Nov 21, 2009

Spysheriff - The Spyware Causing Anti-Spyware...

free web hosting
Open Discussion & Free Web Hosting > Computers & Tech > Software > Anti-Virus & Anti-Spyware

Spysheriff - The Spyware Causing Anti-Spyware...

Shrike
Many of you probably already know of SpySheriff and its corrupt nature, and maybe there was already a post of it here, but either way if I can let a few people know I'll have helped them avoid some troubles that I went through. First of all under no circumstances should you install SpySheriff.

QUOTE

SpySheriff is a corrupt illegally distributed anti-spyware program. It is secretly installed to victim computers by various trojans and through certain web browser exploits. Once executed, SpySheriff registers itself in the system and runs a payload. It changes the desktop background to a fake warning message, forbids access to some web sites and may even block any attempts to connect to the Internet. The parasite can also disable some Windows essential components and tools such as the System Restore and the Date and Time application. In some cases SpySheriff may attempt to delete certain installed anti-spyware programs, crash the system and display bogus system error reports. This malware is able to prevent the user from uninstalling. It can also restore its removed components. SpySheriff automatically runs on every Windows startup.

Article from www.2-spyware.com - click here for the original article!

Several installations ago I made the mistake of Downloading and Installing SpySheriff, it's website (www.spysheriff.com) does a convincing job of portraying it as a legitimate SpyWare Removal Program. However once I installed it my computer quickly became infected with all sorts of Adware and Spyware and through my best efforts I couldn't get rid of them. SpySheriff would go through its process and pretend to remove them while changing OS settings and locking up the internet. I eventually had to reformat my hard drive and re-install WindowsXP...I found out later that it was in fact SpySheriff that had caused the problem in the first place. dry.gif

 

 

 


Comment/Reply (w/o sign-up)

WeaponX
This infection has been spreading around for some time now and it's ever changing. It's really a part of the Smitfraud infection and came come in various flavors if you can call it that. Removing it used to be a huge pain, until some authors came up with a tool to help remove most of the infection and render it useless (except for a few things to clean up maybe...at most).

For the instructions on how to fix this, read up on Grinler's article at BleepingComputer.

Comment/Reply (w/o sign-up)

Shrike
Yeah, it woulda been nice if I had known what the problem was while I was infected. Thanks for the link to the fix, I'll keep that in case I get infected again from some obscure .exe I download! biggrin.gif I'm using Zone Alarm Internet Security Suite which includes an Anti-Virus/Anti-Spyware but it still misses ALOT. dry.gif

Comment/Reply (w/o sign-up)

Cruzo
Spy Sheriff is a system hijacker that causes popups to appear on your computer telling you that you have spyware installed (which you do!). Clicking on the alert brings you to a website which attempts to sell you a bogus spyware program called "Spy Sheriff".

QUOTE
In order to remove this infection we will need to use HijackThis to manually remove the infection:

1. Print out these instructions as we will need to shutdown every window that is open later in the fix.
2.Download and install CleanUp! but do not run it yet.
*NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.
3. Download, install, and update Ewido Security Suite
1. Install Ewido security suite
2. Launch Ewido, there should be a big E icon on your desktop, double-click it.
3. The program will prompt you to update click the OK button
4. The program will now go to the main screen
5. On the left hand side of the main screen click on Update
6. Click on Start. The update will start and a progress bar will show the updates being installed.
4. After the updates are installed, exit Ewido
5. Reboot into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.
6. Once in Safe Mode, Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
1. Click Options...
2. Move the arrow down to Custom CleanUp!
3. Put a check next to the following:
Empty Recycle Bins
Delete Cookies
Delete Prefetch files
Scan local drives for temporary files
Cleanup! All Users
4. Click the OK button
5. Press the CleanUp! button to start the program.
7. After Cleanup! is finished start Ewido Security Suite
1. Click on scanner
2. Make sure the following boxes are checked before scanning:
Binder
Crypter
Archives
3. Click on Start Scan
4. Let the program scan the machine
5. While the scan is in progress you will be prompted to clean the first infected file it finds. Choose clean, then put a check next to Perform action on all infections in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK.
8. When the scan is complete, exit the program and reboot back to normal mode.
9. Click on Start, then Control Panel, and double-click on the Add/Remove Programs icon.
10. Uninstall the SpySheriff program and then exit Add/Remove Programs.
11. Delete the following, in bold, if found:

C:\Documents and Settings\user account\Start Menu\Programs\SpySheriff <-whole folder
C:\Documents and Settings\user account\Application Data\Install.dat
C:\Program Files\SpySheriff <-whole folder
C:\Windows\Desktop.html
C:\winstall.exe
C:\Program Files\Daily Weather Forecast\

*NOTE* user account is not the actual name of that folder. The name of that folder will be the name of your computer profile.
12. Download HijackThis and save it to your C:\ folder. Extract the hijackthis.zip file to c:\hijackthis. We will use this program later.
13. Make sure you are disconnected from the Internet and that all programs and windows are closed. Run HijackThis and press the Scan button. Place a check next to the following items, if found, and click FIX CHECKED:
O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
14. Close HiJackThis.
15. RIGHT-CLICK HERE and go to Save As (in IE it's Save Target As) in order to download the smitfraud reg to your desktop.
16. Double-click smitfraud.reg on your desktop. When asked if you want to merge with the registry click YES.
17. After the merged successfully prompt, using Windows Explorer, navigate to the following folder:
C:\Windows\Prefetch
18. If there are any files inside the Prefetch folder, delete ALL of them. (Do NOT delete the folder. Just delete the files inside.)
19. Reboot your computer.
20. You should be able to change your desktop back to normal now.

Your computer should now be free of the SpySheriff infection.

 

 

 


Comment/Reply (w/o sign-up)

ProtoMan.EXE
Whoa , I didn't know about SpySheriff could infect my computer before . Thank you . But be careful , I know some products named " Pest trap " and " Spy Trooper " , they are the same as SpySheriff , I visited thheir hamepage and I was surprised that there is no change from SpySheriff 's page except the name of the products .

Comment/Reply (w/o sign-up)

FeedBacker
Replying to ShrikeDo not click on the spysheriff.Com link it's dangerous avg search-shield blocked site!

Comment/Reply (w/o sign-up)


Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

This textarea will convert to Rich-Text automatically (IE, Firefox, Chrome)

