• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

My Gawd!...SpyFalcon's an ornary bugger!

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

ƒÓÒl

Member
Joined
Aug 27, 2005
I just finished up fixing a system for my neighbor's sister-in-law, spending all night (after a 13 hour shift at work) repairing what was done to her poor poor Dell.

She claims her oldest child was downloading a game cheat and he clicked on a baloon pop-up that looks exactly like a windoze update tray icon/balloon...it gave them a hosing of a lifetime.
First the pop-up says "Your computer is infected" and "click this balloon", and then it proceeds to open a rather convincing looking anti-spyware program that's actually a trojan downloader that put 128 pieces of spyware, 55 trojan horses (many duplicates of ~12 different ones), and 77 virus'.
That computer was so hashed by the time I got it, I couldn't install anything (it changed privledges) and it locked out the administrator, and it replaced IE with it's own skin that included a "spy-ware" tool bar that just refired it's download spree.

I finally got into it using the freestanding utilities from AVG's dload page (burned to CD), in combination with an old trusty win98 boot floppy that has CD drivers.
As soon as I got on the net to look for help though, it would just reload all the stuff that AVG took out because the control center wouldn't stay running.
I had to uninstall IE and reinstall it from my own disk to get that back to normal.
Even without the net connected, it would all reinstall on the next boot despite a thorough registry cleaning and restore turned off!

Anyway, I found my way to Kaspersky's free trial and finally got it (dial-up with a dloader hogging it took 3 hours!). That would stay running once I cleaned it in safe-mode.

Then on the wife's lappy (my monitor was on the sick system), I found this wonderfull gent and company... http://malwareremoval.com/plog/index.php?op=ViewArticle&articleId=85&blogId=3
Bless Nick and Noahdfear!!!!

Followed the instructions to the letter, and violla! one computer back from the brink of reformat hell.
And that Ewido did an awesome job too, far better than AdAware did, though the scan was long.
It seams I'll be buying some new software, and so will my customer.

By the way, I uninstalled Kaspersky's and Ewido from her machine...don't wanna sell someone else's handiwork. I just left her with links to their pages on the desktop.
Her machine turned out to be totally unprotected. The only thing I could find on her machine was a version of MacAfee's Security that only had a stoopid link to an INTERNET SCANNER!...one lamer award to Dell.

Now for some sleep...30 hours awake makes us old farts cranky ;)
 
Last edited:
You tried downloading the FixSF.reg and it didn't work? or you can't install any programs as was my pain?

Downloading the standalone removers on AVG's site and writing them to cd on another computer killed enough of the junk in safemode to let me follow the rest of the instructions, because the junk changed permissions and hid the administrator login in windoze, and then wouldn't allow anyone else install software in windoze.

I followed the link in your post, and they point to spyfalcon too, so I'd bet it should work as long as you can weedwhack enough of the stuff to get a good install of the two programs (fixsf and ewido).

HERE'S the link to AVG's standalone killers.
The ones that run in DOS, I changed their name to add "dos" on the front of their filename so I could tell which one had to be run from a bootfloppy and which to run in safemode...which I did in that order.
Then I went to windoze and installed fixsf and ewido without a hitch. (kaspersky's too)
Then I went to safemode and ran them both as the instructions show, followed by kaspersky's.
Reboot to windoze and run ewido again just to be sure, and it came up clean.

I've been wanting the time to build a BartPE disk with those three programs on it, so there's no harddrive software even running, then it would be cake to fix a system.

Luck to ya
 
Last edited:
Back