“I have a malware infection on my laptop, i go into safe mode and look into
the files and the virus file comes up as spysheriff with an icon.”
How do i get rid of it?
Is it easy to get rid of?
How did i come accross it?
*******************************************************
How to get rid of it?
Check out my site:
http://elamb.blogharbor.com/hacked/removespysheriff.htm
If you have already, try this:
http://www.bleepingcomputer.com/forums/How_to_remove_SpySheriff_Winstallexe_Spysheriffexe-t22402.html
The Easiest Way to get rid of it:
Another way you may be able to remove it is to do a system restore:
http://www.elamb.org/hacked/systemerror384.htm
This is what I had to do because I had stuff going on even in Safe Mode.
How did I get it?
I was surfing some serial/crack/warez sites. They are absolutely
INFESTED with malware. Some porn sites are bad, but warez sites seem to
be the worst.
On way to Prevent it is to use FireFox:
See top of this blog.

This is a bogus error screen that replaces your browser's home page. The message Reads:
Detected Spyware! System error #384
Your IP address is XX.XXX.XX.XX. Using this address a remote computer has gained access to your computer and probably is collecting the information about the sites you've visited and the files contained in the folder Temporary Internet Files. Attention! Ask for help of install the software for deleting secret information about the sites you visited.
You computer is full of evidences!
More than likely, this message is just the tip of the iceberg. Using simple intrusion detection tools you will see that your system has scores of viruses, trojans, worms and other malware installed on it. The message is trying to get you to purchase some scamware.
How to remove the “Detected Spyware! System error #384” message and all the malware on your system?
There are actually a few relatively easy ways for removing this malware:
USE FREE (LEGITIMATE) ANTI-SPYWARE
PERFORM A SYSTEM RESTORE
COMPLETELY RE-INSTALL WINDOWS (self explanatory, and complete overkill unless you have rootkit on your system or something crazy like that.)
READ MORE HERE…
I was doing some testing on my Windows XP system surfing about some
sites of “ill repute” with IE6 and got hit with something called Spy
Sheriff.

Spy Sheriff is like a watered down version of PS Guard or Smithfaud. Like PS
Guard, Spy Sheriff claims to want to remove all the malware it infects
you system with. Both of these horrible bits of malicious code
are what I like to call scareware. The get loaded on to your
system along with about 100 other viruses, worms and trojans and take
over you desktop with a message like “Spyware Infection”. The
application then “scans” your system. And tells you that you must
activate the Spy Sheriff or PS Guard in order to clean your
system. When attempt to remove Spy Sheriff using Add/Remove programs, it simply adds itself again once you reboot.
In the background, all the malware they loaded on your system are
collecting data and send status report to a parts of the world.
The scareware will usually make sure you know this to convince you to
buy their product. DO NOT GIVE THEM YOUR CREDIT CARD INFO!
Here is how to remove Spy Sheriff.