Solution to Spybot DSO

Discussion in 'Malware Help (A Specialist Will Reply)' started by Shadow_Puter_Dude, Aug 21, 2005.

  1. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Chas,

    I ran Spybot S&D with the 20050819 Defs and also got the DSO exploit. The five registry keys were:

    To fix this run regedit and navigate to the registry keys indicated by Spybot and modify the DWORD value to 3.

    Reboot, Run Spybot again, the DSO Exploit will no longer be found.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Thanks SPD, I was in the process of researching this new DSO issue. For any user that views this thread I will make the fix available.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixdso.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixdso.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.

     
    Last edited by a moderator: Aug 22, 2005
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From what I have heard, just telling Spybot to fix seems to work. The question is, why are they now starting to show only with the new updates to Spybot. This is the same type of fix used in the past to fix previous DSO Exploit problems but they may not have always been in Zones\0
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I was suprised that they started showing up with the latest defs, and in Zone0 every time. Surfing around researching the latest postives, it seems that having spybot fix it, doesn't always work. The regedit fix works, to resolve the issue. I've rebooted several times and run spybot after system restart, I get no positive results after the manual regedit.

    Microsoft supposedly fixed the DSO Exploit issue. So, why is Spybot finding it in Zone0? I suspect it is a bug in Spybot.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not if you saw it there in a manual search of the registry! Perhaps they just did not look in Zones\0 before???? I looked on 4 of my PCs and I do not have a 1004 key in Zones\0
     
  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I just checked all 4 PCs in the house and they all have the 1004 key in Zone\0. DWORD:00000000. Manually editing the DWORD value to 3, on all 5 registry keys shown by Spybot does the trick.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which means Spybot was correct in its detection! If it does not fix the problems, then that is a bug or a limitation.
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I concur with that assessment.
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I should add that if the manual regedit fails, then something is blocking the fix. SpywareGuard and MS Anti-Spyware are both active on my system, and neither blocked the fix.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    This key is system specific:

    HKEY_USERS\S-1-5-21-507921405-1614895754-839522115-1004

    and will be different on another system.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's correct! I'm waiting to see if that form of a registry patch will work. Sometimes you havd more luck by deleting a key and adding it back in than just trying to edit to a new value.
     
  13. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I'm following the other threads closely.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yeah! BJ just tried my patch in the other thread. That user is currently on! So maybe we will see real soon.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds