Questions about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet

Reply

Join Date: Jul 2004
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Solved Threads: 209
Team Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Questions about HKEY_CURRENT_USER \Software\Microsoft\...\ZoneMap\Domains\

 
0
  #1
Sep 15th, 2004
I spent part of yesterday defragging and running all my AV and spyware programs. Everything was clean until I ran PestPatrol, which found a pest named CWS.GoogleMS.3 located in: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\xxxtoolbar.com. I Googled the xxxtoolbar to try to get some info on it, but all I could find were removal instructions, which I went through, but I didn't have any of the associated files. I set a reatore point and went ahead and deleted it. Here are my questions:

When I went into that Domains Registry, I was shocked by the long list of what appeared to be porn-related entries. I'd like to know
1.) Where could these have come from?
2.) Is there anything in that folder that should not be deleted?
3.) Is the folder itself necessary?

I tried to Google that Registry folder too, to find out it's purpose, but no luck with that either.
Reply With Quote Quick reply to this message  
Join Date: Jul 2004
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Solved Threads: 209
Team Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Questions about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet

 
0
  #2
Sep 15th, 2004
I was just looking through the list more carefully and it's not all porn-related, there's a lot of typical spyware and adware stuff too. I don't see anything in the list that looks like it would be necessary.
Reply With Quote Quick reply to this message  
Join Date: Mar 2004
Posts: 3,826
Reputation: Catweazle is a jewel in the rough Catweazle is a jewel in the rough Catweazle is a jewel in the rough Catweazle is a jewel in the rough 
Solved Threads: 144
Team Colleague
Catweazle Catweazle is offline Offline
Grandad

Re: Questions about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet

 
0
  #3
Sep 15th, 2004
Moved to Security section
Reply With Quote Quick reply to this message  
Join Date: Jul 2004
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Solved Threads: 209
Team Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Questions about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet

 
0
  #4
Sep 16th, 2004
Is it possible this is where the stuff Spyware Blaster installed is kept?
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,985
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 754
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is online now Online
Spyware Killer

Re: Questions about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet

 
0
  #5
Sep 17th, 2004
Do you have ie-spyad installed? It enters over 4000 sites to your registry so that IE cannot go there.
Reply With Quote Quick reply to this message  
Join Date: Jul 2004
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Solved Threads: 209
Team Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Questions about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet

 
0
  #6
Sep 17th, 2004
I don't have ie-spyad (though it appears a good thing to have), and there is not 4,000 entries there, I'd guess 100-200.

Is "...\Internet Settings\ZoneMap\Domains" the place where this type of information would be stored? Or should I delete all the entries there?
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,985
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 754
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is online now Online
Spyware Killer

Re: Questions about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet

 
0
  #7
Sep 18th, 2004
Check out this link. http://www.jsiinc.com/subk/tip5100/rh5130.htm
It appears to be whatever is in your restricted zone so that IE cannot go there.
Reply With Quote Quick reply to this message  
Join Date: Jul 2004
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Solved Threads: 209
Team Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: Questions about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet

 
0
  #8
Sep 18th, 2004
Thanks crunchie! That site is a bit complicated (for me), but you were able to find what I wasn't. After looking at the list, I suspected it was from SpyWareBlaster, and this confirms it. I updated SpyWareBlaster, had it enable all protection and, low and behold, xxx.toolbar.com (the one I originally deleted) is back! From now on, I know that if any of my anti-pest-ware programs find anything in here, I should just ignore it.

You can mark this one as solved! Thanks again!
(I would add to your rep again, but I have to 'spread it around' first. If anyone else reads this, give crunchie some cudos for me!)
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC