• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove SpyFalcon

Myantispyware team February 10, 2006    

SpyFalcon is a rogue anti spyware program that is known to issue fake warnings on your computer in order to manipulate you into buying its full commercial version. If you are infected with this program you may receive warnings in your task bar that appear to be from Microsoft Security Center stating that you are infected with spyware and to run its special anti-spyware tool.
This tool turns out to be the commercial version of SpyFalcon. These warnings are fake and are a goad to have you buy the commercial version of this software.

You may want to print out or make a copy of these instructions before starting, because you will not be able to connect to the internet during most of this fix.

Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found: SpyFalcon
Then using Windows Explorer, delete the following folder: C:\Program Files\SpyFalcon

Download smitRem and save the file to your desktop.
Double click on the file to extract it to it’s own folder on the desktop.

Download HijackThis and save the file to your desktop.
Double click on the file to extract it to it’s own folder on the desktop.

Next, Download, install, and update the free version of Ewido trojan scanner:

1. When installing, under “Additional Options” uncheck “Install background guard” and “Install scan via context menu”.
2. Run Ewido.
3. From the main ewido screen, click on update in the left menu, then click the Start update button.
4. After the update finishes (the status bar at the bottom will display “Update successful”)
5. Exit Ewido. DO NOT scan yet.

If you do not already have Ad-Aware SE installed, follow these download and setup instructions. Also check for updates.

Again, do NOT run a scan yet.

Next, please reboot your computer in Safe Mode by doing the following:

1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.

Now you need to run HijackThis and click “Do a system scan only.” Place a check next to the following entries (if they are still there):


O2 – BHO … C:\Windows\SYSTEM32\hp*.tmp (the name changes)
O4 – HKLM\..\Run: [SpyFalcon] C:\Program Files\SpyFalcon\SpyFalcon.exe /h

Now close all browser and other windows except for HijackThis, and click “Fix Checked” to have HijackThis fix the entries you checked.

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Your desktop and icons will disappear and then reappear again — this is normal.
Wait for the tool to complete and Disk Cleanup to finish — this may take a while; please be patient.

Next, run Ad-aware and perform a full scan. Remove everything found.

Run Ewido

1. Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
2. If Ewido finds anything, it will pop up a notification. Please select “clean” and check the boxes “Perform action with all infections” and “Create encrypted backup” before clicking on OK.
3. When the scan finishes, click on “Save Report”. This will create a text file. Make sure you know where to find this file again.

Next go to Start -> Control Panel, click Display -> Desktop -> Customize Desktop -> Web -> Uncheck “Security Info” if present.

Using Windows Explorer, locate and delete the following file:
C:\WINDOWS\system32\dxmpp.dll.
C:\Program Files\SpyFalcon\

Perform an online scan with Panda Active Scan.

Where “C:\Windows\SYSTEM32 ” – patch to your Windows\System32 directory.

if you can`t remove these files, use KillBox, download here.

Your computer should now be free of the SpyFalcon infection.

If you are still having problems with spyware after completing these instructions, then please follow the steps outlined in the topic linked below

Spyware removal – Read Before Posting

Tutorials - HowTo

 Previous Post

Adware SE 08.02.2006 update now available

Next Post 

New Bagle – W32/Bagle.FM@mm, Email-Worm.Win32.Bagle.fm mass-mailer found

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

4 Comments

  1. Arlen
    ― February 13, 2006 - 7:29 pm  Reply

    Thanks. I was going pretty crazy with that damned thing on my computer, prompting me to pay for it each time I rebooted.

  2. mark rice
    ― April 12, 2006 - 2:27 am  Reply

    Followed your instructions to remove spyfalcon.If I could do it they must be fantastic instructions.
    Only thing though,how do I remove the balloon which says my antivirus is turned off,and which presumably puts the problem on my computer in the first place.Hope you can help.
    Regards Mark

  3. Lavoyd
    ― April 24, 2006 - 8:37 am  Reply

    I’m going through a horrible diemma with my computer. Everytime I reboot my system after dumping viruses off from AVG, I get this Spyware Soft Stop program in which I thought not long ago I removed it from the Add/Remove Programs. I instantly suspected that this such device is spyware and I have tried to find that hidden bug that was causing me headaches. I need help as to how can I get rid of this suspicious program and to rid it off for good? HELP!!!!

  4. Patrik
    ― April 24, 2006 - 8:55 am  Reply

    To Lavoyd, if you have problems with get rid of this rogue antispyware, please make new topic in the Spyware Removal forum. I`ll help you 🙂

Leave a Reply to Lavoyd Cancel reply

New Guides

scam alert
Remove Searchernow.com Redirect: Chrome, Edge, Firefox
Avoid the ExLig.com Bitcoin Scam: Insights on Promo Code Frauds
scam alert
Denwex.com Review: Bitcoin Promo Codes as a Scam
scam alert
CEFOLEX.com Review: A Closer Look at the Bitcoin Promo Code Scam
The Bigexcoin.com Bitcoin Promo Code Scam: How to Stay Safe

Follow Us

Search

Useful Guides

How to reset Internet Explorer settings to default
Iphone Calendar virus spam
Iphone Calendar Virus/Spam 2022 (Removal guide)
How to reset Mozilla Firefox (Updated Apr. 2018)
How to remove browser hijacker virus (Chrome, Firefox, IE, Edge)
Best free malware removal tools
Best Free Malware Removal Tools 2025

Recent Guides

Adware SE 08.02.2006 update now available
Sun Java JRE sandbox bypass vulnerability
SpyFalcon – new rogue anti-spyware
Vulnerability in Internet Explorer Could Allow Remote Code Execution
File permissions vulnerability in Adobe Creative Suite 2

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.