PC Review Forums Newsgroups Microsoft AntiSpyware Security Signatures False positives (ZoneMap\Domains * 4)

Reply

False positives (ZoneMap\Domains * 4)

 
Thread Tools Rate Thread
Old 09-01-2005, 08:20 PM   #1
Klausen
Guest
 
Posts: n/a
Default False positives (ZoneMap\Domains * 4)


Microsoft AntiSpyware (MAS) detected "SearchSquire"
(HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\Domains\searchsquire.com and
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\Domains\searchsquire.com * 4), i.e., SearchSquire with
a REG_DWORD value named *, and a a hex value data entry of 4.

What the MAS didn't realize is, that the * 4 =BLOCKS= the installation
of the zonemap domain by automatically blocking access to the specified
site from which its downloaded.

In my case, the entries were added by Spybot S&D, and after I allowed
MAS to remove the threat, Spyware later told me that there was one more
known threat against which I need to inocculate. Doing so added the
entry again.

I currently ignore the "threat" after each scan, but am reluctant to
"Always Ignore", in case I =do= get infected. I'm not sure if MAS would
be smart enough to ignore the * 4 DWORD, but not ignore a genuine
infection or other values, i.e., how specific is the "Ignore" setting:
the specific value or the entire branch?
  Reply With Quote
Reply



Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off