Spybot Logo
Go Back   Safer-Networking Forums > Software > Spybot-S&D
Register ProjectsBlogs FAQ Search Today's Posts Mark Forums Read Home Support Download Donate

Reply
 
Thread Tools Display Modes
Old 2006-01-21, 13:03   #1
KJWilson
Junior Member
 
KJWilson's Avatar
 
Join Date: Jan 2006
Location: United States
Posts: 5
Question 007 Spy Software

This was reported on my last scan - HKEY_CLASSES_ROOT\Interface\{55C904F2-85EB-4982-BF62-C97108367B3A}. The information listed on that key is Name (Default); Type REG_SZ; Data clsSendMail. There are 3 subfolders: Forward, ProxyStubClsid and ProxyStubClsid32. The subfolders contain the same Name & Type information but have different Data. I can not determine what program installed the keys. Should I go ahead and remove the keys? I can not find anything in the forums that tell me what 007 Spy Software is or what type/how much of threat it is. By the way, I did find other helpful information on the forums, thank you for that.
KJWilson is offline   Reply With Quote
Old 2006-01-21, 15:28   #2
Sword
Junior Member
 
Join Date: Jan 2006
Posts: 15
Default

it is a keylogger :D
__________________
Vote for your best AntiSpyware software!

helping out Spybot-S&D! users, "giving back" to the community...
Sword is offline   Reply With Quote
Old 2006-01-21, 21:47   #3
KJWilson
Junior Member
 
KJWilson's Avatar
 
Join Date: Jan 2006
Location: United States
Posts: 5
Red face More Info Please

Thank you Sword. OK, it is a keylogger. Can you add any information? Does the Data clsSendMail mean my keystrokes are being mailed somewhere? Is there a way to find which application installed the keys so I can delete that program? I have noticed alerts that say "logitech is trying to monitor your keyboard strokes" and I think there was one when I was working in FrontPage that was similar. Do you think one of those programs may be the culprit? Thanks for any help.
KJWilson is offline   Reply With Quote
Old 2006-01-21, 22:53   #4
tashi
Member of Team Spybot
 
tashi's Avatar
 
Join Date: Oct 2005
Location: USA
Posts: 23,455
Rated LASSHes: 16
Default

Hello KJWilson.
  • Open SpyBot, check for and get any updates available,
  • Close all browsers, check for problems and fix everything found in red
  • Then on the toolbar menu select mode and switch to advanced mode, on the left lower down select tools, and view report, ensure all the options are selected near the bottom except
  • Uncheck[ ] do not report disabled or known legitimate Items.
  • uncheck[ ] Include a list of services in report.
  • Uncheck[ ] Include uninstall list in report.
  • Now select (near the top) view report.
  • Press export in the save in box choose a place such as your my documents folder, then in your next post near the bottom select the "browse" button; navigate to and attach or post that report please.
__________________
UNITE-ASAP

Microsoft MVP. Consumer Security 2006-2010

Please help us improve Spybot, download our distributed testing client
tashi is online now   Reply With Quote
Old 2006-01-22, 00:12   #5
KJWilson
Junior Member
 
KJWilson's Avatar
 
Join Date: Jan 2006
Location: United States
Posts: 5
Default Report Log Info

tashi, after viewing my logs, can you remove them? I don't know that it is "safe" to have all my system stuff exposed??
KJWilson is offline   Reply With Quote
Old 2006-01-22, 00:43   #6
tashi
Member of Team Spybot
 
tashi's Avatar
 
Join Date: Oct 2005
Location: USA
Posts: 23,455
Rated LASSHes: 16
Default

Hi there.
I removed your log as per your request.

However if it is of any reassurance, logs of many types are posted at all help support sites.
For instance see our malware removal forum:
Malware Forum
It is the only way we can check the system for problems.
__________________
UNITE-ASAP

Microsoft MVP. Consumer Security 2006-2010

Please help us improve Spybot, download our distributed testing client
tashi is online now   Reply With Quote
Old 2006-01-22, 01:39   #7
KJWilson
Junior Member
 
KJWilson's Avatar
 
Join Date: Jan 2006
Location: United States
Posts: 5
Default Thank you tashi

Thank you for removing the log. I guess I should have written if it isn't safe to then remove? If it will help anyone else, you may repost the log. Can you tell from the log which program set the keylogger or how it got into the registry? Tashi, I would like to tell you again I appreciate your help.
KJWilson is offline   Reply With Quote
Old 2006-01-22, 03:52   #8
tashi
Member of Team Spybot
 
tashi's Avatar
 
Join Date: Oct 2005
Location: USA
Posts: 23,455
Rated LASSHes: 16
Default

Hi.

I have asked a helper to take a look at the log and respond to you here with his findings.

Cheers.
__________________
UNITE-ASAP

Microsoft MVP. Consumer Security 2006-2010

Please help us improve Spybot, download our distributed testing client
tashi is online now   Reply With Quote
Old 2006-01-22, 06:47   #9
LonnyRJones
Visiting Staff
 
Join Date: Oct 2005
Posts: 5,089
Default

Hi

I see you let SSD fix it, Good.
007 Spy Software: Interface (Registry key, fixed)
HKEY_CLASSES_ROOT\Interface\{55C904F2-85EB-4982-BF62-C97108367B3A}

Delete this run with your startup manager program or SpyBots tools > system startup
command: wjview /cp "C:\Program Files\MyPointsPointAlert\System\Code" Main lp: "C:\Program Files\MyPointsPointAlert"
file: C:\WINDOWS\system32\wjview.exe
Manualy delete the MyPointsPointAlert folder, do not delete wjview
LonnyRJones is offline   Reply With Quote
Old 2006-01-24, 02:46   #10
KJWilson
Junior Member
 
KJWilson's Avatar
 
Join Date: Jan 2006
Location: United States
Posts: 5
Smile Lonnie, Thank you

I followed your instructions. Hope my system is more secure now. Thank you for your assistance.
KJWilson is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 16:59.


Copyright © 2000-2010 Safer-Networking Limited. All rights reserved.