Spy Sheriff removal.

Discussion in 'Malware Help (A Specialist Will Reply)' started by igetbombed, Nov 9, 2005.

  1. igetbombed

    igetbombed Private E-2

    I've been infected!!! This stupid spy sheriff program won't go away. I've read as many of the posts I could find and have done the following so far.

    1.)Tried to do add/remove program - yet it comes back everytime I've rebooted.
    2.)Run ALL of the following Ad-Aware SE (after updating), smitrem, ewido, cleanup!, spybot search and destroy

    I then downloaded hijackthis and created the following log file:
    (see attachment).

    Any clue how I can now get rid of this for good??
    I'm fairly computer literate - but this is the first time I'm using this site, so If I did something wrong, I appologize. Thanks in advance guys.
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MajorGeeks.com, please follow the steps below:

    http://www.majorgeeks.com/images/grenade.gif Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    http://www.majorgeeks.com/images/grenade.gif Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    http://www.majorgeeks.com/images/grenade.gifAfter doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    http://www.majorgeeks.com/images/grenade.gif Downloading, Installing, and Running HijackThis
     
  3. igetbombed

    igetbombed Private E-2

    Did what you said and reposted my results. Please let me know if there is any other information I could give you.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you have completed all of the steps in the READ ME attach a current HJT log from normal mode.
     
  5. igetbombed

    igetbombed Private E-2

    Here is the new HJT file - please take a look and let me know how to get rid of this

    I did in fact run all the steps in the "do this before posting" post.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download Spy Sweeper
    • Click the link above to download the program.
    • Install it. Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Options on the left side.
    • Click the Sweep Options tab.
    • Under What to Sweep please put a check next to the following:
      • Sweep Memory
      • Sweep Registry
      • Sweep Cookies
      • Sweep All User Accounts
      • Enable Direct Disk Sweeping
      • Sweep Contents of Compressed Files
      • Sweep for Rootkits
      • Please UNCHECK Do not Sweep System Restore Folder.
    • Click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into notepad and save it as spysweeper.txt and attach it to your next post along with a fresh HJT log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds