DSO Exploit

Discussion in 'Malware Help (A Specialist Will Reply)' started by spyware sucks, Aug 21, 2005.

  1. spyware sucks

    spyware sucks Private First Class

    hi. im not really experiencing any problems with spyware right now but i just scanned my computer using spybot and i keep geting a DSO exploit. I cannot remove it. Could someone tell me what it is?
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    The DSO "Data Source Object" Exploit is a bug in Internet Explorer that could, under certain circumstances, allow untrusted software to run - in other words, a vulnerability.

    To fix this issue...
    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixdso.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixdso.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

    After you complete the above, complete another scan with Spybot and see if it returns.
     
  3. spyware sucks

    spyware sucks Private First Class

    yes it is still there.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    That's the fix for the latest DSO exploits, attach your Spybot scan log.
     
  5. spyware sucks

    spyware sucks Private First Class

    maybe it has something to do with the updates? i never got the DSO exploit before but i searched for updates today and now i get it.
     
  6. spyware sucks

    spyware sucks Private First Class

    ok here it is.
     

    Attached Files:

  7. spyware sucks

    spyware sucks Private First Class

    Hi. If someone could help me real quick that would be nice. I'm afraid to turn off my computer if it isn't safe. Thanks
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you have completed post #2, the manualy regedit you should be fixed up. I will double check to confirm.
     
  9. spyware sucks

    spyware sucks Private First Class

    i did do step #2 but it did not fix it.
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Do you have Spybot's TeaTimer or any other antispyware program running because it could be causing a block?

    Also, try fixing it with Spybot and see if it will fix it. The manual regedit should fix it because it sets the values to 3 where they are supposed to be.
     
  11. spyware sucks

    spyware sucks Private First Class

    It will fix it but if i scan again it will show up again. I have Teatimer but i don't think it is running.
     
  12. spyware sucks

    spyware sucks Private First Class

    I have spyware guard running. I also have a firewall.
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Thats probably whats blocking the change then, you will have to do a manual regedit to each key.

    Click Start > Run > Type in regedit

    Navigate to the following key:

    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    On the right hand side look for the DWORD value "1004". Right click on "1004" and select modify. Now change the value data to 3. Click OK

    Navigate to the following key:

    HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    On the right hand side look for the DWORD value "1004". Right click on "1004" and select modify. Now change the value data to 3. Click OK

    Navigate to the following key:

    HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    On the right hand side look for the DWORD value "1004". Right click on "1004" and select modify. Now change the value data to 3. Click OK


    Navigate to the following key:

    HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    On the right hand side look for the DWORD value "1004". Right click on "1004" and select modify. Now change the value data to 3. Click OK


    Navigate to the following key:

    HKEY_USERS\S-1-5-21-1110412475-2304659736-1445258045-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    On the right hand side look for the DWORD value "1004". Right click on "1004" and select modify. Now change the value data to 3. Click OK


    After you complete the above, exit registry editor, reboot and do another scan with Spybot.
     
    Last edited: Aug 22, 2005
  14. spyware sucks

    spyware sucks Private First Class

    HKEY_USERS\S-1-5-21-2280197863-308232438-2037070609-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    On the right hand side look for the DWORD value "1004". Right click on "1004" and select modify. Now change the value data to 3. Click OK


    I can't find this. I click on HKEY_USERS but there is no S-1-5-21-2280197863-308232438-2037070609-1003
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Procede on with the next key, see if they come back after a restart.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thats because it is not that key! It is not the same on all PCs. Yours was:

    HKEY_USERS\S-1-5-21-1110412475-2304659736-1445258045-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
     
  17. spyware sucks

    spyware sucks Private First Class

    which key? i have S-1-5-21-1110412475-2304659736-1005
    i don't have that one that you posted
     
  18. spyware sucks

    spyware sucks Private First Class

    ok thanks for clearing that up chaslang
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Now, after you complete each edit reboot and do another scan and see if they come back.
     
  20. spyware sucks

    spyware sucks Private First Class

    it won't go away. this is really getting on my nerves.
     
  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Attach the new Spybot log.
     
