SpySheriff


SpySheriff is malware that disguises itself as anti-spyware software. It attempts to mislead the user with false security alerts, scaring them into buying the program. Like other rogue antiviruses, after producing a list of false threats, it prompts the user to pay to remove them. The software is particularly difficult to remove, since it nests its components in System Restore folders, and also blocks some system management tools. However, SpySheriff can be removed by an experienced user, antivirus software, or by using a rescue disk.

Other names

SpySheriff is also known by numerous other names, including BraveSentry, Pest Trap, SpyTrooper, Adware Sheriff, SpywareNo, SpyLocked, SpywareQuake, SpyDawn, AntiVirGear, SpyDemolisher, System Security, SpywareStrike, SpyShredder, Alpha Cleaner, SpyMarshal, Adware Alert, Malware Stopper, Mr. Antispy, Spycrush, SpyAxe, MalwareAlarm,, VirusBurst, VirusBursters, DIARemover, AntiVirus Gold, Antivirus Golden, SpyFalcon, and TheSpyBot/SpywareBot. The name SpywareBot is used to confuse them with the legitimate SpyBot anti-spyware software.

Websites

SpySheriff was hosted at both www.spysheriff.com and www.spy-sheriff.com, which operated from 2005 until their shutdown in 2008. Going to these websites now will result in a message saying that this domain is for sale. Several other similarly-named websites also hosted the program, but have all been shut down. Several typosquatted websites also attempted to automatically install SpySheriff, including a fake version of Google.com called Goggle.com. From 2015 Goggle.com, which had changed ownership following a lawsuit by Google, hosted a survey scam and displayed links to Amazon items. In 2017, the domain hosted a blank page, with only the word "goggle" present in its HTML script. At the beginning of 2018, the site redirected to the scam site tango-deg.com, but from October 2018, it has existed as a simple HTML markup with a top-level heading reading "Goggle.com Inc.". In late 2019, the website became a WordPress blog, and it is now down in circa February-March 2020.
In the U.S the site is on again with the same Malware and Scam-Polls.

Features of a SpySheriff infection