Do you have pop-ups or your computer infected with trojan or spyware ? Learn how to ask us for help, click here!

How to remove Spyware Sheriff and Antispylab

Spyware Sheriff is an rogue antispyware application that uses Trojans and other malware into tricking or scaring you into purchasing it. If you are infected with this malware, your Internet Explorer home page will be reset to about:blank and display a fake Windows Security Center alert stating that you are possibly infected.

When you click on the button on this page it will bring you to the site antispylab.com which attempts to sell you either Spyware Sheriff, Adware Sheriff, or Regfreeze Antispy.This program will also create fake security alerts in the Windows taskbar stating that there are various security risks with your computer ranging from spam and hack attempts to Trojan infections. When you click on these alerts they will bring you to the antispylab.com site as well. There have also been reports of this infection crashing the legitimate Microsoft process lsass.exe.

lsass

When this process crashes, your computer will begin a countdown which at the end will shutdown your computer.

Read more about Spyware Sheriff: New rogue antispyware – SpywareSheriff

As your first step, please download HijackThis.

Important: Create a specific folder on your hard drive called HijackThis to keep its backups.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HijackThis.
Download HijackThis.exe into this folder.

Print out these instructions as we will need to close every window that is open later in the fix.
Download SmitfraudFix. Extract the content (a folder named SmitfraudFix) to your Desktop.

Download and unzip Avenger to your desktop.

Download CCleaner. Double click on the file for install.

Next, Download, install, and update the free version of Ewido security suite:

1. When installing, under “Additional Options” uncheck “Install background guard” and “Install scan via context menu”.
2. Run Ewido.
3. From the main ewido screen, click on update in the left menu, then click the Start update button.
4. After the update finishes (the status bar at the bottom will display “Update successful”)
5. Exit Ewido. DO NOT scan yet.

Reboot your computer in Safe Mode by doing the following:

1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd. Press the number 2 on your keyboard and the press the enter key to choose the option Clean (safe mode recommended).

You will be prompted : “Registry cleaning – Do you want to clean the registry ?“; answer “Yes” by typing Y and press “Enter” in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer “Yes” by typing Y and press “Enter”.

The tool may need to restart your computer to finish the cleaning process; if it doesn’t, please restart it into Normal Windows.

Reboot again your computer in Safe Mode.

Start up Avenger.
Check the ‘Input script manually’ option.
Click the Magnifying Glass icon.
In the box that opens, copy,then paste the following bold text:

Files to delete:
C:\WINDOWS\system32\winapi32.dll

Then click on ‘Done’.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.

Reboot your PC again in Safe mode.

Run HijackThis, Choose “Do a system scan only” and checkmark the box next to the following entries:

O2 – BHO: winapi32.MyBHO – {26C43C19-A1CE-456E-9CBF-77FFB9E92681} – C:\WINDOWS\system32\winapi32.dll (file missing)
O2 – BHO: (no name) – {77701e16-9bfe-4b63-a5b4-7bd156758a37} – (no file)

close all other windows and browsers, then click “Fix Checked”.

Reboot your computer .

Run Ewido

1. Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
2. If Ewido finds anything, it will pop up a notification. Please select “clean” and check the boxes “Perform action with all infections” and “Create encrypted backup” before clicking on OK.
3. When the scan finishes, click on “Save Report“. This will create a text file. Make sure you know where to find this file again.

Run CCleaner.

Click Analyze button. After scan your system, click Run Cleaner.

Restart your computer in normal mode.

Run the Panda online virus scan.

- Once you are on the Panda site click the Scan your PC button
- A new window will open…click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.

Your computer should now be free of the Spyware Sheriff and Antispylab.com infection.

If you are still having problems with spyware after completing these instructions, then please follow the steps outlined in the topic linked below:

Spyware removal – Read Before Posting

Last update: 06/15/06

May 18, 2006 on 8:05 am | In Rogue Anti Spyware, Tutorials - HowTo | No Comments |


New rogue antispyware – SpywareSheriff

SpywareSheriff, a new rogue antispyware application that is starting to infect a lot of users. This particular infection is harder to remove than other variants such as SpywareQuake and SpyFalcon. This is because it uses a lot of random names for the files. It is, though, easy to tell when you are infected with this malware.

spyware sheriff

When infected your Internet Explorer home page will be set to about:blank that opens the screen shown below. If you attempt to change your home page to another site, it will reset it to the one below.

