| | |
Surf Accuracy gone at last!!
![]() |
Howdie from the land down under! I have been sent crazy-er by the ever persistent Surf Accuracy and had tried everything under the sun. It did not exist in add/remove programs, AdAware did nothing, two different high end anti-virus programs failed and SpyBot would identify and "fix" it but rescan and presto there it was... :evil: And nothing unusual appeared in HJT!!
I did a bit of research and then ran SpyBot again, this time clicking the box to identify what it was fixing. What I found was that something had written in a registry file that loaded the thing from the web location. So here was my fixit that did the trick for me. I welcome comments and please, check the pathing on your Spybot to make sure its the same.
Go to "Run"...type in "Regedit" and open. Here is the path to this little nasty that I found...
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Internet Settings\ZoneMap\Domains\contentmatch.net\ny\https!=W=4
Carefully follow the path in the reg edit to the folder for contentmatch.net and delete that folder.
Close out regedit. I then followed up CCleaner and ran my Avast! virus program just before rebooting and then checked again with SpyBot. The little buggar is gone.....dead......history..... :cheesy: :cheesy: :cheesy:
Hope this works for you and that the big boys here have a look to make sure this won't be a bit much for some users.
Thanks for being here!!
I did a bit of research and then ran SpyBot again, this time clicking the box to identify what it was fixing. What I found was that something had written in a registry file that loaded the thing from the web location. So here was my fixit that did the trick for me. I welcome comments and please, check the pathing on your Spybot to make sure its the same.Go to "Run"...type in "Regedit" and open. Here is the path to this little nasty that I found...
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Internet Settings\ZoneMap\Domains\contentmatch.net\ny\https!=W=4
Carefully follow the path in the reg edit to the folder for contentmatch.net and delete that folder.
Close out regedit. I then followed up CCleaner and ran my Avast! virus program just before rebooting and then checked again with SpyBot. The little buggar is gone.....dead......history..... :cheesy: :cheesy: :cheesy:
Hope this works for you and that the big boys here have a look to make sure this won't be a bit much for some users.
Thanks for being here!!
•
•
•
•
Originally Posted by ClassAustralia
What I found was that something had written in a registry file that loaded the thing from the web location.
The Registry entry you posted doesn't actually tell Windows or IE to load any file(s) from the malicious website, but it does make it possible for IE to communicate with the website, which is obviously a Bad Thing. To be technical about it, the presence of the "contentmatch" site in the Domains key is a modification made by the infection; it is not an actively malicious component of the infection, nor does is point to/execute such a component.
https!=W=4
The (horribly boring) breakdown of that cryptic code from SpyBot is:
https is the secure http protocol.
W=4 means that the default registry DWORD value of the https protocol for the domain in question is 4.
4 identifies the Restricted Sites Zone in the Internet Options control panel's Security tab.
!= is coding/scripting notation for "not equal to".
Human translation: "Yo, Bro'- I found a malicious site which should be listed in your Restricted Sites Zone, but it ain't!"
For a mind-bogglingly boring exposition on the whole ZoneMap/Domains thing, have a read of this Microsoft article (note: make sure you have a pretty good-sized dose of psychotropic drugs at hand; you'll need them....)
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
![]() |
Similar Threads
- help me... virus' (Viruses, Spyware and other Nasties)
- Help Got haywire computer (Viruses, Spyware and other Nasties)
- Popup-MediaTicketsInstaller-cash8.exe-HiJackThis Log posted (Viruses, Spyware and other Nasties)
- Another Hacktool.Rootkit (Viruses, Spyware and other Nasties)
- Damn red circle (Viruses, Spyware and other Nasties)
- internet trouble (Viruses, Spyware and other Nasties)
- Cannot surf the Net.. (Web Browsers)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Cant Run RegEdit
- Next Thread: Hijackthis log RE: Potentially rootkit-masked files
Views: 3215 | Replies: 2
| Thread Tools | Search this Thread |
Tag cloud for Viruses, Spyware and other Nasties
access adobe alert analysis apple attack avg banks bar bing botnet botnets center child-protection chip-and-pin code combofix commercial connect control crypto ddos dialler disk domains dumbass email encryption europe exploit explorer fake firefox fraud google government gumblar hack hacking halloween hijack hosting hosts ibm ie8 internet iphone kneber links logfiles login malware mcafee mega-d mozilla nasties news norton panel pc phishing police pop porn pro problem redirect redirecting regedit report research rogueantivirus rootkit rsa safety samhain search security sites software spam spyware symantec system trojan unwanted update virus viruses vista volume vulnerability warning win windows windowsxp worm xp_antispyware_2010 yahoo zeus






