SpySheriff

From Wikipedia, the free encyclopedia

SpySheriff is an illicit program disguised as a spyware protection program. Some people call it the most unpleasant malware/adware. Ironically, it installs itself undetected by many spyware-blocking utilities and then announces (from the taskbar) that your computer has been infected by spyware. Reportedly, the program has been mostly sighted around msnbc.com [citation needed], and users are warned to use extreme caution in dealing with SpySheriff. While it seems like shareware, suggesting to the user ways in which it supposedly protects a computer, it in fact yields several undesired and hard-to-reverse effects. The program attempts to convince the user to pay money for software purportedly to resolve problems that may, or may not, exist.

Contents

[edit] Problems with SpySheriff

  • Attempts to delete SpySheriff are frequently reported to be unsuccessful as it apparently reinstalls if even a portion of SpySheriff components remain.
  • Users have reported that trying to remove SpySheriff using the add/remove software control panel variously does nothing or may cause a crash, possibly indicating an attempt to prevent the user from removing SpySheriff.
  • Users have reported attempts to connect to the internet via a web browser having been blocked by SpySheriff, and the display of a BSOD suggesting "the system has been stopped to protect you from Spyware."
  • The desktop background can also replaced with a plain blue wallpaper or a notice saying: "SPYWARE INFECTION! Your system is infected with spyware. Windows recommends that you use a spyware removal tool to prevent loss of data. Using this PC before having it cleaned of spyware threats is highly discouraged."

SpySheriff also corrupts programs or overlay files and causes a degradation in system performance. It also encourages users to purchase its clone, a malware piece called SpywareNo.

  • Also reported, and perhaps one of the most serious issues with SpySheriff, is that it acts to stop any attempt to do a System restore by preventing the calendar and restore points from loading. This prevents the user from being able to revert their computer to an earlier usable state. A loop hole has been reported, however, in that if you undo your last restore operation, the system may successfully restore itself possibly allowing the user a chance to be rid of SpySheriff. A System restore is often also possible after booting in Safe mode.
  • SpySheriff has been known to create another user account, at the administrator level, to block access to programs and utilities for other users. If logged in as an administrator, it is sometimes possible to delete the SpySheriff account.
  • SpySheriff and many other trojan horses may be deleted with a program called 'Norton Internet Security'. Although it lags your computer, it protects and deletes harmful viruses, worms and trojan horses from your computer.

[edit] Remedy and Awareness

Though SpySheriff has stated on their website, which will not be posted here as it could infect your computer with malware, that 'NBC has reviewed the program and considers it a wonderful form of protection', this claim cannot be confirmed and is highly unlikely. If SpySheriff shows up on your Desktop, be sure to immediately do a System Restore (the block only works after you shut down and restart) to refresh the system and flush SpySheriff out. Anti-Spyware programs, such as Spybot, Spy Sweeper, and Ad-Aware, all identify SpySheriff as malware and attempt to remove SpySheriff from the infected system. Additionally, SpySheriff removal programs and step-by-step removal guides are available from various sources [1] [2] [3].

[edit] SpySheriff Clones

The company that developed SpySheriff has known that people have become more aware of SpySheriff being malware and has created several SpySheriff clones that have different names and styles than SpySheriff, but share the same interface and similar behaviors of SpySheriff. Below is a list of names of SpySheriff clones.

  • PestTrap
  • PestWiper
  • SpywareNo
  • SpyDemolisher
  • SpyTrooper
  • BraveSentry
  • DIARemover
  • Spyware-Stop

[edit] See also

rogue software

[edit] External links

In other languages