SpySheriff is a Windows rogue anti-spyware/fraudware family that masqueraded as legitimate security software and used fake scans and false security alerts to coerce users into paying for removal of non-existent threats. It was also distributed under aliases including BraveSentry 2.0, Pest Trap, SpyDawn, Alpha Cleaner, SpywareBot, and SpyBouncer. The content attributes it to Innovative Marketing Inc. (also referred to as Innovagest 2000). Behavior described in the source includes displaying fabricated detections such as misleading "Trojan VX ..." alerts, replacing the desktop background with a fake Blue Screen of Death-style warning, blocking web browsing so that spy-sheriff.com was the only accessible site, interfering with or preventing System Restore, reinstalling itself after removal attempts, hiding components in System Restore folders, terminating some antivirus and antispyware processes, and disabling Task Manager and Registry Editor. Attempts to uninstall it via Add or Remove Programs could fail or trigger an unexpected reboot; users sometimes bypassed its blocking of taskmgr.exe and regedit.exe by renaming those executables. SpySheriff was hosted on www.spysheriff.com and www.spy-sheriff.com from 2005 until shutdown in 2008, with similarly named sites also distributing it. Vendor detections cited in the content include Symantec Adware.SpySheriff, F-Secure Rogue:W32/SpySheriff and Rogue:W32/BraveSentry, Fortiguard Adware/SpySheriff, McAfee Adware-SpySheriff, and Trend Micro ADW_SPYSHERIFF, DOWNLOADER_SPYSHERIFF, FREELOADER_SPYSHERIFF, VBS_SENTRY, ADW_BRAVESEN, and ADW_PESTTRAP.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
2005 Brontok Emcodec Extended Copy Protection PGPCoder PoisonIvy Samy SpySheriff
A rogue anti-spyware program for Windows that displayed false security alerts and fake scan results to coerce users into purchasing it. It could reinstall itself, alter the desktop background, block internet access except to its own site, disable security tools, and interfere with Task Manager, Registry Editor, and System Restore.
Rogue security application/fake alert malware referenced as installed or associated software in the fake codec ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.