False positive due to Spybot S&D immunization

G

gwmatt

I use Spybot Search & Destroy 1.3, in addition to Microsoft
AntiSpyware Beta 1. One of the options in SS&D is to
"Immunize" against certain known spyware sites and threats.
When you do this, it puts a list of known "bad" sites and
products in various places - including the Restricted Sites
Zone. This provides some passive protection against sites
and products that are known to be spyware threats.
JavaCool's Spyware Blaster (which I also use) uses a
similar technique.

Microsoft AntiSpyware Beta 1 finds one of these
immunization entries in the registry and misidentifies it
as spyware. Specifically, it finds the following registry key:

\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\Domains\searchsquire.com

When I let MS AntiSpyware remove this, then run Spybot's
"Immunize" function, it reports that one known bad product
has not been immunized against. When I re-immunize it,
MS-AS again finds the same registry key. I think MS-AS is
failing to recognize that this entry is in the Restricted
Sites Zone, and misidentifying it as a spyware trace.
 
D

DReCo

I've had the same thing happen to me. It seems
SearchSquire musta paid some under the table $$$ to get
itself cleansed from the restricted zone! :)

CounterSpy does the same thing but it too is using Giant
engine technology.

I've also had other AS programs try and remove sites that
have been "blacklisted" in my restricted sites zone.

Go figure.....
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top