DSO exploit and xedso

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mcrbloke, Aug 21, 2004.

  1. mcrbloke

    mcrbloke Private E-2

    Hi All,

    i wonder if anyone has the solution to the spys i seem to have in my computer? I've run spybot search and distroy, Ad Aware, spy sweeper and Mcafee antispy ware. I've also downloaded NAV and stopped using the mcafee as NAV found two viruses and several different spys. I've followed the instructions and turned off the system restore etc, run all the checkers in safe mode, used the cwshredder and hsremover and also the kill2me.

    yet everytime i go back on to IE, the xedso comes up on a different page. also, each time i run the spybot, the DSO exploit comes back even when i've not been on the internet.

    Ive even tried to go round the problem and downloaded firefox. the problem is that my computer stops recognising that the internet connection is there. so that means outlook express cannot get email, and no browsing on the internet until i reboot the computer. i think i have about 15 minutes.

    Ive throught about making a network connection to my lapton which doesnt seem effected and seeing if i can run a virus scan from that. but then i was worried that i might infect my laptop.

    the operating system is xp with service pack 1 but not 2 (it will not allow me to download it yet.

    does anyone have any suggessions on how to solve my problem. i've been going at this for a month now and each time i think i am nearering the end, i seem to get back to square one.

    cheers folks.

    John (mcrbloke)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    With a little bit of search you would see that the DSO Exploit issue with SpyBot has been discussed a couple thousand times. It's a bug you can ignore. Just veryify you have all your MS Critical (now call High Priority) Updates installed.

    What does this mean:
    "yet everytime i go back on to IE, the xedso comes up on a different page"

    What is the xedso?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way do not install SP2 yet. There are lots of issues people are having with it. See the software forum. At a minimum you want to check for software compatibility issues.
     
  4. mcrbloke

    mcrbloke Private E-2

    hi again, soz about the DSO Exploit, so much to read and i had just started to get that message. as for the xesdo, soz again, i'm dyslexic and its hard at times. what i actually meant to type was

    xadso

    when i load up IE, another page comes up and with xadso. I've read stuff on this and it says its:

    xadso.offeroptimizer spyware

    and that spybot will get rid of it. however, it doesnt seem to.

    is that any clearer?

    thanks for you time by the way

    John (mcrbloke)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, that's better. I believe this is part of the "abetterinternet" family of crap! Do the following:

    1) Download HijackThis from here
    2) Read information about using HJT and posting HJT logs (as text attachments) here
    3) Download the VX2 finder, run it and select "click to find abetterinternet". Then select "make log" and copy/paste the log back here (also as an attachment).
     
  6. mcrbloke

    mcrbloke Private E-2

    Hi again,

    i've done the both the hijace this and the vx2 finder and will post the logs on here. Just a note of caution, i'm by no means an advance user. again, thanks for you help.


    thanks

    John (mcrbloke)
     

    Attached Files:

    Last edited by a moderator: Aug 22, 2004
  7. mcrbloke

    mcrbloke Private E-2

    Oh Chaslang, I'm not sure what you mean by adding it as an attachment?

    JOHN
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I changed it to an attachment for you. Take a look. You just needed to save the logs to a text file (a .txt suffix) and then upload it using the manage attachments button from advanced mode of adding your message.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a bunch of things wrong including some trojans. You need to run some online scans before we do anything else. Run the following and let me know if they find anything ( Select Auto Clean as appropirate with these):

    http://housecall.trendmicro.com/housecall/start_corp.asp
    http://www.pandasoftware.com/activescan/com/activescan_principal.htm
    http://www.ravantivirus.com/scan/
    http://www.trojanscan.com/

    Run HijackThis and put checks on the following items and then click Fix:
    O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/1025960.exe
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/i...382/mcfscan.cab
    O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CC} - http://direct.data-line.us/gbn298.exe

    There is more but we need to do the above before continuing. Now post me a new HijackThis log but do it as an attachment.
     
  10. mcrbloke

    mcrbloke Private E-2

    Hi,

    here is my new Hijack this file after fixing the ones you mentioned. I've tried to run the links you have put up but for some reason, i am unable to do so. it tells my my activex control settings are wrong but they are set to enble. I've tried running them through firefox too, but nothing yet. i'll keep trying and post the results once done.

    thanks

    John (mcrbloke)
     
  11. mcrbloke

    mcrbloke Private E-2

    here's the attachment

    John
     

    Attached Files:

  12. mcrbloke

    mcrbloke Private E-2

    another stubbling block. I've tried to run the scans for all four sites listed but with no success. it tells me that i need to have activex enabled and i have followed the instructions. the only thing is, when i go to internet options and then security, the custom button is not highlighted so i can not press it to make sure that activex is enabled. on the other three buttons it is. has anyone any suggestions on how to do this so i can run the scan?

    thanks all

    John
     
  13. mcrbloke

    mcrbloke Private E-2

    hi all

    I think i've come to the end of the road with the computer problem i'm having. I uninstalled my NAV and put the 30 trial of Panda in. did a complete scan and found 2 viruses and 6 spy ware and one boot. let it sort them out and it needed to restart the comp to sort one spyware out. well, not it seems to go round in circles. it loads up to a certain point and then automatcially starts to log off.

    it will also not let me start in safe mode as it says the configuration registry database is corrupt and cannot log on.

    any suggestions to get out of this fix?

    or is it a case of admitting defeat and chucking it in the bin and starting again?


    ta

    john
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you logged in with Administrator priveledges?
     
  15. mcrbloke

    mcrbloke Private E-2

    no I'm not unfortunatly. does this mean i am better chucking it. i'd rather not but i've been at this four weeks now and its really getting me down.

    John
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When fighting problems like these it is best to follow the directions we give you and not jump around and do other things on your own or to try working the problem on multiple help forums simultaneously (which others have done). As a I said in my previous messages there were multiple issues to worry about. We need to be careful what we did. I was worried that deleting the some items without taking certain precautions could make the computer non-bootable. And now that could be what has happed due to uninstalling NAV and using Panda. The lines from you log that were of concern to me were:

    F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
    O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
    O2 - BHO: (no name) - {62AC4609-BD40-7692-8003-64550DA72A1A} - C:\WINDOWS\System32\fbyxdt.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [Win32 USB2 Driver] svchosting.exe
    O4 - HKLM\..\Run: [Microsoft IT Update] dwervdl32.exe
    O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
    O4 - HKLM\..\Run: [Microsoft Java Virtual Machine] javams.exe
    O4 - HKLM\..\Run: [Shell Monitor] taskmgr32.exe
    O4 - HKLM\..\Run: [Microsoft WinUpdate] syslx32.exe
    O4 - HKLM\..\RunServices: [Win32 USB2 Driver] svchosting.exe
    O4 - HKLM\..\RunServices: [Microsoft IT Update] dwervdl32.exe
    O4 - HKLM\..\RunServices: [Microsoft Java Virtual Machine] javams.exe
    O4 - HKLM\..\RunServices: [Shell Monitor] taskmgr32.exe
    O4 - HKLM\..\RunServices: [Microsoft WinUpdate] syslx32.exe
    O4 - HKCU\..\Run: [Win32 USB2 Driver] svchosting.exe
    O4 - HKCU\..\Run: [Microsoft IT Update] dwervdl32.exe
    O4 - HKCU\..\Run: [Microsoft Java Virtual Machine] javams.exe
    O4 - HKCU\..\Run: [Shell Monitor] taskmgr32.exe
    O4 - HKCU\..\Run: [Microsoft WinUpdate] syslx32.exe

    Deleting the wsaupdater.exe file (which the virus scan may have done), without fixing the registry, Windows XP will never log on again. It'll show the welcome screen and everything, but will immediately log off if you attempt to log on. (by any means, including safe mode command prompt)

    Now you will need to boot with the Windows XP CD to the recovery console, and copy userinit.exe to wsaupdater.exe. And the we may be able to boot back normally and repair the registry entry.

    So boot from your WinXP CD and when you reach the setup screen, press R to start the Recovery Console.

    Choose the installation to log on to (if there's just one, hit enter). When prompted for password, just hit enter unless you have set a password for the user "Administrator" (it's blank by default in XP)

    When you get logged onto the Recovery Console, go to c:\windows\system32 (or wherever Windows is installed).

    Use the following commands.

    cd \windows\system32

    copy userinit.exe wsaupdater.exe

    Take the CD out of the drive, and type exit to quit the recovery console and restart Windows normally.

    Let me know if you can get to this point and we will then look into repair the registry.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you the Administrator of the PC and do you know the Administrator password?

    Is this your PC?
     
  18. mcrbloke

    mcrbloke Private E-2

    Yes it is my pc, but i have no idea about the administrator password. I've asked the person who put xp on for me but he has no idea.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try booting as the Administrator and just hit return for a "blank" password thats the default.
    See if that works.

    When you loging now as a particular user, you do not have admin capabilities?
     
  20. mcrbloke

    mcrbloke Private E-2

    it only goes to administrator when i try to start in safe mode. Iim not really sure if i have any admin rights when signed on as me.

    i've just tried what you suggested and hitting blank but it seems to ask for a password and then i hit return again, it seems to stick. so to no avail. the shame is, it looked like panda would have sorted this out finding what it did. I did save the log but now cannt get at it.

    John
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where are you logging in from right now?

    There is small little application that can be run to erase the Administrator password but you need to boot from either a CD or a floppy disk with this application on it. See this link: http://home.eunet.no/~pnordahl/ntpasswd/

    Once you have blanked out the Administrator password, we could than try using you WinXP CD to boot to the recovery console. You do have your original WinXP CD don't you and is it a bootable CD?
     
  22. mcrbloke

    mcrbloke Private E-2

    Hi again,

    I'm currently using a laptop at the side of the no defunct computer so i can do what you suggest as i have a xp disc too.


    I'm just about to print off the instructions but they will take me a while to wade through.

    thanks again, youre very resoursefull. it is appreciated (if not spelt correctly).

    John
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let me know when you have gotten your password blanked out.
     
  24. mcrbloke

    mcrbloke Private E-2

    Hi Chaslang,

    I appriciate all the help and time you've given me, its good to know there are people out there willing to do so, so thank you.

    I think i'm going to have to leave it. I've tried to go through the programs to get the password sorted, but the level of competency needed is way beyound me so i didnt know what i was meant to do.

    anyway, thanks again

    regards

    John (mcrbloke).
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    John,

    It isn't too difficult. I know it can look confusing. But all you have to do is download a compressed file (a ZIP file) and extract the files and then run a a command that will make a boot floppy for you. Obviously you need a formatted floppy disk too. After that you just boot the disk and basically accept all the defaults until you get to the point about the password. There you just use the option to blank it out rather than change it. Just go here to get the ZIP file I'm talking about and save it to a directory on your computer:

    ftp://listsoft.ru/pub/12378/bd040116.zip

    Be patient after clicking on that link. It sometimes takes a while to start downloading.

    Then unzip it, put a formatted floppy in your floppy drive, run the install.bat file by double clicking on it, give the letter of your floppy drive (which is always "a"). And it will make a bootable floppy with the NT Password Reset tool on it.

    How else are you going to use this PC if you don't fix it? Are you just planning to reinstall WinXP all over again? That takes some work too and you could loose anything you have not backed up on the hard disk. Also, you will have to reinstall and reconfigure any applications that you use too.
     
    Last edited: Aug 24, 2004
  26. mcrbloke

    mcrbloke Private E-2

    Hi Chaslang,

    john again. thanks for your support. I eventually got the program to install onto a floppy but needed to install something called rawrite2. you'll probably laugh, but i didn’t even know how to get the computer so boot from the a drive. so i was looking on line to see if i could fine out when i came across some information about repairing the OS.

    http://www.michaelstevenstech.com/XPrepairinstall.htm

    as i had nothing to loose, i gave it a go. it works too. you have to put the S/N again, which i managed to get hold of. so at least i was able to get some important emails and documents off.

    I think the panda antivirus was causing the problem, but then again, i think the computer is just broken. It still will not go into safe mode.

    so anyway, I’m going to get rid and start again. I know it's going to cost but even though I’m not an expert, i rely on a computer so need to know it will work.

    so all your help really did help and I’m so grateful that you gave some of your time up to me.

    I was wondering if there was a group who boycotted the companies who use this spyware to advertise to us. For example, yell.com came up once in a popup as did the AA. I don’t know how else to challenge this appalling behaviour.

    Right, all the best

    JOHN
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    John,

    The ZIP file I sent you the address of had rawrite2 already in it. Are you able to boot this computer now in normal mode?

    How are you attempting to get into safe mode and exactly what happens?
     
