SpySheriff

Discussion in 'Malware Help (A Specialist Will Reply)' started by jtu50, Jun 21, 2005.

  1. jtu50

    jtu50 Private E-2

    I have been infect with this piece of trash. Have run all programs in antivirus tutorials without success - nothing seems to detect it. Please advise how to remove this garbage. Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well first we need to work thru some standard cleanup procedures to remove any other possible background problems and to get you PC into a known state. We will get to SpySheriff in the end.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. jtu50

    jtu50 Private E-2

    Chaslang,

    Thanks for the reply. I ran all the basic stuff suggested, plus Trojanscan (only able to get it to run once, computer kept crashing). It found a bunch of cookies labeled as malware - deleted all cookies. Couldn't get Bitdefender to run - got a message Active X controls not allowed. Ran Panda, it found three viruses that it said Active scan couldn't remove. I haven't done anything else. Attached is HJT log. I did go into registry and deleted all references to SpySheriff. The program seems to have stopped running, but I'm still left with the desktop hijack



    Thanks for your help,
    Jeff
     

    Attached Files:

  4. jtu50

    jtu50 Private E-2

    Additional info - HJT was run in normal mode. After reading other threads with Spysheriff problem, I also found Daily weather, which is apparently a bad actor. It did not show up in Add/Remove, but there was a folder in Program files. I deleted it, but had to do so in safe mode.


    Jeff
     
  5. jtu50

    jtu50 Private E-2

    While waiting for reply, I read the Hijack This tutorial and followed instructions given to Mr. Anderson by BJGarrick in another thread. I think I've solved the problem. Everything appears normal. Attached is the final Hijackthis log. Please advise if any other actions are needed.


    Jeff
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to post your HJT log from normal boot mode so we can be sure you are clean.
     
  7. jtu50

    jtu50 Private E-2

    Attached is the HJT log done in normal mode after following all directions to eliminate Spysheriff and other trash. Please advise as to whether my system looks clean.

    Also if you don't mind, give me some reassurance about deleting msjava and replacing with sun java. I am concerned about ending up with more problems. Can sun java be loaded without deleting msjava to test it? If so how.

    Thanks for all your help.

    Jeff
     

    Attached Files:

  8. jtu50

    jtu50 Private E-2

    Ran Panda online scan again. It claims there is one infected file that "ActiveScan" cannot repair. How do I handle this?

    Jeff
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell us the file name and path! Can you delete it yourself after booting in safe mode?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Microsoft Java is not safe to use and is the root of many problems. Sun Java will not cause you more problems. It will prevent you from having more problems.

    Your HJT log is clean. Now complete the steps in the below thread to help keep you clean:

    How to Protect yourself from malware!
     
  11. jtu50

    jtu50 Private E-2

    Panda didn't give the location or name of the file, or I didn't see where it did so. If it is supposed to, I'll run it again and look for it. I used their online scanning program. I also tried to run Bitdefender, it now will run (before I was getting a message that Active x controls were not permitted), but IE keeps crashing during the scan. I plan to try again!

    Jeff
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is probably not a major problem but we should try to find out what Panda was referring to.

    You could also try the below online scanner:

    RavAntivirus <-- select Auto Clean then click Scan My PC
     
  13. jtu50

    jtu50 Private E-2

    Finally got bitdefender to complete a scan. It foundAdware.Wheaterbut.A in AIM(%. It could not repair or delete. I deleted the entire folder.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So does that mean everything is okay now?
     
  15. jtu50

    jtu50 Private E-2

    Actually, I ran Panda again, and figured out how to get a report. This is what came up:

    SpywareNo

    Technical name: Adware/SpywareNo

    Threat level: Low

    Alias: Trojan.Win32.FakeAlert.a, spysheriff.com, Renos

    Type: Spyware


    How do I get rid of it?

    Jeff
     
  16. jtu50

    jtu50 Private E-2

    I ran regedit and searched for spywareno. Found references to it, renos, and win32fakealert and delete them. Also found the following references which I think also refer to them but since I'm not sure I would like advice regarding deleting them.



    Key Name: HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603
    Class Name: <NO CLASS>
    Last Write Time: 6/24/2005 - 9:55 PM
    Value 0
    Name: 003
    Type: REG_SZ
    Data: Desktop.html

    Value 1
    Name: 004
    Type: REG_SZ
    Data: wp.bmp

    Value 2
    Name: 005
    Type: REG_SZ
    Data: wp.exe


    Once again, thanks for your help

    Jeff
     
  17. jtu50

    jtu50 Private E-2

    Found that I have lost the ability to modify my desktop. There is no active desktop option when right clicking on desktop. When going to Display Properties and clicking on Desktop tab, the image of the monitor shows a white screen and backround options are "frozen" - they just don't work.
     
  18. jtu50

    jtu50 Private E-2

    Does this have something to do with the registry changes I added from the response of bjgarrick to Mr. Anderson? The changes are attached
     

    Attached Files:

  19. jtu50

    jtu50 Private E-2

    Solved desktop problem by following directions given to Na13sh. Now only need to resolve items in registry - whether they can be deleted - see previous posts. Sorry to asking so many questions. Appreciate all the help

    Jeff
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MRUs are nothing to worry about. MRU = Most recently used. It is just a history of things that you have been doing.

    The full fix for SpySheriff and proper registy patch is in the sticky: SpySheriff (aka SpywareNo) Removal
     
  21. jtu50

    jtu50 Private E-2

    All seems to be well. I thank you so much for all your help. I do plan to run Panda one more time to see if everything is gone.

    Jeff
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     
  23. jtu50

    jtu50 Private E-2

    Chaslang,

    I ran Panda again. It keeps finding references to Spysheriff in my registry. Nothing else seems to find this. My computer is running fine. Any final suggestions?

    Jeff
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What and where is it finding it? If it is MRU's ignore them or run a program that removes MRU's (like MRUClear 1.4)
     
  25. jtu50

    jtu50 Private E-2

    It doesn't say exactly where it is, except in the registry. Nothing else seems to find it. Ran Norton, RAV, spybot, adaware. I'll try the mru cleaner. That may be it, if not I think I'll give up as everything seems to be working ok.

    Jeff
     
  26. jtu50

    jtu50 Private E-2

    Yup, turns out it was an MRU - ran MRUClear. No more virus warning from Panda. I'll leave you to bail some other poor soul out.

    Jeff :)
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds