- SpySheriff
-
SpySheriff is malware that disguises itself as an anti-spyware program. SpySheriff is also known as Brave Sentry, Pest Trap, SpyTrooper,[1] and SpywareNo.[2] The program attempts to trick the user of an infected computer into buying the program by repeatedly informing them of false threats to their system.[3] SpySheriff is difficult to remove from an infected computer;[4] attempting to remove it using the "Add/Remove Programs" applet in control panel does not remove all components,[5] and SpySheriff's components may be in the System Restore folders.[6] However, SpySheriff can easily be removed using anti-malware tools.[7]
Contents
Websites
SpySheriff used to be hosted at www.spy-sheriff.com. However, this website is now defunct.[8] Several typosquatted websites also attempted to automatically install SpySheriff, including a version of Google.com (oogle.com). As of 2007, these sites no longer distribute SpySheriff.
Problems caused by SpySheriff
- SpySheriff reports false malware infections and uses poor heuristics to detect real malware infections[1].
- The desktop background may be replaced with an image resembling a blue screen of death, or a notice reading: "SPYWARE INFECTION! Your system is infected with spyware. Windows recommends that you use a spyware removal tool to prevent loss of data. Using this PC before having it cleaned of spyware threats is highly discouraged.".[5]
See also
- Rogue security software
- Trojan horse (computing)
References
- ^ a b "SpySheriff Technical Details". Symantec. http://subsync.symantec.com/security_response/writeup.jsp?docid=2005-122910-4625-99&tabid=2. Retrieved 2009-11-01.
- ^ "SpywareNo!". http://www.spywareguide.com/product_show.php?id=2136. Retrieved 2009-11-11.
- ^ "Spyware tunnels in on Winamp flaw". Joris Evers, CNET News.com, February 6, 2006. http://www.zdnetasia.com/news/security/0,39044215,39310016,00.htm. Retrieved 2009-11-01.
- ^ "Top 10 rogue anti-spyware". Suze Turner, ZDNet, December 19, 2005. http://blogs.zdnet.com/Spyware/?p=727. Retrieved 2009-11-01.
- ^ a b "SpySheriff - CA". CA. http://www.ca.com/securityadvisor/pest/pest.aspx?id=453096400. Retrieved 2009-11-01.
- ^ "Persistent Malware: Microsoft's System Restore Feature". CA. http://community.ca.com/blogs/securityadvisor/archive/2008/11/05/persistent-malware-microsoft-s-system-restore-feature.aspx. Retrieved 2009-11-01.
- ^ "PestTrap removal instructions". spywareremove.com. http://www.spywareremove.com/removePestTrap.html. Retrieved 2009-11-01.
- ^ "SunBelt Security Blog". Sunbelt Security. http://sunbeltblog.blogspot.com/2005/10/sleazy-install-of-week.html. Retrieved 2009-11-01.
External links
Categories:- Rogue software
- Windows trojans
- Scareware
Wikimedia Foundation. 2010.