Remaining problems after SpySheriff infection

Remaining problems after SpySheriff infection

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Remaining problems after SpySheriff infection Leo 12-30-2005
Posted by =?Utf-8?B?TGVv?= on December 30, 2005, 10:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On one of the accounts on my computer, running under XP, I attracted the
SpySheriff Troyan horse last Monday. As a result the desktop of this account,
was covered with a dark bleu background with a black box on it and stating in
big red letters that the computer was infected. All icons were still visible.
Furthermore every few seconds a pop-up message appeared from the task bar
indicating the same.

After running AdAware SE, I was able to remove quite a few files which were
linked to this or other unwanted programs. The bleu desktop background with
the black box and red letters as well as the pop ups remained, however.
Subsequently, I downloaded and ran Microsoft antiSpyware. Again a few
unwanted files were found and remove from my PC. The bleu desktop background
with black box and red letters, however, was still there; the pop ups were
gone.
Finally, McAfee was able to find even more files which were removed. I am
now left with the bleu background, from which the black box with the red text
is gone. I am not able to change the background of my desktop back to the
original picture via screen properties.

Furthermore, when starting up this account a now always get the following 2
error messages (translated from Dutch):
VCClient.exe: Can not initialize this application properly (0xc0000135).
Press OK to terminate the application.
VCMain.exe: Can not initialize this application properly (0xc0000135). Press
OK to terminate the application.

In the folder C:/program files/common files a folder is present named
“VCClient”. This contains a number of files.

My other account, on the same computer, seems not to be affected.

Questions:
How can I get back the control over my desktop background and remove the
bleu background?
What to about the error messages when starting up the account?
What is the function of the files in the VCClient folder; can I delete this?
What more can I do to prevent further infections like this (besides not
logging on to the net ;-))?
--
Leo

Posted by David H. Lipman on December 30, 2005, 10:50 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| On one of the accounts on my computer, running under XP, I attracted the
| SpySheriff Troyan horse last Monday. As a result the desktop of this account,
| was covered with a dark bleu background with a black box on it and stating in
| big red letters that the computer was infected. All icons were still visible.
| Furthermore every few seconds a pop-up message appeared from the task bar
| indicating the same.
|
| After running AdAware SE, I was able to remove quite a few files which were
| linked to this or other unwanted programs. The bleu desktop background with
| the black box and red letters as well as the pop ups remained, however.
| Subsequently, I downloaded and ran Microsoft antiSpyware. Again a few
| unwanted files were found and remove from my PC. The bleu desktop background
| with black box and red letters, however, was still there; the pop ups were
| gone.
| Finally, McAfee was able to find even more files which were removed. I am
| now left with the bleu background, from which the black box with the red text
| is gone. I am not able to change the background of my desktop back to the
| original picture via screen properties.
|
| Furthermore, when starting up this account a now always get the following 2
| error messages (translated from Dutch):
| VCClient.exe: Can not initialize this application properly (0xc0000135).
| Press OK to terminate the application.
| VCMain.exe: Can not initialize this application properly (0xc0000135). Press
| OK to terminate the application.
|
| In the folder C:/program files/common files a folder is present named
| VCClient. This contains a number of files.
|
| My other account, on the same computer, seems not to be affected.
|
| Questions:
| How can I get back the control over my desktop background and remove the
| bleu background?
| What to about the error messages when starting up the account?
| What is the function of the files in the VCClient folder; can I delete this?
| What more can I do to prevent further infections like this (besides not
| logging on to the net ;-))?



Two part reply..

Perform Part 1 then perform Part 2.

It is suggested that you execute each tool in Normal Mode then in Safe Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0, then
you are are strongly urged to remove any/all versions that are prior to JRE
Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0 Update 6
be installed ASAP.

http://www.java.com/en/download/manual.jsp




Use the alternate if the first two parts are ineffective...
Note: Alternate only for Win2K, WinXP and Win2003 Server

Part 1
-----------

Use noahdfear's SmitFraud and SpyAxe removal tool -- SmitRem.exe
http://noahdfear.geekstogo.com/click%20counter/click.php?id=1

http://www.bleepingcomputer.com/forums/topic36868.html


Part 2
-----------

Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to enable WGET.EXE to download the needed McAfee related files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\ScanReport.HTML will be
generated. At the
end of the scan, it will be displayed in your browser (Opera, FireFox or
Internet Explorer).
It is suggested that you move the report out of c:\mcafee before performing
another scan.

Alternate:

Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.

http://secured2k.home.comcast.net/tools/AntiPuper.exe

http://forums.mcafeehelp.com/viewtopic.php?t=65072


Please Copy and Paste the contents of the HTML Log file;
C:\mcafee\ScanReport.HTML in your
reply.

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Malke on December 30, 2005, 10:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Leo wrote:

> On one of the accounts on my computer, running under XP, I attracted
> the SpySheriff Troyan horse last Monday. As a result the desktop of
> this account, was covered with a dark bleu background with a black box
> on it and stating in big red letters that the computer was infected.
> All icons were still visible. Furthermore every few seconds a pop-up
> message appeared from the task bar indicating the same.
>
> After running AdAware SE, I was able to remove quite a few files which
> were linked to this or other unwanted programs. The bleu desktop
> background with the black box and red letters as well as the pop ups
> remained, however. Subsequently, I downloaded and ran Microsoft
> antiSpyware. Again a few unwanted files were found and remove from my
> PC. The bleu desktop background with black box and red letters,
> however, was still there; the pop ups were gone.
> Finally, McAfee was able to find even more files which were removed. I
> am now left with the bleu background, from which the black box with
> the red text is gone. I am not able to change the background of my
> desktop back to the original picture via screen properties.
>
> Furthermore, when starting up this account a now always get the
> following 2 error messages (translated from Dutch):
> VCClient.exe: Can not initialize this application properly
> (0xc0000135). Press OK to terminate the application.
> VCMain.exe: Can not initialize this application properly (0xc0000135).
> Press OK to terminate the application.
>
> In the folder C:/program files/common files a folder is present named
> “VCClient”. This contains a number of files.
>
> My other account, on the same computer, seems not to be affected.
>
> Questions:
> How can I get back the control over my desktop background and remove
> the bleu background?
> What to about the error messages when starting up the account?
> What is the function of the files in the VCClient folder; can I delete
> this? What more can I do to prevent further infections like this
> (besides not logging on to the net ;-))?

