SpyBot S&D may detect BoClean Malware List?? [Resolved]

A recent scan by SB had some Reg Key “changes” as hit results. (Can supply Log result if necessary)
Further scans by SuperAnt-Spyware, and some others revealed nothing. I’m thinking the results are related to having just installed BoClean; which is really fine software by the way (:CLP) and SB has identified some BOC Malware entries ??? Is that even possible?
Secondly, if I ‘quaranteen’ the SB hits, will that have any affect on BOC if in fact SB is picking something up from within BOC?
Thought I’d wait for some input before I do anything… all other investigation has shown no cause for concern. OS is “atypical” :SMLR

S…t, did that make any sense…yep!
Thanks for the help in advance, (:KWL)

Please do, as I think you may be misinterpreting what SB reported…

No Problem.
Keep in mind that there were no hits prior to BOC install.

All input appreciated. (:KWL)

— Search result list —
Sgrunt: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-706699826-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sgrunt.biz*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-706699826-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-706699826-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net*!=W=4

MediaMotor: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-706699826-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\elitemediagroup.net*!=W=4

MediaMotor: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-706699826-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net*!=W=4

MediaMotor: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-706699826-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mmohsix.com*!=W=4

Smitfraud-C.: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-706699826-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\asdbiz.biz*!=W=4

Smitfraud-C.: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-706699826-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ga31.com*!=W=4

Smitfraud-C.: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-706699826-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\greg-tut.com*!=W=4

Are you running IE-SPYAD by any chance?

Those are websites that should be in the Restricted Internet Zone, but according to SB are not, hence the exclamation mark in "*!=W=4’

However, I don’t see in what way BOClean could have anything to do with it.

If these entries were put there by IE-SPYAD, I suggest you uninstall it, then reinstall the applcation.

When done, run the SpyBot updater in order to be sure to have the latest database updates, then run another scan to see whether the issue is resolved.

No.
Thanks (:KWL)

Let’s remove all sites listed in the Restricted and Trusted Internet Zones:

Download: DelDomains.inf

To download this file, right-click the hyperlink and select: “Save Target As”

To run the file: right-click the downloaded inf-file, and select: Install (no need to restart - there is no on-screen action)

When done, update SpyBot and run another scan. It will come up clean.

No worries. Went ahead and simply deleted items found for deletion.
Rescan… all fine.
Thanks again. (:KWL)

That’s good to hear. Happy surfing! :slight_smile: