Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Spy falcon and other spyware probs(iworm_attck_v122.02a)
   
BullGuard Antivirus Forum > General Security > Spyware > Spy falcon and other spyware probs(iworm_attck_v122.02a)  
Forum Quick Jump
 
New Topic Post reply to : Spy falcon and other spyware probs(iworm_attck_v122.02a) Printable version of : Spy falcon and other spyware probs(iworm_attck_v122.02a)
[ << Previous Thread | Next Thread >> ]

smithy_23
New Member


Date Joined Feb 2006
Total Posts : 1
 
   Posted 2-19-2006 9:21 (GMT +1)    Quote: Spy falcon and other spyware probs(iworm_attck_v122.02a)Alert an admin about: Spy falcon and other spyware probs(iworm_attck_v122.02a)
i have spyware which downloads spy falcon without my consent and i have several 'urgent system messages' which look like genuine windows popups but are infact links to websites. here is my hijackthis log file and so can anyone help me please:
 
Logfile of HijackThis v1.99.1
Scan saved at 17:22:14, on 19/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\system32\nvctrl.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\1024\ld57CB.tmp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by ACT!
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpB761.tmp
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SpyFalcon] C:\Program Files\SpyFalcon\SpyFalcon.exe /h
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Acez.com - Download Free Screen Savers - {88E50F1D-4790-4C6B-BEE3-D54E46B6EEF6} - C:\WINDOWS\acezlink.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/...trolLite_EN.cab
O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000} - http://www.eingang69.de/EroticAccess/Cabs/1843068.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst_current.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by101fd.bay101.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/16bce870f42c3e...ip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1127057084278
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} (Eyeball Video Session Control) - http://imlive.com/ChatSource/gVideoContol.cab
O16 - DPF: {E154E3CC-0C3A-4101-91D8-6B4876F0FD64} (PrintScreen Class) - http://www.myemo.com/my_picture/Flash2Image.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Back to Top
 

antispy
Junior Member


Date Joined May 2005
Total Posts : 77
 
   Posted 2-19-2006 10:33 (GMT +1)    Quote: Spy falcon and other spyware probs(iworm_attck_v122.02a)Alert an admin about: Spy falcon and other spyware probs(iworm_attck_v122.02a)
spyfalcon infection comes in right-bottom corner balloon tip saying that "your somputer is infected". spyfalcon starts every time you boot your computer up. uninstalling, or Add/Remove Programs tool will not help. The tool that removes spyfalcon completely is here: remove spyfalcon


 

Back to Top
 

andy1
Junior Member


Date Joined Jun 2005
Total Posts : 61
 
   Posted 2-22-2006 10:27 (GMT +1)    Quote: Spy falcon and other spyware probs(iworm_attck_v122.02a)Alert an admin about: Spy falcon and other spyware probs(iworm_attck_v122.02a)
I heard good responses about a guide explaining how to remove spyfalcon on this site.
Back to Top
 

birdman
New Member


Date Joined Feb 2006
Total Posts : 1
 
   Posted 2-22-2006 10:42 (GMT +1)    Quote: Spy falcon and other spyware probs(iworm_attck_v122.02a)Alert an admin about: Spy falcon and other spyware probs(iworm_attck_v122.02a)
I had this problem occur yesterday ( xp sp2 ). I ran spybot ( 87 errors ) and spydoctor ( 151 errors ) and avg ( free version ) all in safe - mode and deleted all high risk problems which included SPYAXE. I am pleased to say that I have solved this annoying problem. I am certain that my machine was infected through an email attachment. Hope this helps.
Back to Top
 

scagrat2
New Member


Date Joined Feb 2006
Total Posts : 12
 
   Posted 2-23-2006 1:47 (GMT +1)    Quote: Spy falcon and other spyware probs(iworm_attck_v122.02a)Alert an admin about: Spy falcon and other spyware probs(iworm_attck_v122.02a)
download and run microsoft anti-spyware from www.microsoft.com u will need to validate ur pc first but as long as ur legal ul b fine, also if you havnt got an anti-virus i recomend highly that you download avast anti-virus from www.avast.com which will remove all viruses/trojan and spyware (it works along it
Back to Top
 

tschrock
New Member


Date Joined Mar 2006
Total Posts : 3
 
   Posted 3-23-2006 9:38 (GMT +1)    Quote: Spy falcon and other spyware probs(iworm_attck_v122.02a)Alert an admin about: Spy falcon and other spyware probs(iworm_attck_v122.02a)
A lot of companies will ask you to download free trial versions (or pay versions) of their software to get rid of Spy Falcon.  If you are handy with a computer, try the tutorial at http://www.schrockinnovations.com/removespyfalcon.php.  It is 100% free and they won't ask you to buy a product to fix your computer.  Its pretty detailed, and might even work for other variants like Spy Sherrif, etc..
Back to Top
 

dubosea
New Member


Date Joined Apr 2006
Total Posts : 1
 
   Posted 4-6-2006 12:19 (GMT +1)    Quote: Spy falcon and other spyware probs(iworm_attck_v122.02a)Alert an admin about: Spy falcon and other spyware probs(iworm_attck_v122.02a)
I tried the "tschrock" post and highly recommend it. I got this virus about a month ago and spent 1.5 hrs on hold with Norton, then another 1.5 hrs with their tech support and it cost me $70. None of the other free software did anything. Norton (cost me $40 aside from tech support), AVG, MicroTrends (Company av software), and windows defender all did nothing to remove. AVG was the only one that detected it, but still couldn't remove it.

THANKS!
Back to Top
 

FordJenn
New Member


Date Joined May 2006
Total Posts : 3
 
   Posted 5-8-2006 9:32 (GMT +1)    Quote: Spy falcon and other spyware probs(iworm_attck_v122.02a)Alert an admin about: Spy falcon and other spyware probs(iworm_attck_v122.02a)
I work in a computer repair shop in Lincoln, Nebraska and we have seen a sudden up tick in the number of people infected with a new variant of the SpyFalcon spyware infection.  While the basic infection is the same, there are a few new files to worry about. 
 
We have a free removal tutorial posted at http://www.schrockinnovations.com/removespyfalcon.php, but suddenly people started reporting that upon restarting their computers they were becoming reinfected.  We have since found that two additional files are being installed now that were not before.  We updated the fixsf.zip removal tool in the tutorial to include these files.
 
Good luck and please post back here and let us know if you have any problems getting it removed.
 
Back to Top
 

Wilson
New Member




Date Joined Feb 2006
Total Posts : 5
 
   Posted 5-13-2006 12:18 (GMT +1)    Quote: Spy falcon and other spyware probs(iworm_attck_v122.02a)Alert an admin about: Spy falcon and other spyware probs(iworm_attck_v122.02a)
antispy said...
spyfalcon infection comes in right-bottom corner balloon tip saying that "your somputer is infected". spyfalcon starts every time you boot your computer up. uninstalling, or Add/Remove Programs tool will not help. The tool that removes spyfalcon completely is here: remove spyfalcon


This one worked really well. yeah I had 'uninstalled' SpyFalcon, but was still getting the annoying pop-up in the bottom corner.
When I followed the instructions on this site, I found that of all the files listed for deletion from System32, only appmagr.dll was present. Got rid of it.....and got rid of the pop-up hop

Great stuff

PS Why do so many people on this forum refer to using Norton? I thought everybody knew that Norton was not in the same league as Bullguard!
Back to Top
 
New Topic Post reply to : Spy falcon and other spyware probs(iworm_attck_v122.02a) Printable version of : Spy falcon and other spyware probs(iworm_attck_v122.02a)
 
Forum Information
Currently it is Saturday, November 21, 2009 12:31 PM (GMT +1)
There are a total of 73.031 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 70 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
37 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Constant scanning andskipped files? (1)21-11-2009 10:08:33 (Dickens)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)
Atlanta Falcons Jerseys (0)21-11-2009 06:15:26 (donejerseys)