Regarding all Spy Sheriff input?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fisherking, Jun 19, 2005.

  1. Fisherking

    Fisherking Private E-2

    Regarding the issue Spy Sheriff hi-jacking the desktop of a computer. I have tried to remove this spyware/malware application using almost every recommended spyware detection software and it still will not release the desktop image. I believe that the application itself is finally gone but cannot regain control of the desktop. Short of restoring the entire system, does anyone have any suggestions as to how to regain control of the desktop or just re-install that part of the operating system?

    While testing processes in task manager - I began to stop processes one by one as they relate to the operating system and the "spy sheriff" blue and black screen finally disappeared when I stopped running explore.exe but then again the entire desktop disappeared. However, that seems to tell me that Spy Sheriff changed the explore settings or .exe somehow. Does that seem logical and if so, is there a way to just restore that part of windows without the whole operating system?
     
  2. Fisherking

    Fisherking Private E-2

    I am new to forums so please forgive any mis-step in protocol. Although I had already completed the steps in READ ME FIRST BEFORE ASKING FOR SUPPORT, I realized after posting that I didnt' state that. I have performed all functions and scans as detailed to the point of posting a Hijack this log file. I am at my wits end with this problem and am considering a complete system restore. Please help.
     

    Attached Files:

  3. Fisherking

    Fisherking Private E-2

    Dear Major Geeks Forum...sorry to have posted a hijack this log file without being asked...again I am new to the forum environment. Also, am very frustrated with this Spy Sheriff desktop hijacking. I consider myself a fairly savvy computer user but this is a real pain-in-the-butt. Needless to say my frustration level is maxed and I missed the comment about not posting until asked. I have also posted my hijack this log file for analysis on the hijack This website and followed the recommendations for repairing nasty and unknown items. Still my desktop is held captive. However, Spy Sheriff the application hasn't returned. I simply need help getting control of me desktop.
    Thanks...and awaiting any replies or assistance.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to the PM you sent me, it would seem one of my other posts helped you out. Please give the thread ID that helped you.

    Are you still having any problems? I did notice other issues in your HJT log.

    Is the below Start Page valid:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cyberism.com/

    Here are the other problems is see in you previous log that needed fixing.
    R3 - URLSearchHook: (no name) - 3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
    O4 - HKLM\..\Run: [Archive] C:\Program Files\Archive\archive.exe
    O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present <-- not a problem but can get in the way of fixing problems
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
     
    Last edited: Jun 19, 2005
  5. Fisherking

    Fisherking Private E-2

    yes, it was another post - i can't seem to find that - it had a registry edit that worked - the HTJ attached was old - we had sbmitted that one to the "analyze" portion and 'fixed" anything that looked or was indicated suspicious - the link to "cyberism" is valid and safe - so, there are new logs with much happier readings

    NOW, new question - it seems that during the "fixing" process i lost &/or screwed up my "printer spooling service' - there are no printers listed anymore and i can't access them, i get a warning that the "printer spooler service is not running" - any suggestions?

    i found a site for registry checks and DLed and it gave a bunch of errors, although i'm not sure which/if any maybe the problem - i certainly, don't wish to bring back the spy sheriff issue - i appreciate your time and effort! thanks again for any suggestions
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your new questions should be dicussed in the Software Forum. However it maybe be that for you printer problems that you just need to run services.msc and look for the Print Spooler service. Set the Service Status to Started and set to the Startup Type to Automatic.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds