also @ TechSpot: Lenovo sees huge increase in PC sales as rest of industry declines

Avg has trojan sheriff in vault

Discussion in 'Virus and Malware Removal' started by shetawk, Mar 6, 2008.

  1. shetawk Newcomer, in training Posts: 38

    AVG free says I have a trojan sheriff.D located in my spybot.exe program and that the file is in the vault.


    If I click "remove from the vault" does that mean to delete the whole file from my computer or will it release it back into my hard drive?

    Should I remove it, uninstall spybot and download it again?

    Thank you. ST
  2. Blind Dragon TechSpot Evangelist Posts: 4,048

    is this avg anti virus or anti-spyware?
  3. shetawk Newcomer, in training Posts: 38

    avg

    Thank you so much for getting back so soon.

    avg antivirus


    I just took all spybot files off after emptying the vault and then emptied trash.

    Sorry, I searched for avg and nothing came up. didn't know there were already posts on same subject.
  4. Blind Dragon TechSpot Evangelist Posts: 4,048

    No problem, infections are often unique to the infected machine, so it is always a good idea to get specific instructions.

    If you are concerned that there still may be infections on your machine, and would like to clean them

    Please follow these Viruses/Spyware/Malware, preliminary removal instructions and post back in this thread with the requested logs. There should be at least 3.

    1)AVG log
    2)Combofix log
    3)Hijackthis log (Step 15)
  5. shetawk Newcomer, in training Posts: 38

    OK, it'll take me a while. Have to download HJT and find out what a combofix log is.

    ; )
  6. shetawk Newcomer, in training Posts: 38

    testing...

    testing...
     
  7. shetawk Newcomer, in training Posts: 38

    testing 2...

    testing 2...
  8. shetawk Newcomer, in training Posts: 38

    Sheriff....rest coming. Thank you.

    Removed, files attached.
  9. shetawk Newcomer, in training Posts: 38

    AVG sheriff

    Removed, attachment later.
  10. shetawk Newcomer, in training Posts: 38

    Hijack avg sheriff.. Thank you

    Removed. Attached to later posts.
  11. shetawk Newcomer, in training Posts: 38

    What is a recovery console? Thank you. ST

    What is a recovery console?
  12. Blind Dragon TechSpot Evangelist Posts: 4,048

    It is something that is on your windows install CD. You can install it on your computer for when we fix malware. In case something goes wrong we can recover your computer.

    I am not seeing anything in your logs that looks bad though.

    Can you please attach the AVG log and combofix logs as an attachment using the icon above your reply that looks like a paperclip
  13. shetawk Newcomer, in training Posts: 38

    Here they are...

    avg log is xml and site won't load it. What can I change ext to? Thank you.

    Attached Files:

  14. Blind Dragon TechSpot Evangelist Posts: 4,048

    change it to .txt or .log
  15. kritius TechSpot Guru Posts: 2,087

    C:\Program Files\Hijackthis\HijackThis.exe

    and

    C:\Program Files\Hijackthis\Crusty2.exe ?
  16. shetawk Newcomer, in training Posts: 38

    Hope this works... avg sheriff thank you.

    AVG just notified me that the sheriff is back in town in systm volume information\,restore{99D315FOD7-49D5-9FCC-528B21F98A9}\RP116\A0016556.exe
    Trojan horse SpySheriff.D




    thank you.

    Attached Files:

  17. shetawk Newcomer, in training Posts: 38

    Crusty?

    Somwhere on the site I was told to change Hijack to Crusty to avoid tricks to imbed viri in Hijack. There were two hijack.exe files, different sizes so I name one Crusty and the other Crusty2.


  18. shetawk Newcomer, in training Posts: 38

    recovery console...

    I installed the whole program.

    Is the file called recovery console?

    Thank you. ST
  19. shetawk Newcomer, in training Posts: 38

    Ran avg again and it said shell32.dll was changed.

    After I emptied virus chest on avg, I ran avg again and it said shell32.dll was changed.

    Did search and cannot find shell32.dll. Could it have been renamed?

    Afraid to turn my 'puter off because it may not come on again.

    Searched for "trojan" and "sheriff" and nothing came up.

    I'll do a trend housecall scan and see what comes up.

    ST
  20. Blind Dragon TechSpot Evangelist Posts: 4,048

    I think you are ok. You wont see files in the system32 folder, because windows hides them from you unless you tell it to show them to you.

    Where did you get the recovery console from?