Zonemap Domains

Bernardus

New member
Member
VIP
Local time
12:55 AM
Messages
282
In the register I found even hundreds of strings with this kind of links.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\beautypornpost.com

Also many with "casino"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\casino-onlines.net

Since I didn't trust it, I removed them, but some time later again hundreds showed up.
Found out that Spybot may use this strings?
Are they safe or should I destroy these?

If safe, how to restore that list?
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
Motherboard
ASRock G41MH/USB3.
Memory
8,00 GB
Graphics Card(s)
(1) Intel(R) G41 Express Chipset (2) Intel(R) G41 Express
Sound Card
(1) VIA High Definition Audio (2) Intel(R) High Definition
Monitor(s) Displays
S24B350 Samsung
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
(1) ST31000528AS ATA Device (2) Generic- Compact Flash USB Device (3) Generic- MS/MS-Pro USB Device (4) Generic- SD/MMC USB Device (5) Generic- SM/xD-Picture USB Device
Antivirus
ZoneAlarm Free Antivirus + Firewall version: 12.0.104.000 Vs
ZoneMap\Domains shows the sites set as 'Trusted Sites' in IE (fyi, I only got paypal and my bank in that list). You very probably got some malware that needs to be found and eradicated.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell \ Lenovo\ HP \ Toshiba
OS
W7, W8.1
Antivirus
MSE, Malwarebytes
Browser
FF
So it is safe to eliminate all further stuff?
I have read that some of that malicous casino's installed a bug to spybot because they detected their malware..
Spybot than replied with legal charges.

Thanks for you reply
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
Motherboard
ASRock G41MH/USB3.
Memory
8,00 GB
Graphics Card(s)
(1) Intel(R) G41 Express Chipset (2) Intel(R) G41 Express
Sound Card
(1) VIA High Definition Audio (2) Intel(R) High Definition
Monitor(s) Displays
S24B350 Samsung
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
(1) ST31000528AS ATA Device (2) Generic- Compact Flash USB Device (3) Generic- MS/MS-Pro USB Device (4) Generic- SD/MMC USB Device (5) Generic- SM/xD-Picture USB Device
Antivirus
ZoneAlarm Free Antivirus + Firewall version: 12.0.104.000 Vs

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell \ Lenovo\ HP \ Toshiba
OS
W7, W8.1
Antivirus
MSE, Malwarebytes
Browser
FF
After a clearing of this crap, I ran an update and "immunisation" of Spybot,
I got 926 pornsites back in the reg.!
Zonemap/ domains and Zonemep esc.domains????

Plus 754 Casino's, also in Zonemap/ domains plus Zonemap/ esc. domains!!!
See what your suggestion wil change to this.

Think I found the cause.
In Windows/sys32/drivers/etc/hosts there is a list with thousands of pornsites which probably? belongs to Spybot search and destroy.

Snap106_zps1ff67226.jpg


It contains something like this

127.0.0.1 localhost
# Start of entries inserted by Spybot - Search & Destroy
127.0.0.1 xxokoriq.cn
127.0.0.1 www.xxxallvideo.com
127.0.0.1 xxxallvideo.com
127.0.0.1 xxxcategories.com
127.0.0.1 xxxemailxxx.com
127.0.0.1 xxxl-cash.net
127.0.0.1 www.xxxl-cash.net
127.0.0.1 xxxmovietour.com
127.0.0.1 www.xxxmovietour.com
127.0.0.1 xxxpornmovs.com
127.0.0.1 www.xxxpornmovs.com
127.0.0.1 xxxteenfilm.com
127.0.0.1 www.xxxteenfilm.com
127.0.0.1 xxx-testen.de
127.0.0.1 www.xxx-testen.de
127.0.0.1 xxxtoolbar.com
127.0.0.1 xxxvideos.sso9523.com
127.0.0.1 www.xxxzonevideo.com
127.0.0.1 xxxzonevideo.com
 
Last edited:

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
Motherboard
ASRock G41MH/USB3.
Memory
8,00 GB
Graphics Card(s)
(1) Intel(R) G41 Express Chipset (2) Intel(R) G41 Express
Sound Card
(1) VIA High Definition Audio (2) Intel(R) High Definition
Monitor(s) Displays
S24B350 Samsung
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
(1) ST31000528AS ATA Device (2) Generic- Compact Flash USB Device (3) Generic- MS/MS-Pro USB Device (4) Generic- SD/MMC USB Device (5) Generic- SM/xD-Picture USB Device
Antivirus
ZoneAlarm Free Antivirus + Firewall version: 12.0.104.000 Vs
Spybot S&D

Hi,

I haven't used Spybot S&D for some time. Last time was a couple of years ago. As far as I know the Immunize feature adds some websites to the restricted zone in Internet Explorer. That means that they're blocked.

As far as the hosts file entries go - it's nothing to worry about. It just means that connection to the sites listed will not be possible.

The only problem that you'll encounter is when you want to visit a site that's blocked. Or if you use a very large hosts file that contains thousands of entries like the one that I'm using it will drastically slow down the machine. There's a workaround.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
I understand your argument, however there are Zone Domains and Esc. domains and I don't know which one is OK?
Thought that Zone Domains contained the bad guys and Esc. Domains the good one's ?
Thanks for your replies.
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Ultimate 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
Motherboard
ASRock G41MH/USB3.
Memory
8,00 GB
Graphics Card(s)
(1) Intel(R) G41 Express Chipset (2) Intel(R) G41 Express
Sound Card
(1) VIA High Definition Audio (2) Intel(R) High Definition
Monitor(s) Displays
S24B350 Samsung
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
(1) ST31000528AS ATA Device (2) Generic- Compact Flash USB Device (3) Generic- MS/MS-Pro USB Device (4) Generic- SD/MMC USB Device (5) Generic- SM/xD-Picture USB Device
Antivirus
ZoneAlarm Free Antivirus + Firewall version: 12.0.104.000 Vs
Zone Map

See the explanations here:

Internet Explorer security zones registry entries for advanced users

Internet Explorer: Enhanced Security Configuration

I suppose that the test is to reset IE to defaults or reset all security zones to default.

Resetting IE will mean needing to re-enable add ons.

Personally I'd only ever use Sybot S&D to scan on demand and then only on rare occasions. It can be configured so that real time protection and immunization is disabled - then it can be used as an on demand scanner. Currently I don't have it installed.
 

Attachments

  • Internet Properties.jpg
    Internet Properties.jpg
    28.9 KB · Views: 8
  • Internet Properties 3.jpg
    Internet Properties 3.jpg
    27.8 KB · Views: 8
  • Internet Properties 2.jpg
    Internet Properties 2.jpg
    42.6 KB · Views: 8

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Back
Top