|
|
|||||||
| Register | Projects | Blogs | FAQ | Search | Today's Posts | Mark Forums Read |
|
|
#1 |
|
Junior Member
Join Date: Jan 2006
Location: United States
Posts: 5
|
This was reported on my last scan - HKEY_CLASSES_ROOT\Interface\{55C904F2-85EB-4982-BF62-C97108367B3A}. The information listed on that key is Name (Default); Type REG_SZ; Data clsSendMail. There are 3 subfolders: Forward, ProxyStubClsid and ProxyStubClsid32. The subfolders contain the same Name & Type information but have different Data. I can not determine what program installed the keys. Should I go ahead and remove the keys? I can not find anything in the forums that tell me what 007 Spy Software is or what type/how much of threat it is. By the way, I did find other helpful information on the forums, thank you for that.
|
|
|
|
|
|
#2 |
|
Junior Member
Join Date: Jan 2006
Posts: 15
|
it is a keylogger :D
__________________
Vote for your best AntiSpyware software! helping out Spybot-S&D! users, "giving back" to the community... |
|
|
|
|
|
#3 |
|
Junior Member
Join Date: Jan 2006
Location: United States
Posts: 5
|
Thank you Sword. OK, it is a keylogger. Can you add any information? Does the Data clsSendMail mean my keystrokes are being mailed somewhere? Is there a way to find which application installed the keys so I can delete that program? I have noticed alerts that say "logitech is trying to monitor your keyboard strokes" and I think there was one when I was working in FrontPage that was similar. Do you think one of those programs may be the culprit? Thanks for any help.
|
|
|
|
|
|
#4 |
|
Member of Team Spybot
Join Date: Oct 2005
Location: USA
Posts: 23,455
Rated LASSHes: 16
|
Hello KJWilson.
__________________
UNITE-ASAP Microsoft MVP. Consumer Security 2006-2010 Please help us improve Spybot, download our distributed testing client |
|
|
|
|
|
#5 |
|
Junior Member
Join Date: Jan 2006
Location: United States
Posts: 5
|
tashi, after viewing my logs, can you remove them? I don't know that it is "safe" to have all my system stuff exposed??
|
|
|
|
|
|
#6 |
|
Member of Team Spybot
Join Date: Oct 2005
Location: USA
Posts: 23,455
Rated LASSHes: 16
|
Hi there.
I removed your log as per your request. However if it is of any reassurance, logs of many types are posted at all help support sites. For instance see our malware removal forum: Malware Forum It is the only way we can check the system for problems.
__________________
UNITE-ASAP Microsoft MVP. Consumer Security 2006-2010 Please help us improve Spybot, download our distributed testing client |
|
|
|
|
|
#7 |
|
Junior Member
Join Date: Jan 2006
Location: United States
Posts: 5
|
Thank you for removing the log. I guess I should have written if it isn't safe to then remove? If it will help anyone else, you may repost the log. Can you tell from the log which program set the keylogger or how it got into the registry? Tashi, I would like to tell you again I appreciate your help.
|
|
|
|
|
|
#8 |
|
Member of Team Spybot
Join Date: Oct 2005
Location: USA
Posts: 23,455
Rated LASSHes: 16
|
Hi.
I have asked a helper to take a look at the log and respond to you here with his findings. Cheers.
__________________
UNITE-ASAP Microsoft MVP. Consumer Security 2006-2010 Please help us improve Spybot, download our distributed testing client |
|
|
|
|
|
#9 |
|
Visiting Staff
Join Date: Oct 2005
Posts: 5,089
|
Hi
I see you let SSD fix it, Good. 007 Spy Software: Interface (Registry key, fixed) HKEY_CLASSES_ROOT\Interface\{55C904F2-85EB-4982-BF62-C97108367B3A} Delete this run with your startup manager program or SpyBots tools > system startup command: wjview /cp "C:\Program Files\MyPointsPointAlert\System\Code" Main lp: "C:\Program Files\MyPointsPointAlert" file: C:\WINDOWS\system32\wjview.exe Manualy delete the MyPointsPointAlert folder, do not delete wjview |
|
|
|
|
|
#10 |
|
Junior Member
Join Date: Jan 2006
Location: United States
Posts: 5
|
I followed your instructions. Hope my system is more secure now. Thank you for your assistance.
|
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|