PDA

View Full Version : Spybot closing



DrkWing
2007-01-07, 04:29
OK, I looked through several posts and didnt see this so here it goes.

I have windows xp and the latest version of SB. So I run the scan and that goes well, no freezing. So, now I click Fix selected and poof...gone. Spybot closes itself...no errors, no nothing. I tried only selecting a few of the problems and fixing them slowly, worked a little then gone again. I am getting nothing as far as errors popping up, just gone.

Anyone else?? Thoughts on this?

Zenobia
2007-01-07, 12:20
Could you show what problems Spybot is finding before it closes?
Run another scan.When the scan completes, right click on the results list, select "Copy results to clipboard".Then paste those results here.

DrkWing
2007-01-08, 07:28
QuickPage.SwitchDialer: Global settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{5CBF8C22-E9A6-11D7-90FE-000AE4012DB4}

QuickPage.SwitchDialer: Global settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\ClsidFeature\{5CBF8C22-E9A6-11D7-90FE-000AE4012DB4}

eXact Advertising.BargainsBuddy: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZESOFT

eXact Advertising.BargainsBuddy: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ZESOFT

EZ-Searching: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{07E890E3-EF0C-4EA6-9F79-C5749ACA9CC1}

EZ-Searching: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{96515724-397E-48C7-8974-86C203E666E1}

FunWebProducts: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}

ISearchTech.PowerScan: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\PowerScan

Roings: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{47E42EA5-AF8C-4D78-9937-AA40354B3018}

Roings: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E4BCF50-865B-4EF4-A0BC-BF57229EA525}

Roings: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{64A5BD22-8D8A-4193-9CF8-7DB5212ABB17}

Roings: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{78A163D2-2358-464D-807B-0E2A078C7727}

Roings: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{E832FFDE-8ED2-47B7-BE50-729A238040A0}

Roings: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\IObjSafety.DemoCtl

Roings: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{9F61CFDF-5C79-4D35-B4DA-766B28367223}

FunWebProducts: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}

KeenValue.eUniverse.MyFreeCursors: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\updater

MTC.Saristar: Settings (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{90A52F00-64AC-4DC6-9D7D-4516670275D0}

MTC.Saristar: Settings (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\Saristar.DLL

MTC.Saristar: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Saristar.Saristar

MTC.Saristar: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Saristar.Saristar.1

MTC.Saristar: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Saristar

MyWay.MyWebSearch: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}

MyWay.MyWebSearch: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ScreenSaverControl.ScreenSaverInstaller

MyWay.MyWebSearch: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ScreenSaverControl.ScreenSaverInstaller.1

MyWay.MyWebSearch: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}

MyWay.MyWebSearch: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}

MyWay.MyWebSearch: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}

MyWay.MyWebSearch: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{ADB01E80-3C79-4272-A0F1-7B2BE7A782DC}

MyWay.MyWebSearch: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}

MyWay.MyWebSearch: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}

MyWay.MyWebSearch: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\FocusInteractive

WildTangent: Program directory (Directory, nothing done)
C:\WINDOWS\wt\

Zango: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\msbb

Zango: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2000478354-2111687655-839522115-1004\Software\msbb

Microsoft.WindowsSecurityCenter.AntiVirusDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0

Microsoft.WindowsSecurityCenter.AntiVirusOverride: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride!=dword:0

Microsoft.WindowsSecurityCenter.FirewallDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0

Microsoft.WindowsSecurityCenter_disabled: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start!=W=2

eXact Advertising.BargainsBuddy: System Service (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZESOFT

FunWeb: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}

FunWeb: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}

Huntbar: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2000478354-2111687655-839522115-1004\Software\WinTools

TwainTech: Data (File, nothing done)
C:\WINDOWS\INF\twaintec.inf

TwainTech: Data (File, nothing done)
C:\WINDOWS\system32\stlbdist.XML

VX2.f.MSView: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2000478354-2111687655-839522115-1004\Software\MxTarget

PurityScan: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{20F13844-04BC-4987-9964-2502F0DA54D3}

PurityScan: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E43040C-73C1-4898-A4F8-E2C9428B1167}

PurityScan: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{EE6F3F6A-AD8E-48DA-9B1D-D5204B2D227D}

Targetsaver: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2000478354-2111687655-839522115-1004\Software\TSA

Targetsaver: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\TSA

IE Plugin: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2000478354-2111687655-839522115-1004\Software\intexp

MyWebSearch: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}

MyWebSearch: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}

MyWebSearch: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}

MyWebSearch: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}

MyWebSearch: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}

MyWebSearch: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}

MyWebSearch: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}

MyWebSearch: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}

MyWebSearch: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}

Windows AdTools: Data (File, nothing done)
C:\WINDOWS\system32\ide21201.vxd

Zlob.strCodec: Settings (Registry value, nothing done)
HKEY_USERS\S-1-5-21-2000478354-2111687655-839522115-1004\Software\Internet Security\Path=...C:\Program Files\strCodec...

WebTrends live: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


AdRevolver: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Avenue A, Inc.: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Zedo: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Statcounter: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


MediaPlex: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


AdRevolver: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Marketengines: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


DoubleClick: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


SexTracker: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


MediaPlex: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


FastClick: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


WebTrends live: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


SexTracker: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


MediaPlex: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


SexTracker: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


TagASaurus: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Win32.Small.ddx: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitsLink: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Win32.Small.ddx: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Win32.Small.ddx: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


MediaMotor: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


VX2.Favoriteman: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


WebTrends live: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


WebTrends live: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


WebTrends live: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


WebTrends live: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


ValueClick: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


WebTrends live: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Winsoftware.WinAntiVirusPro2006: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


LinkSynergy: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Win32.Small.ddx: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


WebTrends live: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


TargetNet: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


Tradedoubler: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


MP3 Networks Ltd: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


MediaMotor: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


HitBox: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


FastClick: Tracking cookie (Internet Explorer: George) (Cookie, nothing done)


FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)


MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done)


Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)


Statcounter: Tracking cookie (Firefox: default) (Cookie, nothing done)


Tradedoubler: Tracking cookie (Firefox: default) (Cookie, nothing done)


Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)


Zedo: Tracking cookie (Firefox: default) (Cookie, nothing done)


Zanox: Tracking cookie (Firefox: default) (Cookie, nothing done)


FastClick: Tracking cookie (Mozilla: default) (Cookie, nothing done)


MediaPlex: Tracking cookie (Mozilla: default) (Cookie, nothing done)


MediaPlex: Tracking cookie (Mozilla: default) (Cookie, nothing done)


Statcounter: Tracking cookie (Mozilla: default) (Cookie, nothing done)


VX2.Favoriteman: Bookmark (Internet Explorer: George) (Bookmark, nothing done)


VX2.Favoriteman: Bookmark (Firefox: default) (Bookmark, nothing done)



--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2007-01-06 unins000.exe (51.41.0.0)
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-02-06 advcheck.dll (1.0.2.0)
2006-02-20 Tools.dll (2.0.0.2)
2004-11-29 Includes\LSP.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2006-11-24 Includes\Hijackers.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2006-12-22 Includes\Malware.sbi (*)
2006-10-20 Includes\PUPS.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2006-10-13 Includes\Spybots.sbi (*)
2006-12-08 Includes\Trojans.sbi (*)
2007-01-05 Includes\Cookies.sbi (*)
2007-01-05 Includes\Revision.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-01-05 Includes\TrojansC.sbi (*)
2007-01-05 Includes\SpybotsC.sbi (*)
2007-01-05 Includes\SecurityC.sbi (*)
2007-01-05 Includes\PUPSC.sbi (*)
2007-01-05 Includes\MalwareC.sbi (*)
2007-01-05 Includes\KeyloggersC.sbi (*)
2007-01-05 Includes\HijackersC.sbi (*)
2007-01-05 Includes\DialerC.sbi (*)

Zenobia
2007-01-08, 09:02
You could ask for help in Malware Removal.

The steps to follow are here:
http://forums.spybot.info/showthread.php?t=288
(You could try the part about scanning with Spybot in safe mode,but if Spybot still disappears when trying to fix problems,you could just move on to the next step.)

Malware Removal:
http://forums.spybot.info/forumdisplay.php?f=22

DrkWing
2007-01-31, 03:10
OK its been a while since I went on with this but I narrowed it down to what is killing the window. I am showing a shot of the window with the problem file.
http://70.84.137.194/~fantasyf/misc/spybot.jpg

I hope this helps not only me but you guys to figure out why this one file causes this.

Zenobia
2007-01-31, 09:41
If that is causing Spybot to shutdown,I'd suggest posting in the malware removal forum,and perhaps a helper will help you delete that with a regfile or something.You could link back to here if you like,so the helper will know what the problem is.
Instructions above.