  22. spyware sucks

    spyware sucks Private First Class

    is this really a big problem? cause school starts tomrrow and i raelly need to get to bed
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    No it's really not a huge deal but it does need to be addressed as soon as possible. We will get it tomorrow, go on to bed :p
     
  24. spyware sucks

    spyware sucks Private First Class

    here is the log. i think when i rebooted the registry values went back to the originals.
     

    Attached Files:

  25. spyware sucks

    spyware sucks Private First Class

    thanks for your help man. i really appreciate it.
     
  26. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Reboot into Safe Mode and then complete the below...

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixdso1.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixdso1.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

     
  27. spyware sucks

    spyware sucks Private First Class

    i can't add the registry. there was an error in accessing the registry.
     
  28. spyware sucks

    spyware sucks Private First Class

    should i try it in normal mode?
     
  29. spyware sucks

    spyware sucks Private First Class

    am i the only one with this problem?
     
  30. spyware sucks

    spyware sucks Private First Class

    is there anyway to fix it?
     
  31. spyware sucks

    spyware sucks Private First Class

    http://forums.majorgeeks.com/showthread.php?t=70491

    sorry for the repeated posting but i need to figure this out before i go nuts. i have the same problem as this person. spybot scans were coming out clean before but after i updated it i got those DSO exploits.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the other thread, it is not a problem as long as you have your Windows Updates. It is more than like due to new definitions related to Security Center settings.

    Some users have just fixed them by manual editing of the registy. Others are taking the approach of disabling that particular scan within Spybot.
     
  33. spyware sucks

    spyware sucks Private First Class

    so what action should i take? is it ok to just leave it the way it is?
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of Windows do you have and what service pack level?
    Do you have all your updates? Don't assume or guess you do! Check to make sure.

    Once you are fully updated. Either manually edit each of those registry keys Spybot reports to change the value (the dword value) to a 3. It is probably a 0. Your other choice as I already said is to tell Spybot to ignore this.

    See: http://www.wilderssecurity.com/showthread.php?p=536951#post536951
     
  35. spyware sucks

    spyware sucks Private First Class

    I have windows xp with service pack 2. my computer is set to download automatic updates. it asks me to install every once in a while when i shut down.

    I have tried to manually edit the registry but they just keep changing back. How do i tell spybot to ignore it?
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you look at the links I gave you?
     
  37. spyware sucks

    spyware sucks Private First Class

    i skimmed through it just now.

    i have a question. is it recommended to set spybot to ignore the exploits? because setting it to ignore and just physically ignoring it have the same results.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not necessary to set it to ignore. You can just do that yourself but you will always have them on every scan. It is up to you.

    Are you using any kind of Security Center software other than the one in WinXP SP2?
     
  39. spyware sucks

    spyware sucks Private First Class

    i have a firewall
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Whose firewall? This is not necessarily a security center.

    Did you disable Windows Security center?
     
  41. spyware sucks

    spyware sucks Private First Class

    I use symantec personal firewall. i didn't disable Windows Security center
     
  42. spyware sucks

    spyware sucks Private First Class

    Actually i think 4 of the entries were fixed because the scan only shows 1 entry now.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which one? Maybe you never went back and fixed the one that was necessary because the original fix post showed the wrong key.
     
  44. spyware sucks

    spyware sucks Private First Class

    The one in S-1-5-21
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So go to the registry key and manual change it so the dword value in the key is 3 instead of 0.

    I assume you mean the below key:

    HKEY_USERS\S-1-5-21-1110412475-2304659736-1445258045-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004
     
  46. spyware sucks

    spyware sucks Private First Class

    I just did and the spybot scan i ran still showed the same problem. Well I'll stop wasting your time. I think it's best for me to just leave it alone if it really isn't any harm.
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying you fixed the registry key manually?

    Did it actually show the change taking effect in regedit?

    Double check the key after making the change!
     
  48. spyware sucks

    spyware sucks Private First Class

    yes i fixed it manually. It did show the change in effect but spybot still picks it up in the scans.
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you are changing the same exact key that Spybot is detecting?
     
  50. spyware sucks

    spyware sucks Private First Class

    yes. i am sure
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds