Spy sheriff and wallpaper

Discussion in 'Malware Help (A Specialist Will Reply)' started by Gramm, May 30, 2005.

  1. Gramm

    Gramm Private E-2

    Hi all
    A week ago i had a lot of malware that come onto my computer.I could delete them all (with help from your forum :) ) but there is still one that that really bore me : Spy sheriff .
    This "spyware remover" is ... unremovable . I can't delete it,(I have tried from windows uninstaller to anti spyware to directory delete) and it has freezed my wallpaper to a black text box : "system stopped use spyware remover etc. "

    I need your help because it is real crap.
    thanks !!
    edit : i've forgot to say "please please please !!!!!!"
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Gramm

    Gramm Private E-2

    In fact, I have already run most of them, but I'm trying again anyway.
    I can't access to internet from safe mode because my adsl modem don't run while on it (I'm actually in normal mode).
    I can't neither run online scan online fron trend or symantec because one let me with a blank box with a little red cross , while the auther open a blank window that stills loading for about 15mn...Maybe some program like spyblaster have overprotected my computer ?
    So i am installing trial of trend...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just complete all the steps that you can and provide feedback on the results. Do not install more than one full antivirus application. This does not include online scanners. Just the full AV package.
     
  5. Gramm

    Gramm Private E-2

    I have done almost everything.Expect 6 trojan, none of programs have found something .
    I have run them all from my login, which is not the one who is infected (spysheriff have infected one login out of 4).maybe it's why nothing was found(i don't think so).
    I think all these program search for malware whereas spysheriff is a "anti spyware" that found "trojan" (it is the only program that found trojan,it's possible they come with it) and it needs a registration to delete them out.
    I'm now posting a hijack log so you can see waht's going on.
    And do someone know how can i do to change my wallpaper?it's still freezed since spysheriff came...
     
  6. Gramm

    Gramm Private E-2

    Here is my log file ! Following board instructions ! :)
     

    Attached Files:

    • log.txt
      File size:
      6.6 KB
      Views:
      2
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why aren't you running the procedure on the infected user logins?

    By the way this login is infected too.

    Also your OS and IE version are way out of date. You must get updated after current problems are fixed.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you cannot uninstall SpySheriff using Add/Remove programs, the below steps should take care of it.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\win32.exe
    C:\WINDOWS\System32\t?skmgr.exe
    C:\Program Files\SpySheriff\SpySheriff.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Do you recognize the below abcsearch4u URLs as something you wanted? (I doubt it!) If not, fix them too.
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://abcsearch4u.com/index.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://abcsearch4u.com/index.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)
    O2 - BHO: IE SP2 AddOn - {FE99FED2-B81E-4BAE-922A-DD9D71887BC8} - C:\WINDOWS\System32\spnui.dll (file missing)

    Do you recognize this next line with Disk Keeper? If not, fix it too.
    O4 - HKLM\..\Run: [Disk Keeper] C:\WINDOWS\System32\Services\{CC1DDF65-9676-4C0F-98F3-A9AC9B53A03A}\SECURITY.EXE

    O4 - HKCU\..\Run: [wbjyfhy] c:\windows\rqmxfko.exe
    O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
    O4 - HKCU\..\Run: [awt4RPH7e] pxwehlp.exe
    O4 - HKCU\..\Run: [Oaol] C:\Documents and Settings\Maman.DELATTRE\Application Data\usou.exe
    O4 - HKCU\..\Run: [wupd] C:\WINDOWS\System32\win32.exe
    O4 - HKCU\..\Run: [Nzg] C:\WINDOWS\System32\t?skmgr.exe
    O4 - HKCU\..\Run: [fseunsg] c:\windows\gueolrn.exe
    O4 - HKCU\..\Run: [wcqcpgb] c:\windows\gueolrn.exe
    O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O15 - Trusted Zone: *.slotchbar.com
    O15 - Trusted Zone: *.windupdates.com
    O15 - Trusted IP range: 67.19.178.84


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\win32.exe
    C:\Program Files\SpySheriff <--- the whole folder
    c:\windows\rqmxfko.exe
    C:\winstall.exe
    c:\windows\pxwehlp.exe or c:\windows\system32\pxwehlp.exe
    C:\Documents and Settings\Maman.DELATTRE\Application Data\usou.exe
    C:\WINDOWS\System32\win32.exe
    c:\windows\gueolrn.exe


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. Gramm

    Gramm Private E-2

    It's all gone !!! :) :) :)
    but stills my wallpaper freezed...I can't do anything on wallpaper tab
    anyway thank's a lot for your help ! do you advise me to install SP1&2 ? I've heard a lot of bad things about the 2nd.
    I've attach a new hijack log.
    And thanks a lot again !
    (i'm happy)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're log is clean. Did you check your other user logins? Try the below for your Wallpaper problem.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixdt.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixsdt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes
     
  11. Marlmela

    Marlmela Private E-2

    oh my gosh I want to thank chaslang. I have been looking on google for nearly 5 hours before finding a solution to my problem. [death of spy sheriff] on my laptop. I personally registered on this forum just because I am so happy that it's finally GONE and I finally have my desktop back the way it was. THANKS CHASLANG YOU ARE THE BEST. I bow down to you.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy to hear it helped you out.
     
  13. MicroMicro

    MicroMicro Private E-2

    well i have the spy sherif wallpaper and i ran hijackthis and saved the log
    here is what it says please tell me what to do now



    oh and sorry for the late post
     
    Last edited by a moderator: Jun 20, 2005
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not your thread. Please read the announcement. No HJT logs should be posted unless requested. Especially do not post in another user's thread. Also run the steps in the READ ME FIRST sticky thread before even starting a thread. You have a lot more wrong than SpySheriff. Including this: C:\Program Files\Warez P2P Client\warez.exe
     
  15. estokes

    estokes Private E-2

    Hello

    I've followed everything written here (and the PLEASE READ FIRST thread)... I have FINALLY gotten rid of Spy Sheriff *whoop of joy* and I add the regedit posted here in an attempt to fix my desktop - The annoying messages are all gone, but I still have a gawdawful blue desktop and no option to change it in my display properties. Is there something more I could do?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post in your own thread and read the SpySheriff sticky: SpySheriff (aka SpywareNo) Removal
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds