PC Review
Forums
Newsgroups
Microsoft AntiSpyware
Security Signatures
False positives (ZoneMap\Domains * 4)
Forums
Newsgroups
Microsoft AntiSpyware
Security Signatures
False positives (ZoneMap\Domains * 4)
![]() |
False positives (ZoneMap\Domains * 4) |
|
|
Thread Tools | Rate Thread |
|
|
#1 |
|
Guest
Posts: n/a
|
Microsoft AntiSpyware (MAS) detected "SearchSquire"
(HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchsquire.com and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchsquire.com * 4), i.e., SearchSquire with a REG_DWORD value named *, and a a hex value data entry of 4. What the MAS didn't realize is, that the * 4 =BLOCKS= the installation of the zonemap domain by automatically blocking access to the specified site from which its downloaded. In my case, the entries were added by Spybot S&D, and after I allowed MAS to remove the threat, Spyware later told me that there was one more known threat against which I need to inocculate. Doing so added the entry again. I currently ignore the "threat" after each scan, but am reluctant to "Always Ignore", in case I =do= get infected. I'm not sure if MAS would be smart enough to ignore the * 4 DWORD, but not ignore a genuine infection or other values, i.e., how specific is the "Ignore" setting: the specific value or the entire branch? |
|
![]() |
|
| Thread Tools | |
| Rate This Thread | |
|
|

Main Page 

