Help with SpySheriff removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by lilhaydo, Dec 6, 2006.

  1. lilhaydo

    lilhaydo Private E-2

    Hey there...

    I followed all of the instructions for the removal of SpySheriff in the stickied thread. However, my antivirus is still going off. It is saying that C:\WINDOWS\system32\xxfgmy.dll is infected with adware.spysheriff. The antivirus will not delete it. It will only skip over the file and do nothing.


    Any help would be greatly appreciated.
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Please run through the steps outlighted in our first steps guide to removing malware as many of the Activescan items would have been removed if you had done the preliminary cleaning steps, READ & RUN ME FIRST Before Asking for Support ?

    and follow up with attaching all the logs requested as these were missing, if you had issues in running any of them please tell us what they were,


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    • CounterSpy
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
    • Bitdefender - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
     
  3. lilhaydo

    lilhaydo Private E-2

    Sorry...I had read through that thread and it said...

    "Before you start the below procedure, you may want to first check to see if your problem is covered in the Special Removal Procedures sticky thread."

    So I did...but I missed the part that says...

    "If it is, try that procedure first and come back here to the READ & RUN ME if necessary afterwards."

    Again I apologize.
     

    Attached Files:

  4. lilhaydo

    lilhaydo Private E-2

    One more
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    After you complete this post, I need you to run another CounterSpy scan and this time remove the found infections do not ignore them.

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    • ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!!
    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  6. lilhaydo

    lilhaydo Private E-2

    Sorry I was away for a few days. I thought things were working pretty well but apparently they are now.
     

    Attached Files:

  7. lilhaydo

    lilhaydo Private E-2

    Opps I mean not working!! :mad:
     

    Attached Files:

  8. lilhaydo

    lilhaydo Private E-2

    Here is the HJT log!
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  10. lilhaydo

    lilhaydo Private E-2

    I don't understand why Active Scan is still picking up cookies...I ran CCleaner.
    Let me know if I should post a HJT log. Thanks
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I need a fresh HJT log, also if you have multiple user accounts you will need to run CCleaner on each account.
     
  12. lilhaydo

    lilhaydo Private E-2

    I keep getting this when scanning with CounterSpy even after quarantining and removing:

    Trojan-Downloader.Zlob.Media-Codec

    If I am not mistaken does that imply SpywareQuake or SpyFalcon?
    I did those removal procedures also.
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log looks good, reboot into Safe Mode and delete the following two files...

    C:\WINDOWS\ss3unstl.exe

    C:\Documents and Settings\kmitchell\My Documents\My Pictures\sinstaller.exe

    Once you remove these two files, run CCleaner and then reboot back to normal mode. Let me know how things are running and if any problems remain.
     
  14. lilhaydo

    lilhaydo Private E-2

    Thanks bjgarrick for all your help. I am just curious...what are the two files that you said to delete?
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    From your Panda scan, typical adware per the log.
     
  16. lilhaydo

    lilhaydo Private E-2

    Well I deleted the two files you said to and everything seems to be running fine. I ran Counterspy again and "Trojan-Downloader.Zlob.Media-Codec" was not recognized.

    Once again bjgarrick, thank you so much for your help!!
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds