Spybot1.4 vs MS-AS, 139mm.com - Restricted Site

Discussion in 'Malware Help (A Specialist Will Reply)' started by Northern Eagle, Feb 11, 2006.

  1. Northern Eagle

    Northern Eagle Private E-2

    Hi Guys

    Installed SpyBot S&D 1.4 today with Microsoft Anti-Spyware previously installed.

    While using SpyBot S&D to immunize, MSAS popped up and advised that 139mm.com was being added to the trusted sites zone with the choice of allowing or blocking.

    I think this is a bug in the Micorsoft Anti-Spyware program as they published a KB article regarding this issue:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;902956

    Also, I used a command line utility form DiamondCS (xwhois.exe) to determine information on 139mm.com, with the report as follows:

    START REPORT

    C:\DiamondCS Utilities (Command Line)>xwhois.exe 139mm.com
    XWhois - DiamondCS Whois\RWhois Advanced Lookup (www.diamondcs.com.au)
    XWhois Lookup started at 20:50:20 02-11-2006
    Connecting to rs.internic.net:43 ...

    Whois Server Version 1.3

    Domain names in the .com and .net domains can now be registered
    with many different competing registrars. Go to http://www.internic.net
    for detailed information.

    Domain Name: 139MM.COM
    Registrar: XIN NET TECHNOLOGY CORPORATION
    Whois Server: whois.paycenter.com.cn
    Referral URL: http://www.paycenter.com.cn
    Name Server: NS.XINNETDNS.COM
    Name Server: NS.XINNET.CN
    Status: REGISTRAR-LOCK
    Updated Date: 04-feb-2006
    Creation Date: 16-jan-2003
    Expiration Date: 16-jan-2007


    >>> Last update of whois database: Sat, 11 Feb 2006 15:14:31 EST <<<

    END OF REPORT


    From this, I cannot determine if the site is malware or otherwise, however, I assume SpyBot S&S is trying to add this site to the Internet list of restricted sites. To be sure, I opened the Security tab of Internet properties and added *.139mm.com to the restricted sites anyway, just in case Microsoft Anti-Spyware added this site to the trusted sites.

    Anybody with suggestions??

    Northern Eagle
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spybot is adding it to the Restricted Zone, not the Trusted Zone. MS AS is wrong (which is what the knowledge base article also tells you).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds