Spyware Dr.False readings?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TommySack, Oct 31, 2004.

  1. TommySack

    TommySack Private E-2

    :confused: First I would just like to say that I appreciate all the free advice that you offer,I have visited this site many times as a guest and found it very helpful.Now for my problem.I downloaded,and purchased,spyware doctor.It continually shows the same results which no other scan detects.I have used spybot,ad-aware and many free scans on the internet.Not one of these scans has revealed any of these results.Are they false readings?Is spyware dr.installing them?I have deleted them all from my registry many times both in safe mode and while on-line.They continue to come back and when I click on remove them in spyware dr.it does not eliminate them.Any advice is greatly appreciated.Thanks!
    Here are the log results from spyware dr.that don't show up in any other scans:
    007 Keylogger (HKCR\clsid\{48E59293-9880-11CF-9754-00AA00C00908}) Registry *
    007 Keylogger (HKCR\TypeLib\{48E59290-9880-11CF-9754-00AA00C00908}) Registry *
    Super-gals.com (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\xxxtoolbar.com) Registry *
    Virtual Bouncer (HKCR\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}) Registry *
    Virtual Bouncer (HKCR\CLSID\{48E59294-9880-11CF-9754-00AA00C00908}) Registry *
    Virtual Bouncer (HKCR\CLSID\{48E59295-9880-11CF-9754-00AA00C00908}) Registry *
    Virtual Bouncer (HKCR\InetCtls.Inet) Registry *
    Virtual Bouncer (HKCR\InetCtls.Inet.1) Registry *
    Virtual Bouncer (HKCR\Interface\{48E59292-9880-11CF-9754-00AA00C00908}) Registry *
    Virtual Bouncer (HKCR\TypeLib\{48E59290-9880-11CF-9754-00AA00C00908}) Registry *
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\i-lookup.com) Registry *
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\offshoreclicks.com) Registry *
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\teensguru.com) Registry *
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\xxxtoolbar.com) Registry *
     
  2. TommySack

    TommySack Private E-2

    No Help?

    I know I'm a newbie here but I was really hoping someone would know about my previous spyware doctor post.I have read and done all the things in your "read me 1st" section but they did not help.Should I do a hjt scan and posting now?Please,any advice would really be appreciated!!!
     
  3. Kodo

    Kodo SNATCHSQUATCH

  4. goldfish

    goldfish Lt. Sushi.DC

    Re: No Help?

    Paitience. Look at your original thread.
     
  5. goldfish

    goldfish Lt. Sushi.DC

    He "said" that he followed them in his other thread, which is why you didn't know that.

    I'd check if those registry values actually exist. They are valid, despire abbriviations.

    HKCR = HKEY_CLASSES_ROOT
    HKCU = HKEY_CURRENT_USER

    Make sure you've got the latest version of spyware doctor.
     
  6. TommySack

    TommySack Private E-2

    Sorry if I seemed impatient,it is not you guys,it's just these conflicting scan results making me nuts!Hope you understand.I checked for latest spyware dr.version and I already had it.The readings are valid?Does that mean they are spyware?(Again,sorry but I'm pretty much a newbie).Why didn't any other scans,I used all the downloads in your read me first post,pick up any of the same results and why do they keep returning when I delete them from the registry.Should I do the Hijack-this now and post the results here?Thanks,and I promise to be more patient this time!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to stay in one thread. Posting new messages in new threads will get you no where. I am merging all of your threads (3 of them) together. Please look for your previous thread each time you come back and post in it.
     
  8. TommySack

    TommySack Private E-2

    Those are entries in the registry but even when I delete them they just come back.I don't know what else to do.This is also affecting other spyware programs,spyware blaster keeps losing protection for 4 websites.I don't want to run hijack this until you say to and I really don't want to screw up my registry anymore than it already is.PLEASE HELP!!!!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Part of the detections from Spyware Doctor are not valid. Entries like below usin ZoneMap\Domains are place into your registry via programs like SpyBot and SpywareBlaster to protect you from malware sites. Spyware Doctor needs to do a better job of detecting these valid entries (there are a 1000 or more of them)

    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\i-lookup.com) Registry *
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\offshoreclicks.com) Registry *
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\teensguru.com) Registry *
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\xxxtoolbar.com) Registry *
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As for the other items, let's look at a HijackThis log.

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or from a sub-folder of C:\Documents and Settings, or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2
     
  11. TommySack

    TommySack Private E-2

    thanks for the spware dr.info.that is a relief.here is the hijack this log that you asked for.i hope i did it right,i think i followed your directions.thanks again!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You only have a few minor things to fix.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/1755c5764b3e5a5a5a05/netzip/RdxIE601.cab
    O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/cablevision/excavation/install.cab
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab

    Now reboot and post a new HJT log. And tell us how things are working.
     
  13. TommySack

    TommySack Private E-2

    ok,here's the new hjt log.I really hope that it's clear of spyware!What about the 007 keylogger,was that also a false reading by spyware dr.?I am very grateful for the help you guys give and like most of the best stuff on the internet,it's free!keep it up,we do appreciate it!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Your log is clean now!

    Try uninstalling iISystem Wiper first (at least temporarily). I have seen several reports of issues like yours where Spyware Doctor report issues and when tracking eraser software was removed, the problems were gone. Here is an example: http://www.wilderssecurity.com/showthread.php?t=52392
     
  15. TommySack

    TommySack Private E-2

    WOOOO-HOOOO!thanks..big relief.but I can't help but wonder how many other poor non-geeks got fooled by this and wound up doing drastic measures!i was all set to format my drive and re-install everything for no real reason.So,what should i use instead of iIsystem wiper-cc?thanks!!!!!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First a question, did you uninstall it and did that fix the problem?
     
  17. TommySack

    TommySack Private E-2

    Yes,I uninstalled iISystem Wiper but the 007 still shows up in the spyware dr. report.There are also 2 items that spybot cannot remove:Sti_Trace.log and SchedLgu.txt.Any advice?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  19. lschmidt

    lschmidt Private E-2

    When I ran AdAware,SpybotS&D and GIANT Anti-Spyware they found nothing.
    But when I ran Spyware Dr,it found 18 items. I think there needs to be single database that all anti-spyware programs work from.

    Altnet Software (HKLM\SOFTWARE\Microsoft\DownloadManager) Registry
    IEPlugin (HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl) Registry
    IEPlugin (HKLM\SOFTWARE\Microsoft\Internet Explorer\Main##Search Bar) Registry
    Slotchbar (HKLM\SOFTWARE\Microsoft\DownloadManager) Registry
    Virtual Bouncer (HKCR\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}) Registry
    Virtual Bouncer (HKCR\CLSID\{48E59294-9880-11CF-9754-00AA00C00908}) Registry
    Virtual Bouncer (HKCR\CLSID\{48E59295-9880-11CF-9754-00AA00C00908}) Registry
    Virtual Bouncer (HKCR\InetCtls.Inet) Registry
    Virtual Bouncer (HKCR\InetCtls.Inet.1) Registry
    Virtual Bouncer (HKCR\Interface\{48E59291-9880-11CF-9754-00AA00C00908}) Registry
    Virtual Bouncer (HKCR\Interface\{48E59292-9880-11CF-9754-00AA00C00908}) Registry
    Virtual Bouncer (HKCR\TypeLib\{48E59290-9880-11CF-9754-00AA00C00908}) Registry
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\i-lookup.com) Registry
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\offshoreclicks.com) Registry
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\teensguru.com) Registry
    Zango Search Assistant (HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\xxxtoolbar.com) Registry
    RealPlayer Search Bar (C:\Program Files\Common Files\Real\Update_OB\realsched.exe) file
    RealPlayer Search Bar (C:\Program Files\Common Files\Real\Toolbar\RealBar.dll) file
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ischmidt,
    That would be nice. But then most of those companies would not need to exist. If they all were smart enough to scan for the same things and find them and delete them, all the tools would be the same.

    I have the same comments on your log, Spyware Doctor is falsely detecting valid items in ZoneMap\Domains.
     
  21. TommySack

    TommySack Private E-2

    Yes,all the same findings came back in spyware dr:Virtual bouncer,007,super-gals,zango,etc.It has to be spyware dr.cause like the previous post no other spyware scans detected any of the same ones.I'm just putting them in the ignore list.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run regedit and navigate to:
    HKCR\CLSID\{48E59293-9880-11CF-9754-00AA00C00908

    and with that key selected click File, Export. Give it a filename (like spydrbug) and remember where you saved it. Now use windows explorer to locate the saved file. It will be call spydrbug.reg. Change the .reg to .txt by right clicking on the file and selecting rename. Now upload it here as an attachment.
     
  23. TommySack

    TommySack Private E-2

    OK,heres the file that you asked for.Any special reason this one needs further attention?I thought we had cleared out all the spyware.Thanks again!
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I wanted to be sure by looking at the registry values myself. I believe these are all okay and that Spyware Doctor is showing false positives.
     
  25. TommySack

    TommySack Private E-2

    Ok,Had me worried for a minute.Hopefully I won't have to be posting any time soon w/more problems!You guys are terrific and I have already told others to check out this site.Keep up the good work!
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  27. pctools

    pctools Private E-2

    Hi.

    This false positive has been addressed by Spyware Doctor since early mid November. Please make sure you have applied the latest updates to fix this.

    Thank you
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds