1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

SpySheriff help.

Discussion in 'Virus & Other Malware Removal' started by Slader81, Jan 13, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. Slader81

    Slader81 Thread Starter

    Joined:
    Jan 13, 2006
    Messages:
    5
    I've gotten this infection called spysheriff and nothing i do works. ive delete reg, .dll's, .exe and everything i do it keeps coming back. I've ran scans from alot of programs and nothing works. Any advise on what i should do? regsrv32.exe will not stop running. Something is causing it to start and i cant find what it is

    Logfile of HijackThis v1.99.1
    Scan saved at 4:43:08 PM, on 1/13/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\System32\shell386.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    D:\My Software\hijackthis\HijackThis.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\WINDOWS\system32\regsvr32.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R3 - URLSearchHook: (no name) - _{855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
    O2 - BHO: winapi32.MyBHO - {06CC1B18-42FA-41B8-91A9-D3E3A848C7A8} - C:\WINDOWS\System32\winapi32.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\GameClient.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
    O16 - DPF: ConferenceRoom Java Client - http://chat.ksexradio.com/java/cr.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
    O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
    O16 - DPF: {06CC1B18-42FA-41B8-91A9-D3E3A848C7A8} (winapi32.MyBHO) -
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/13f80402e99f594ad805/netzip/RdxIE601.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://pcpitstop.com/pestscan/pestscan.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127537137402
    O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
    O16 - DPF: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper) -
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {EEE7178C-BBC3-4153-9DDE-CD0E9AB1B5B6} -
    O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by113fd.bay113.hotmail.msn.com/activex/HMAtchmt.ocx
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
     
  2. Carbonik

    Carbonik

    Joined:
    Jan 13, 2006
    Messages:
    12
    I'm not a PC genius, but have you checked the \Microsoft\Windows\CurrentVersion\Run registry keys?

    Usually that's how the spyware/trojan/virus reinstalls itself.
     
  3. Slader81

    Slader81 Thread Starter

    Joined:
    Jan 13, 2006
    Messages:
    5
    yes. i've deleted teh same reg's over and over, but they keep coming back
     
  4. Ricochet9

    Ricochet9

    Joined:
    Jan 9, 2006
    Messages:
    37
    I'm a rookie so bare with me :)
    I had the same problem (but it was called SpyAxe, not SpySheriff). I think it's Malware which:
    -Installs a programme onto your computer without your permission.
    -Redirects your homepage to a system warning about Malware.
    -Slows down web browsing.
    -Gives you a speech bubble warning-thingy on the bottom right of your screen (above your icons) and makes a popping noise every 3 seconds or something.
    Those are the symptoms I had.
    How to get help:
    -Download Hijackthis http://www.thespykiller.co.uk/files/HJTSetup.exe
    -Click scan and save a logfile.
    -Then post it here so the moderators can take a look at it for you.
    DON'T click fix on anything in hijack this
     
  5. Carbonik

    Carbonik

    Joined:
    Jan 13, 2006
    Messages:
    12
  6. Slader81

    Slader81 Thread Starter

    Joined:
    Jan 13, 2006
    Messages:
    5
    that didnt work thxs thos. I dont have any of those files left on my pc that it says spysheriff installs, b ut i keep getting fake alerts and directed to spysheriff website and i also have a couple of trojans that keep coming up with my scans, but when i delete them they come right back
     
  7. Carbonik

    Carbonik

    Joined:
    Jan 13, 2006
    Messages:
    12
    Try downloading and installing that Ewido Anti-malware program. It's about 7mb. It fixed my problem.
     
  8. Slader81

    Slader81 Thread Starter

    Joined:
    Jan 13, 2006
    Messages:
    5
    thxs Carbonik that program did teh trick.
     
  9. pivot_master

    pivot_master Banned

    Joined:
    Jan 12, 2006
    Messages:
    62
    is your system totally fine now?
     
  10. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    You have multiple things - post a new hijack log so that we can see what Ewido got

    I assume you didn't save the Ewido log
     
  11. pivot_master

    pivot_master Banned

    Joined:
    Jan 12, 2006
    Messages:
    62
    Nobody told him to... so i assume not.
     
  12. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/433821

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice