Sign in with
Sign up | Sign in
Your question

XP Registry & Spyware

Last response: in Windows XP
Share
May 20, 2005 3:22:57 PM

Archived from groups: microsoft.public.windowsxp.help_and_support (More info?)

Hi All,

I have just finished clearing a machine that was absolutely clogged with
spyware. I thought I would run a scan of the registry to check for one
particularly nasty one - crazywinnings.com - that would keep appearing as a
trusted site no matter how many times I deleted it. I think I have got it off
now, but wanted to check the registry.

I ran a search and came across it, and hundreds of other nasty looking
entries in;

HKEY_USERS\(then a long number)\Software\Microsoft\Windows\Current
Version\Internet Settings\Zone Map\Domains

They all look like suspicious entries to me, i.e. there is no microsoft.com
or google.com (although there are one or two variations on the spelling).

Are they meant to be there, or should I delete the whole lot....?

Thanks very much for your help.

Mav

More about : registry spyware

Anonymous
May 21, 2005 12:11:02 AM

Archived from groups: microsoft.public.windowsxp.help_and_support (More info?)

probably down to zonealarm ? marking dodgy domains

Alasdair

--
please note email address requires editing

www.digitalmystic.co.uk

"Mav" <Mav@discussions.microsoft.com> wrote in message
news:F20D278B-20A5-46C4-88D3-6BDB34E3BB7C@microsoft.com...
> Hi All,
>
> I have just finished clearing a machine that was absolutely clogged with
> spyware. I thought I would run a scan of the registry to check for one
> particularly nasty one - crazywinnings.com - that would keep appearing as
> a
> trusted site no matter how many times I deleted it. I think I have got it
> off
> now, but wanted to check the registry.
>
> I ran a search and came across it, and hundreds of other nasty looking
> entries in;
>
> HKEY_USERS\(then a long number)\Software\Microsoft\Windows\Current
> Version\Internet Settings\Zone Map\Domains
>
> They all look like suspicious entries to me, i.e. there is no
> microsoft.com
> or google.com (although there are one or two variations on the spelling).
>
> Are they meant to be there, or should I delete the whole lot....?
>
> Thanks very much for your help.
>
> Mav
>
>
>
!