Similar Topics

Keywords : spysheriff, spyware, causing, anti, spyware

  1. Hard To Work With Spyware
    (5)
  2. Annoying Spyware
    (8)
    Every 1 or 2 page views i do with IE all IE pages are directed to another page saying: QUOTE
    Warning - you are infected by this site! Please, read our suggestions! You can learn more about
    harmful web content and protect your computer at Total Secure 2009. Just download Total Secure 2009
    Now and Protect your Business forever! Suggestions: Make backup of important files and documents!
    Read more about Total Secure 2009 Return to the previous page and pick another result. Try another
    search to find what you're looking for. If nothing will help you - reinstall ....
  3. Excellent Anti-spyware/adware Free
    (2)
    If you follow the magazine reviews, PC Tools Spyware Doctor is one of the best detection and removal
    programs available, however most users do not know that the very capable Lite version is available
    FREE from Google. Didn't see it mentioned any where and thought I'd post and let others
    know. If you go to Google's 'Pack' section, which offers loads of free software, one of
    the programs available is Spyware Doctor. This is the same program sold retail with just a few of
    the live scanning options missing from the configuration menu, so it detects and....
  4. Best Free Anti-virus Program
    NID UR ADVISE! PLS. HELP (32)
    NID UR ADVISE! PLS. HELP....
  5. A Screenshot Of The Most Spyware Infected Pc In The World
    (28)
    The title says it all. http://img211.imageshack.us/img211/8523/sp...estationgv6.png I don't
    think this is some person's actual PC. I think it's just a test PC used by an anti-spyware
    software company to test how toxic this spyware soup would be. Like to test whether various types of
    spyware would "jump at each other's throats" so to speak. Although to be fair I did spot the
    VMWare systray icon right next to the clock, so that says something.....
  6. Spyware Terminator
    Interesting... (6)
    I recently installed Spyware Terminator after reading a review on this board about it being really
    good! And so far I'm impressed, it works well, it's fast and caught the spyware on my
    computer! I only have one problem... When I had a look at my Installed Programs list, I found that
    Spyware Terminator was taking up a grand total of 18.4GB, yes thats Gigabytes!! of space.
    /tongue.gif" style="vertical-align:middle" emoid=":P" border="0" alt="tongue.gif" /> I couldn't
    believe it! what is it doing with that much space! I had a look at my hard drive space - an....
  7. In My Opinion , There Is No Best Anti-virus.
    (9)
    I think the best way to defend the virus is finely backup your important files and system. I don`t
    install any virus scaner in my computer, a ghost(software) instead. I backup my system the time
    when the system is quite good .All the processes only took 10 minites.Some important files uploaded
    to an online disk and my moving disk. When there is something wrong. It take just 10 minites to
    restore the system and less time to download my files. In my opinion , there is no best
    Anti-Virus. When you use it, it take lots of resources of your computer,and must be updated ne....
  8. Free Anti-virus/anti-spyware Programs
    A list of free anti-virus & anti-spyware programs (3)
    All programs listed here are either free or trails! If you found one that is not in this list you
    can post it and i'll edit the post. Hope anyone can use this /wink.gif"
    style="vertical-align:middle" emoid=";)" border="0" alt="wink.gif" /> Anti-virus programs
    Active Virus Shield ( Site ) AntiVir Personal Edition ( Site ) avast! Home Edition ( Site ) AVG
    Free ( Site ) BitDefender Free Edition 8 ( Site ) ClamWin (ClamAV) ( Site (Windows version) |
    Site (UNIX version) ) McAfee Stinger ( Site ) NOD32 ( Site ) Anti-spyware programs Ad-Aware (
    Site ) AV....
  9. Norton Anti Virus Uninstall
    How to do this??? (2)
    I now own a new laptop and the Retail 60 or 90 day trial of Norton anti-virus came per-installed.
    Piece of carp. And I want to install a different Software, probably the One M^E suggested in
    another topic, but anyway... Is the removal of Norton's Antivirus and Norton's Internet
    Security as simple as it sounds? Simply use the uninstallers and delete the folders from the system
    to free up space? Or are there other things which should be done? I'm thinking registry cleaning
    and all that. Are these extra steps required? or reccomended?....
  10. What Is The Best Anti-virus
    (65)
    Just wondering, what is the best anti-virus software that is out there? Also, is there a place that
    has it for free or a free trial. The only anti-virus software I know are Norton and Macfee (unless
    you count trend, but that waas mandatory for school).....
  11. Microsoft Vista Needs No Anti-virus?
    Stupid Microsoft employee... (25)
    Here's the article I'm talking about- link This guy is saying that he lets his kid run
    Windows Vista without an anti-virus because of the parental controls. He thinks that since the new
    Windows has made such great improvements in security that he no longer needs an anti-virus. I think
    Microsoft has gone waaaaay too far in their PR, now they are flat out lying. They are getting to be
    like Apple (sorry Apple fans, but most of their ads are totally untrue). Vista will be a huge
    target for hackers because it is one of the most anticipated releases of an OS ins....
  12. Avast
    Anti-virus Avast (5)
    I am using avast. Avast is best anti-virus software for me. Avast is free and you can download it on
    this link . Try it! Its Super.....
  13. Besides AVG, What's The Best Free Anti-Virus?
    (19)
    I hate AVG personally, but i havent yet figured out what I want to use for an Anti-virus program. I
    have Anti-vir right now, but I really love to the many different opinions that are given here on
    these forums. I just don't know what would be good. I had Avast for a little bit, it seemed
    pretty good, and I'm not quite sure why I didnt use it again. So what do people think is the
    best free anti-virus (please don't mention AVG)?....
  14. Antivirus, Anti-spywares And Firewalls.
    My Full Review About Security Programs LOok! (2)
    Hi to all members, im going to make my full review about all security programas that i have used in
    my life. I hope you enjoy my review, and please comment about what you think about those security
    programs. /biggrin.gif" style="vertical-align:middle" emoid=":D" border="0" alt="biggrin.gif" />
    All the programas below i have tested for at least a week. Antivirus:
    Kaspersky Antivirus Personal is the best antivirus i ever used, thats why he is in firts
    place here. He is fast, Simple, Updated all the time and trustfull. The best pa....
  15. Looking For Good Free Anti Virus Program
    (14)
    hi i was wondering were i can find some anti virus software which is free and hasnt got spyware
    wiv it every single one i have tried looking for one it has always installed loads of junk onto my
    pc is well so can someone help me out plz would be much appriesated....
  16. Is Norton The Best Anti-virus?
    (34)
    Hi, I have had Norton for 5 years now and I like it but I wanted to know if it was the best or not.
    I think it's the best but that's just my opinion. What's you opinion? Yacoob....
  17. Spyware Doctor!
    (3)
    Best Anti-spyware..! Try it.. you'll never regret......
  18. Annihilate Adware With The Bazooka!
    A very effective anti-adware tool (6)
    I've been using this tool, called " Bazooka Adware and Spyware Scanner ," for a year or so now,
    and I firmly believe it's the ultimate anti-adware and anti-spyware tool there currently is.
    Bazooka is really small (under 1MB), and it's totally free; its database is very comprehensive;
    it's very light on your system; it scan your system for malware in merely a couple of seconds,
    but don't let this fool you, it does the job perfectly. You can also update the database from
    within the program. Now, I think the reason only few people know about this t....
  19. Firewalls
    Anti-virus, Anti-Spyvware and firewalls (20)
    Hi, I don't know if there might allready be some subtopic regarding firewalls, but in these
    anoying computer unhumanity terror days, would I like to discus with others their expirence
    regarding diffrent security systems. I've been using several of these systems, and the most of
    them without any bigger surpriseing results. As many might allready had mentioned is Norton Internet
    Security an very heavy solutions, that too often alow virus and other unwanted stuff access your
    system, and the same problem had I expired with both Panda and McAfee Internet security. ....
  20. Good Spyware Combo
    It's a 1-2 punch! (19)
    I actually used to use this spyware combo in my old computer, and it happens to be a really good
    one. The main spyware program that you need to first get is called Spybot S & D, which is a free
    spyware blocker and deleter program. It's a very handy program, and it can be found at this
    address: security.kolla.de . You can download it for free, and it has some credentials, which is a
    plus. Then, the next bit to get to finish it off is the Spyware Blaster. Spyware Blaster is a free
    spyware install preventer, if you will. With the both of them, you get a pretty mu....
  21. Anti Virus Software
    (15)
    I want people to name some of the Anti Virus software they are currently using on their pc.....
  22. Anti - Virus For Windows 2000 Server
    Which is best??? (2)
    Hi friends, Recently I have changed my PC form Windows XP to Windows 2000 Server because I have to
    run many server side applications. But the antivirus for Server computers are different from the
    client computers. Currently I am having Symantec Corporate Edition 10 antivirus. But I want to know
    the any other good and free anti-virus for Windos 2000 server computer???? Thanks in advance.....
  23. Ms Antispyware Detects Messenger Plus As Spyware
    (9)
    Microsoft AntiSpyware detects the Messenger Plus exe as Spyware. I think the reason is Messenger
    Plus! may install some sponsor software to your system. Microsoft is doing the right thing. If
    they want people to use Microsoft Messenger Plus, simple, just remove the spyware. althogh I have
    never missed the "sponsor program" installation screen when I've run the installer, most people
    just keep clicking next buttom when they are installing software. Anyway, Messenger Plus! is
    asking Microsoft to stop detecting and collecting users signature. To show your suppo....

    1. Looking for spysheriff, spyware, causing, anti, spyware

See Also,

*SIMILAR VIDEOS*
Searching Video's for spysheriff, spyware, causing, anti, spyware
advertisement



Spysheriff - The Spyware Causing Anti-Spyware...

Affordable Web Hosting, Low cost Web Hosting - ComputingHost.com