Then when you click on the page, it will take you to the url http://antispylab.com/
You will also periodically get fake taskbar messages that state the following among others:

Alert! Trojan.Virus.Z.32.exe launch attempt detected…
It is recommended that you run a full system scan now to
reveal other possible threats. Click here to download spyware
remover.

Internet attack attempt detected…
Somebody’s trying to infect your system with spyware or
harmful viruses. Run system scan now to secure your PC from Internet
attacks and hijacking attempts!
Click here to download spyware remover now…

Alert!
Trojan.Virus.Z.32.exe launch attempt detected and blocked!
It is recommended that you run a full system scan to reveal other
possible threats.
Click here to visit Security Center web site and protect your system
against spyware and harmful viruses…

Credit card hijacking attempt detected…
This is a result of harmful spyware activity.
Scan your PC now to reveal and remove malicious spyware.
Visit Windows Security site to download antispyware…

The application is distributed at antispylab(dot)com or spywaresheriff(dot)com.

If you can`t uninstall or remove, we can help, post in the Spyware Removal Forum about that.

Thanks to Bleeping Computer Blog

May 5, 2006 on 7:44 am | In Rogue Anti Spyware | No Comments |


Tutorials

Rogue antispyware/antivirus, malware removal instructions

How to remove Spyware Protect 2009 (Delete instructions)
How to remove Spyware Guard 2009 (Delete instructions)
How to remove Total Protect 2009 (Delete instructions)
How to remove eXPress Antivirus 2009 (Delete instructions)
How to remove iSafe AntiVirus (Delete instructions)
How to remove Astrum Antivirus Pro (Delete instructions)
How to remove System Security (Delete instructions)
How to remove MS Antispyware 2009
How to remove Antivirus 360 (Delete instructions)
How to remove Perfect Defender 2009 (Delete instructions)
How to remove ExtraAntivir (Delete instructions)
How to remove AntiSpywareGuard (Delete instructions)
How to remove Winweb Security 2008 (Delete instructions)
How to remove SpywareRemover2009 (Delete instructions)
How to remove Antivirus Trigger (Delete instructions)
How to remove XP Protection Center (Delete instructions)
How to remove VirusTrigger (Delete instructions)
How to remove SecureFileShredder or SecureFile Shredder (Removal instructions)
How to remove Ultra Antivirus
How to remove Antivirus Pro 2009
How to remove Personal Defender 2009
How to remove WinDefender 2009
Removal instructions for Real Antivirus
How to remove XP Antispyware 2009
How to remove Pro Antispyware 2009 (Antispyware Pro 2009) Delete instructions
How to remove SpyProtector
Removal instructions for PC Defender 2008
How to remove RapidAntivirus
Removal instructions for Antivirus 2010
How to remove AntispywareXP 2009
How to remove SpywareGuard2008 (Uninstall instructions)
How to remove PersonalAntispy malware
How to remove VideoActiveXCodec malware
How to remove rogue anti-spyware application eAntivirusPro
How to remove VirusResponseLab
How to remove rogue antispyware application Cleaner2009
How to remove SpyDevastator
How to remove Antispyware PRO XP
How to remove XP Protector 2009
How to remove System Antivirus 2008
How to remove Smartantivirus2009
How to remove Total Secure 2009
How to remove Antivirus XP 2008 and tdssserv.sys trojan
How to remove rogue antispyware: XP Guard, AntiVir64, MSAntivirus, Power Antivirus, SpywarePrevent, XpertAntivirus
How to remove cnn.com and msnbc.com fake breaking news spam-virus and joke-bluescreen malware
XLGuarder – fresh rogue antispyware | How to remove
How to remove VirusRemover2008 (Delete instructions)
How to remove AdvancedXPFixer and DisableSpyware rogue antispyware programs
How to remove XPSecurityCenter rogue antispyware
AntiSpywareMaster and RegistryGreat | How to remove
How to remove new rogue antispywares Malware Bell and IE Antivirus
How to remove IE Defender
VirusHeat rogue antispyware – How To Remove
How to remove IE Defender
How To Remove Spylocked And Spywarelocked rogue antispyware
How to remove DriveCleaner Infection
How to remove Spyware Sheriff and Antispylab
How to remove Spyware Soft Stop
How to remove SpywareQuake
How to remove BraveSentry
How to remove AlfaCleaner
How to remove SpyFalcon
How to remove VideoCodec3_05b – ICQCHK.exe – MSX.DLL
How to remove AdwarePunisher – rogue anti spyware
How to remove SpywareStrike
How to remove the Aurora, Nail.exe, Epolvy Hijackers
How to remove Winhound
How to remove SpyAxe
How to remove WinFixer
How to remove WebHancer

Trojans, worms removal instructions

How to remove msqpdxserv.sys trojan (trojan tidserv)
How to remove Win32.BackDoor-DNM, Spyware.ISpynow, win32.zafi.b, Win32.Netsky.Q, Trojan.Zlob.G (Fake Security Center Alert)
How to remove brastk.exe/karna.dat trojan or trojan.fakealert
How to remove trojan TDSServ (TDSSserv.sys), clbdriver.sys and seneka.sys
How to remove Trojan-Keylogger.WIN32.Fung (fake Windows Security Alert)
How to fix shell.exe, spoolvs.exe problem
How to remove xlavra (Trojan-Downloader.Win32.Agent) and Wintools adware
How to remove trojans that uses autorun.inf file
How to remove braviax.exe/cru629.dat/users32.dat malware
How to remove core.cache.dsk and parportt.sys
How to fix shell.exe, spoolvs.exe problem
How to remove xlavra (Trojan-Downloader.Win32.Agent) and Wintools adware
How to remove trojan dns/changer
Automatic removal HaxDoor trojan
How to remove Look2Me
How to remove Trojan Vundo (VirtuMonde, WindowsUpd, Adware.VirtuMonde, TrojanDownloader.Win32.Agent.e, ADW_TARGETSOFT.A)
How to remove BlackWorm, W32.Blackmal.E@mm, WORM_GREW.A, W32/Nyxem-D, Email-Worm.Win32.VB.bi

Popups, toolbars removal instructions

How to remove beautyscreens.com/jokes.php popups
How to remove CID popups
How to remove Video Add-on and antispyware/security toolbar 7.1
How to remove beautyscreens.com/jokes.php popups
Automatic removal MBS Account Manager
How to remove NEED2FIND and RXToolbar
How to remove HotBar
How to Remove the Ist Bar (Trojan.ISTsvc)

Hijackers removal instructions

How to remove webcry.com hijacker
How to remove savetheinformation.com and secirityonpage.com hijackers
How to remove Pcsecuritylab.com Hijacker
How to remove safenavweb.com hijacker
How to remove softwarereferral/safewebnavigate hijackers and etlrlws toolbar
How To Remove cyberstoll.com, search-daily.com hijacker and WebHancer spyware
How to remove webcry.com hijacker
How to remove savetheinformation.com and secirityonpage.com hijackers
How to remove Pcsecuritylab.com Hijacker
How to remove safenavweb.com hijacker
How to remove antispywarebox hijacker
How to remove CWS Hijacker
How to remove Needupdate (securityerrors) hijacker

Basic Windows instructions

How to make Internet Explorer more secure
How to drop rights for safe surf
How to disable Active Scripting support
How to remove browser hijackers
How to detect keylogger on my computer
How to use “Internet Zone Settings”
How to use the HOST file to block ads
How to install and use the Windows XP Recovery Console
How to show hidden files in Windows
How to Disable System Restore in Windows ME or Windows XP

Others instructions

How to block VML exploit
How to protect from PowerPoint 0-day vulnerability
How to block Drag-and-Drop Vulnerability
How to recovery lost files (due to W32.Blackmal.E@mm – BlackWorm virus or other reasons)
How to block WMF exploit

January 8, 2006 on 5:20 am | In | No Comments |



My Anti Spyware - Free antispyware programs and Spyware Removal Instructions.