RedSherrif spyware

Author
Discussion

simpo two

Original Poster:

85,831 posts

267 months

Tuesday 6th January 2004
quotequote all
After a patch of slow-running I ran Adaware and hoofed out a RedSherrif...

http://kalsey.com/2002/11/java_spyware/

Anyone else met this chap?

Godfrey H

145 posts

251 months

Wednesday 7th January 2004
quotequote all
Are you using the free version of Adaware? There has been a lot of discussion about Red Sheriff lately. I'm trying deliberately to pick it up to analyse what measures to take to block it. I can't find it at the moment. Either my detection software is not finding it, or something on my system is blocking it, or I'm not visiting sites that use it.

Plotloss

67,280 posts

272 months

Wednesday 7th January 2004
quotequote all
Gits!

Just done a search on measure.class and sure enough its there...

simpo two

Original Poster:

85,831 posts

267 months

Wednesday 7th January 2004
quotequote all
[quote=Godfrey H]Are you using the free version of Adaware? There has been a lot of discussion about Red Sheriff lately. I'm trying deliberately to pick it up to analyse what measures to take to block it.[quote]

I searched Google and seem to recall they have their own website - a company makes it and sells it quite openly.

Yes, I used the free version of Adaware.

.Mark

11,104 posts

278 months

Wednesday 7th January 2004
quotequote all
Plotloss said:
Gits!

Just done a search on measure.class and sure enough its there...


Me too. 2 entries in the registry, can I just delete it?

polar_ben

1,413 posts

261 months

Wednesday 7th January 2004
quotequote all
Plotloss said:
Gits!

Just done a search on measure.class and sure enough its there...
Frs! Me too. Adaware didn't notice it. Sorted it with the read-only trick

polar_ben

1,413 posts

261 months

Wednesday 7th January 2004
quotequote all
Mark - the registry entries may be where you've searched for it (ie just a list of search terms).

Do a search for measure.class, open it in notepad, delete everything in it and save it. Then right click, properties & tick the read only box.

Disclaimer: it might sound like I know what I'm talking about, but I reserve the right to be ridiculed/corrected by the resident PH techies. FWIW, my PC still works fine after the above treatment

Plotloss

67,280 posts

272 months

Wednesday 7th January 2004
quotequote all
Was yours under profile in the .java-cache file?

polar_ben

1,413 posts

261 months

Wednesday 7th January 2004
quotequote all
jpi_cache

simpo two

Original Poster:

85,831 posts

267 months

Wednesday 7th January 2004
quotequote all
Worth mentioning that I got the latest free version of Adaware - luckily about a day after it was updated aroung mid-Dec. So if you downloaded it before then, try it again!

Godfrey H

145 posts

251 months

Wednesday 7th January 2004
quotequote all
Whoa! Found entries for Red Sheriff in the registry.
Hmmmn how to stop it.

.Mark

11,104 posts

278 months

Wednesday 7th January 2004
quotequote all
polar_ben said:
Mark - the registry entries may be where you've searched for it (ie just a list of search terms).

Do a search for measure.class, open it in notepad, delete everything in it and save it. Then right click, properties & tick the read only box.

Disclaimer: it might sound like I know what I'm talking about, but I reserve the right to be ridiculed/corrected by the resident PH techies. FWIW, my PC still works fine after the above treatment


Measure.class does not feature anywhere on my C: doing a search through the start menu. It only appears in the registry under something to do with explorer.
Does that mean I am 'clean'?

polar_ben

1,413 posts

261 months

Wednesday 7th January 2004
quotequote all
I think so.

I found a list of the things I'd searched for through the start menu in my registry, "redsherrif" being one of them.

simpo two

Original Poster:

85,831 posts

267 months

Wednesday 7th January 2004
quotequote all
I thought it was spelled 'RedSherrif', hence that name on the post. However I think it's actually RedSheriff - so best search for both versions.
NB My registry was clear, so hopefully OK.