The VCClient is connected with Volcano chat and is malware. Use the
System Configuration Utility to remove the reference to it in Startup.

How to Troubleshoot By Using the Msconfig Utility in Windows XP -
http://support.microsoft.com/?id=310560

You may also want to run HijackThis and post your log to one of the
following forums (not here, please) to make sure your computer is
really clean:

http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Merijn
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42 -
another tutorial
http://aumha.net/viewforum.php?f=30
http://castlecops.com/forum67.html
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

For the Desktop issue - Go to the Display applet in Control Panel and
look on the Desktop tab. Click on Customize Desktop, and then click on
the Web tab. You will see that there are checkmarks next to "My Current
Home Page" and probably "Lock Desktop Items". Uncheck these. By
highlighting the "My Current Home Page" and clicking on the Properties
button, you will be able to determine the name of the file that is the
message. It might be called something like "security.html" or the like.

Click Apply and OK out when you've made your changes. Then you want to
find the *.html malware file and delete it.

If you can't enable desktop backgrounds after a virus, MVP Kelly Theriot
has a fix. Look under Wallpaper-Desktop-Disable Changing here:

http://www.kellys-korner-xp.com/xp_w.htm

If Display tabs are missing, run Kelly's registry edit on line 285,
right-hand side "Restore all display tabs".

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Posted by Alison Dew on December 30, 2005, 12:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Run this removal tool

AntiPuper v1.1 by secured2k
http://secured2k.home.comcast.net/tools/AntiPuper.exe

This tool removes Spysheriff and unlocks the ability to change or disable
the desktop background image or active web desktop background. You will need
to manually change your desktop background.
Go to Control Panel > Display > Desktop Tab > Customize Desktop > Web Tab.
If you see any entries that are checked, uncheck them. Click OK.





> On one of the accounts on my computer, running under XP, I attracted the
> SpySheriff Troyan horse last Monday. As a result the desktop of this
> account,
> was covered with a dark bleu background with a black box on it and stating
> in
> big red letters that the computer was infected. All icons were still
> visible.
> Furthermore every few seconds a pop-up message appeared from the task bar
> indicating the same.
>
> After running AdAware SE, I was able to remove quite a few files which
> were
> linked to this or other unwanted programs. The bleu desktop background
> with
> the black box and red letters as well as the pop ups remained, however.
> Subsequently, I downloaded and ran Microsoft antiSpyware. Again a few
> unwanted files were found and remove from my PC. The bleu desktop
> background
> with black box and red letters, however, was still there; the pop ups were
> gone.
> Finally, McAfee was able to find even more files which were removed. I am
> now left with the bleu background, from which the black box with the red
> text
> is gone. I am not able to change the background of my desktop back to the
> original picture via screen properties.
>
> Furthermore, when starting up this account a now always get the following
> 2
> error messages (translated from Dutch):
> VCClient.exe: Can not initialize this application properly (0xc0000135).
> Press OK to terminate the application.
> VCMain.exe: Can not initialize this application properly (0xc0000135).
> Press
> OK to terminate the application.
>
> In the folder C:/program files/common files a folder is present named
> "VCClient". This contains a number of files.
>
> My other account, on the same computer, seems not to be affected.
>
> Questions:
> How can I get back the control over my desktop background and remove the
> bleu background?
> What to about the error messages when starting up the account?
> What is the function of the files in the VCClient folder; can I delete
> this?
> What more can I do to prevent further infections like this (besides not
> logging on to the net ;-))?
> --
> Leo



Posted by Leythos on December 30, 2005, 12:49 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Run this removal tool
>
> AntiPuper v1.1 by secured2k
> http://secured2k.home.comcast.net/tools/AntiPuper.exe

NNTP-Posting-Host: ppp-69-237-53-123.dsl.bkfd14.pacbell.net
69.237.53.123 PCBUTTS1

And if it works for you, make sure that you give the AUTHOR of the fix
credit for it - the person posting the link has nothing to do with the
creation of the fix, only seeking to take credit for it.

--

spam999free@rrohio.com
remove 999 in order to email me

Similar ThreadsPosted
spysheriff December 27, 2006, 7:57 am
Spysheriff solution? Seriously . . . January 9, 2007, 2:45 pm
Qoologic infection? July 1, 2005, 6:10 pm
Adware infection December 1, 2008, 2:52 pm
Windows XP "RBOT" virus infection? February 18, 2006, 7:20 pm
Confirmed infection: TROJ_SE.85638 March 14, 2006, 8:53 pm
Infection found: Win32/Parasitic-gen February 5, 2007, 7:23 pm
Post-infection registry repair November 23, 2008, 7:05 am
System tray pop-out "buy me - to fix infection" type malware... September 23, 2008, 3:29 am
MS Anti-Spyware won't install after SpyAxe/Zlob infection January 3, 2006, 12:17 pm

The site map in XML format XML site map

Contact Us | Privacy Policy