Pest Patrol v Spybot S&D 1.5

breezerMN

New member
Long time user; first time poster. I recently installed spybotsd152 and now PestPatrol is
reporting four new problems. I am aware of the clintdll and zipdll compatability issue, and PestPatrol is updated and causes no problems when run with Spybot S&D 1.4. I am fairly certain the installer package i got from SaferNetworking is adbug and toolbar free :-). I am equally certain my computer is pest free. [I just reinstalled Windows on my pc and updated everything OFFLINE.] Is my problem a FP or a bug or what? Please Help, and Thank You.
Windows XPsp2 w/IE7 [all security updates]
Spybot S&D 1.5.2.20 [FULL AUTO ON & updated]
PestPatrol 4 Standard [old version still catches things others don't]
NVIDIA NForce Networking Firewall [came w/ mobo; seems to work]
AVG 7.5 free [best free AV on the planet!]
SpywareBlaster [I also use Spybot's blocklists]
PeerGuardian 2 [never WWW without it!]
AVG Antispyware [trial version prior to my recent rebuild did not find anything amiss, but
PestPatrol did.] (not currently installed)
AdAware [same story as AVGAS.] (not currently installed)
All of these freeware solutions work together well, and only spybotsd15 is new to the list. (i was using spybotsd14!)

HERE IS WHAT PEST PATROL SAYS:
OS: Windows XP
Product Edition: Standard
PestPatrol.exe: 12/27/2004 4.4.4.81
PestPatrolCL.exe: 12/15/2004 4.4.4.80
Pest Database: 01/11/2007

Pests found:

ISTbar,HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet

settings\zonemap\domains\contentmatch.net,na,na,02/23/2008,00-17-31-70-AE-A0,USA
Mirar,HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet

settings\zonemap\domains\getmirar.com,na,na,02/23/2008,00-17-31-70-AE-A0,USA
Mirar,HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet

settings\zonemap\domains\mirarsearch.com,na,na,02/23/2008,00-17-31-70-AE-A0,USA
Mirar,HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet

settings\zonemap\domains\net-nucleus.com,na,na,02/23/2008,00-17-31-70-AE-A0,USA

HERE IS A SPYBOT S&D REPORT:

--- Search result list ---

--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---

2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SDMain.exe (1.0.0.5)
2007-10-07 SDShred.exe (1.0.1.2)
2008-01-28 SDUpdate.exe (1.0.8.8)
2008-01-28 SDWinSec.exe (1.0.0.11)
2008-01-28 SpybotSD.exe (1.5.2.20)
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-02-22 unins000.exe (51.49.0.0)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDFiles.dll (1.5.1.19)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-02-20 Includes\Cookies.sbi (*)
2007-12-26 Includes\Dialer.sbi (*)
2008-02-20 Includes\DialerC.sbi (*)
2008-02-20 Includes\HeavyDuty.sbi (*)
2008-02-20 Includes\Hijackers.sbi (*)
2008-02-20 Includes\HijackersC.sbi (*)
2008-02-20 Includes\Keyloggers.sbi (*)
2008-02-20 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-02-20 Includes\Malware.sbi (*)
2008-02-20 Includes\MalwareC.sbi (*)
2008-02-20 Includes\PUPS.sbi (*)
2008-02-20 Includes\PUPSC.sbi (*)
2008-02-20 Includes\Revision.sbi (*)
2008-01-09 Includes\Security.sbi (*)
2008-02-20 Includes\SecurityC.sbi (*)
2008-02-20 Includes\Spybots.sbi (*)
2008-02-20 Includes\SpybotsC.sbi (*)
2007-11-06 Includes\Tracks.uti (*)
2008-02-20 Includes\Trojans.sbi (*)
2008-02-20 Includes\TrojansC.sbi (*)
2007-12-24 Plugins\TCPIPAddress.dll
 
I suggest you actually look at the following four (4) registry entries and see what the dword of the entries are:
Code:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\contentmatch.net]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\getmirar.com]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mirarsearch.com]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\net-nucleus.com]
Spybot's immunization process places those sites in Internet Explorer's Restricted Sites Zone by adding those entries and setting the dword=00000004.

If those entries have a dword=00000004 than I would say that the detections are PestPatrol false positives.

If the entries have some other dword than there may be cause for concern.

Meaning of the words for that type of registry entry:

0 - My Computer
1 - Local Intranet Zone
2 - Trusted sites Zone
3 - Internet Zone
4 - Restricted Sites Zone
 
DWORD is 4

Wow, thanks for the very prompt reply. Yessiree, the DWORD value IS 4 for all of those entries. Thanks again for helping me confirm this IS a FP.
 
Back
Top