  28. mcrbloke

    mcrbloke Private E-2

    hya,

    i'm able to get on to the actual loggin now. there isnt anything in safe mode (when i press ctrl, alt and delete, there are not programs to be found.

    is it possible that as it is four years old that it is just past it?

    Johhn
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please clarify your statements.

    If you login, there must be something showing in Task Manager under Processes.

    What do you mean there isn't anything in safe mode? I thought you could not boot in safe mode?
     
  30. mcrbloke

    mcrbloke Private E-2

    i don't really understand it myself. i repaired the xp by putting the cd in. however, it doesnt seem to have worked properly, most be some errors somewhere. so now when i go to safe mode, all it has is the four 'safe mode' in each corner but nothing else (which is where i started before i got the disc in with all the viruses and adwares.

    I did think of formating the disc but then i can understand who it will format itself when the operating system is on the disc.

    so it is working of a sorts, but not reliably yet.

    does that make anymore sense?

    regards

    JOHN

    ps, sorry for the late reply, i've been away for a long weekend.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so booting in safe mode comes up with nothing. Not even the Taskbar at the bottom of the screen where you can click Start?

    What about booting normal mode?

    And are you saying you booted from the XP CD to the recovery console and did a repair?
     
  32. mcrbloke

    mcrbloke Private E-2

    HI Chaslang.

    got my new computer so that old problems ended. thanks for all your help. hopefully, this one will be ok. hope so.

    all the best

    JOHN
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome John!

    Make sure you get your system protected from reoccurrence of issues like this. Here are some simple steps you can take to reduce the chance of infection in the future. I strongly encourage you to do them all.

    1. Visit Windows Update:
    Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly
    patched OS.
    a. Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp
    Do this at least once a month.
    b. Never add any site to your Trusted Sites Zone.

    2) Anti Virus: make sure you have one and keep it updated. Here are some good free ones:
    http://majorgeeks.com/download1968.html Avast
    http://majorgeeks.com/download886.html AVG
    The top two hands down. Better than Norton or McAfee!
    Only run ONE AV!

    3) Firewall: if you don't have one get one of these below. The last two are free versions:
    Don't care if your on dial up or High Speed....you must have a firewall
    http://majorgeeks.com/download738.html Kerio Personal Firewall
    http://majorgeeks.com/download3356.html Sygate Personal Firewall Free
    http://www.majorgeeks.com/download388.html ZoneAlarmFree

    4) Get a Temp File/Cookies/index.dat cleaner
    http://majorgeeks.com/download4191.html CCleaner (Crap Cleaner)

    5) SpyWare Prevention (These prevent, they are not scanners. Scanners are listed later.)
    http://majorgeeks.com/download2859.html SpyWare Blaster
    http://majorgeeks.com/download3045.html SpyWare Guard

    6) SpyWare Scanners/Removers
    http://majorgeeks.com/download2471.html SpyBot (Use the Immunize feature. I don't activate the TeaTimer)
    http://majorgeeks.com/download506.html Ad-aware SE
    http://download.lavasoft.de.edgesui...lvx2cleaner.exe VX2 Cleaner Plug-In for Ad-Aware
     
  34. mcrbloke

    mcrbloke Private E-2

    Hi Chaslang,

    it looks like i was too late. it must have been whilst i was downloading NAV. I've got NAV professional too, but it seems that i've got something in, i think it is trying to dail things too, but i'm on broadband and don't have an internal modum it can use. but then it disconects me from broadband. I've run both ad aware and spy bot and NAV with the system restore off, then rebooted but it seems they keep coming back.

    any suggestions

    JOHN
     
  35. mcrbloke

    mcrbloke Private E-2

    Hi Again, Chaslang, do you have any ideas about this, i think it is what is causing me my new problem. this is the information i manged to get from the web page it brought up. i've deleted the dailer

    http:/as1.falkag.de/dat/bgf/200409/09/bugs.html
    1025972.exe
    deposito.hostance.net

    John
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    John,

    Since this is a new problem not pertaining to the info in the title of this thread, it would be better if you started a new thread for this problem. Please clearly explain the exact problem. Are you being hijacked, getting popups ? What is happening? And make sure you follow ALL the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Tell us what you have run and the results of each step so we know what you have executed and what problems may have been present on your system.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds