest
tried everything mentioned here and still no luck getting rid of it.:(
0
0
Guest
find the location of the .exe, (c:windowssystem32atmclk.exe) - reboot in safe mode with command prompt then delete the file itself. (cmd: del c:windowssystem32atmclk.exe)
0
0
Guest
Couldn't get rid of that little @#$% in his wheelchair either for about 12 hours trying. Finally I found the .dll who was supporting it -- APPMAGR,dll --
I only could delete it in safe mode under c: prompt and deleting it manually from C:windowssystem32.
0
0
Guest
What a nasty blatant attack this was. I am no pc whizzkid, but I realised that none of the generated warnings seemed to come from my Windows. I was careful therefore not to click on any of the suspicious links.
Norton did not find anything when I ran a scan. System Mechanic identified spyware but could not eliminate it.
I found this site in desperation. I tried the System Restre solution (which seems an obvious route to take) and it appears to have worked. My system is back to normal with no sign of any annoying pop-up warnings or flashing icons. The three short-cuts that appeared on my desktop have gone too.
Marvellous!
0
0
Guest
terrible, i removed spyfalcon with Ad-aware se but after 3 weeks its back!
0
0
Guest
One more thing about that bullet-proof tray icon. I had cleaned everything related to SpyFalcon using Spy Doctor (yes I paid the $29 just for the aggravation factor) and still had the wheelchair and the 'Your computer is infected' pop up.' Tracked it to appmagr.dll as the only thing left. Could not unregister, as prior cleanup had apparently modified 'entry point.' Tried to delete in safe mode, but the bugger loaded already and I got the 'cannot delete, the file is being used by Windows' message. Booted in safe mode to command prompt, changed to the WINNTSYSTEM32 directory and deleted appmagr.dll. Gone. All you need is love.
0
0
Guest
I was unable to remove appmagr.dll from c:windowssystem32, I tried deleting in manually in regular windows, in safemode, and in comand prompt. It wouldn't let me, it was obviously running, I couldn't get the virus alert out of my system tray.
Then out of curiousity I changed the name to appmagr_begone.dll, it let me! I then restarted windows and the alert is now gone! Then I deleted appmagr_begone.dll out of system32 and it let me!!
Hopefully this will work for others too!
0
0
Guest
i dunnoe why, but when i turn on auto-protect, (i have removed everything but still, the UL Window Seek stuff still comes out), after 3 sec it is automatically turned off again. Is there anythign wrong? I heard from an IT friend that the Trojan is shifting into different directories... :P
0
0
Guest
Did a Window System Restore for the day before. Afterwards went to System32 and deleted the files that weren't able to be deleted before. Poof! Its gone!!
0
0
Guest
I cant find any of the files listed anywhere on the net - everything has been removed from my machine... everything except that bloody icon of a wheelchair. Is it possible i have a newer version of this that has changed it's file name conventions?
0
0
Guest
Like most people here I removed all files mentioned, but still had a wheelchair, I even removed appmagr.dll but the wheelchair was still there. So I sorted the system32 directory by date modified, and found that the appmagr.dll had been renamed to sbnudh.dll.

SOLTUION: Rename sbnudh.dll, kill the explorer.exe process or restart the computer, then delete the renamed file.
0
0
Guest
ok like outhers i tried all kinds of way to get rid of SF it seems it changes the name of the .dll
so you can't find it I look for all the dll's that were listed and no luck I did find a new dll called
FYHHXW.DLL I reloged in safe mode as Administrator (I don't get the flashing green icon in admin mode) went to c:/windows/system32 and del the fyhhxw.dll and reloged that worked
for me. hope that helps
0
0
Guest
i was asked to reboot my computer into safe mode while removing another program and when i rebooted back to a time prior to spy falcon being on my computer after that, the spy falcon had disappeared.
0
0
Guest
Yes. after renaming "sbnudh,dll" , the SF icon never interferes with system tray.
But there's an question that I wanna know. That is I just found "appmgr.dll" in Windows XP
platform (in windowssystem32) instead of "appmagr.dll". Is it mis-typing ???
0
0
Guest
Update on SpyFalcon.com Registrant

Registration Service Provided By: ESTDOMAINS
Contact: +1.3027224217
Website: http://www.estdomains.com
Domain Name: SPYFALCON.COM
Registrant:
SpyFalcon ltd.
David Taylor (david.alant@gmail.com)
Unit 110 Alpha Bldg. Subic International Hotel Rizal cor.
Sta. Rita Road, Subic Bay Freeport
Olongapo City
null,2200
PH
Tel. +206.9543154
Creation Date: 16-Jan-2006
Expiration Date: 16-Jan-2007
Domain servers in listed order:
ns1.antispydns.biz
ns2.antispydns.biz
ns3.antispydns.biz
0
0
Guest
I have just recently battled Spyfalcon on a friend's computer and have gotten rid of the main virus itself. However, he is still getting the constant message bubble from the system tray, and the message that there is infected files on his computer whenever he opens up the internet. I have run a bunch of scans with many different anti-virus software programs, and they aren't catching anything anymore. I have no idea how to rid him of this. Any help anyone can give me is much appreciated. Thanks
0
0
Guest
This has been driving me nuts, especially since I'm working on this computer for someone else. I would never have figured it out if not for this site.

Anyway, this is what worked for me:

I used regedit to get rid of the registry entries, manually deleted the installation folder(c:program filesspyfalcon), then copied/pasted the list of files to delete from above into windows search and found only one: sbnudh.dll. Tried to unregister it, but couldn't--the message said that this dll couldn't be registered in the first place. Restarted in safe mode and deleted it, system tray icon gone!

Hope this helps SOMEONE. Man, what a pain...
0
0
Guest
This was driving me insane, all I could find was reglogs.dll

Couldn't delete it or anything so I restarted in safe mode, found the file and deleted it, now it's all gone.

Thanks a lot guys :D
0
0
Guest
I found this article by searching the atmclk.exe. I don't seem to actually have the spyfalcon program, but atmclk.exe and dcomcfg.exe kept showing up on the process list, and I can't open any folders or IE...

Post Comment:

Attention: Use this form only if you have additional information about SpyFalcon parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Related news:
Similar parasites:
Related discussions:
Compare spyware removers
Compare free products

HijackThis Log Analyzer Beta 2 HijackThis Log Analyzer Beta 2

I failed to remove SpyFalcon using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other