Home Malware Programs Malware SpySheriff

SpySheriff

Posted: May 30, 2006

Threat Metric

Threat Level: 7/10
Infected PCs: 162
First Seen: July 24, 2009
Last Seen: April 18, 2023
OS(es) Affected: Windows

ScreenshotSpySheriff is a system hijacker that secretly installs to victim PCs. SpySheriff causes the desktop to change and display a fake warning message that tricks users into installing the antispyware software. SpySheriff forbids access to some web sites and may even block any attempts to connect to the Internet. SpySheriff can also disable some Windows essential components and tools such as the System Restore and the Date and Time application.

Screenshot

Aliases

PAK_Generic.001 [TrendMicro]Downloader [Symantec]Trojan-Downloader.Gen [Sunbelt]Troj/Dropper-MG [Sophos]Adware/MediaTickets [Panda]Win32/Adware.MediaTickets.A [NOD32]Adware:Win32/PurityScan.dr [Microsoft]Trojan.Crypt.XPACK.Gen [McAfee-GW-Edition]potentially unwanted program Adware-PurityScan [McAfee]not-a-virus:AdWare.Win32.PurityScan [K7AntiVirus]not-a-virus:AdWare.Win32.PurityScan.u [Ikarus]Adware/Purityscan [Fortinet]W32/Malware [F-Secure]Win32/Secdrop.NA [eTrust-Vet]Win32.Downloader [eSafe]
More aliases (33)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



anr0129.exe, winstall.exe, wn0129.exe, us0129[1].exe File name: anr0129.exe, winstall.exe, wn0129.exe, us0129[1].exe
Size: 16.89 KB (16896 bytes)
MD5: eb790be93afb8481cfc43515b00976ab
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
anr10049.exe, Tempwn10049.exe, us10049[1].exe File name: anr10049.exe, Tempwn10049.exe, us10049[1].exe
Size: 16.89 KB (16896 bytes)
MD5: 4c636e4d39efb85c84831973f8134bc9
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
anr10077.exe, Tempwn10077.exe File name: anr10077.exe, Tempwn10077.exe
Size: 16.89 KB (16896 bytes)
MD5: 5353b1a6165776cd500f1ceb8080e4fe
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
Installer.exe File name: Installer.exe
Size: 578.56 KB (578560 bytes)
MD5: 242a20bae9cf9cb816a447150378c02d
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
SpySheriff.exe File name: SpySheriff.exe
Size: 415.74 KB (415744 bytes)
MD5: 0a75149998278734106f2a6f59ba965a
Detection count: 41
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
winstall.exe, webinstall[1].exe File name: winstall.exe, webinstall[1].exe
Size: 122.88 KB (122880 bytes)
MD5: e3e03c8bdfd1f9c7dc9f2103689c5018
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
C:\Documents and Settings\<username>\Desktop\Programming\rogueware\SpySheriff - Program Files\heur002.dll File name: heur002.dll
Size: 119.8 KB (119808 bytes)
MD5: ee21fd7fa9a45453ed55ccb7ce7b9aaa
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Documents and Settings\<username>\Desktop\Programming\rogueware\SpySheriff - Program Files\heur002.dll
Group: Malware file
Last Updated: November 6, 2022
C:\Documents and Settings\<username>\Desktop\Programming\rogueware\SpySheriff - Program Files\heur000.dll File name: heur000.dll
Size: 127.48 KB (127488 bytes)
MD5: ca4822789da674e2ae4658ee4250adb5
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Documents and Settings\<username>\Desktop\Programming\rogueware\SpySheriff - Program Files\heur000.dll
Group: Malware file
Last Updated: November 6, 2022
C:\Documents and Settings\<username>\Desktop\Programming\rogueware\SpySheriff - Program Files\heur003.dll File name: heur003.dll
Size: 120.83 KB (120832 bytes)
MD5: bb06f2c0d34812d455aecc790aab74d4
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Documents and Settings\<username>\Desktop\Programming\rogueware\SpySheriff - Program Files\heur003.dll
Group: Malware file
Last Updated: November 6, 2022

Registry Modifications

The following newly produced Registry Values are:

File name without pathSpySheriff.lnkRun keysWindows installer

Additional Information

The following directories were created:
%ProgramFiles%\SpySheriff

Related Posts

2 Comments

  • Raji says:

    Suberp Website good that we have websites as such to help even the tech people to remove manually the spywares. I wish this website should be popular as google

  • system tool virus removal windows xp says:

    Thank you but all my programs including Task Manager are infected and won't open except for Mozilla Firefox

Loading...