.. wrote:
> In article <448bf64d$>,
> says...
>> Philip wrote:
>>> One of our two Windows machines (Dell Dimension 8400, Win XP SP2) has
>>> acquired a SpySheriff infection. AVG & Spybot report it as malware but
>>> don't seem able to clear it out.
>>>
>>> Google tells me it's resistant to being removed and can lead randomly to
>>> BSOD.
>>>
>>> A product from Canada called XoftSpy claims to be able to remove it but
>>> shows an unhealthy interest in my credit card, and has a website full of
>>> praise that is entirely self-referential.
>>>
>>> Any suggestions?
>>>
>>> Philip
>> Good luck
>> I just reinstalled my PC to get rid of the related Brave_____ (can't
>> quite remember at the moment) thing which hacks its way in.
>>
>
> If you can find manual removal instructions for this type of scumware,
> then Barts PE (or Utimate Boot CD for Windows, a extended Barts PE) is
> very useful tool in removing this crap as it operates outside the
> Windows installation by being a live Windows CD (as some scumware can
> not even be removed from Safe mode).
The problem is - working out how to get rid of it altogether
I had this nasty one downloading files from traffall.biz, had been doing
it for about a week and running stuff through porn sites behind my back
as well, all recorded in our internet logs. Spent hours trying to get
rid of it, I would be running Sysinternals Process Watcher (it disables
access to Task Manager) and whoops, another process with a strange
filename like 60AC.TMP would launch itself from somewhere. After
checking everything I could think of I formatted and reinstalled, also
gets rid of all the crap it downloaded. It only took a few hours to get
everything working again from scratch.