Go Back   PCMech Forums > Software > System Security and Privacy

System Security and Privacy Discussions of Optimal System Protection; Removal of Malware, Security News and Tips

Recommended: Click Here to Run a Free Scan for PC errors

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 12-02-2004, 11:04 AM   #1
Klutz_atlantis
Member (9 bit)
 
Join Date: Apr 2002
Location: Michigan-DA Thumb
Posts: 288
Send a message via MSN to Klutz_atlantis
Question DSO Problems

Hello:

I've scanned a few times with Spybot S&D and came up with 5 DSO enteries. I've tried getting rid of them in Safe Mode and in regular mode, but have had no luck thus far.

S&D Report:

-- Search result list ---
DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1844237615-1004336348-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3






--- Process list ---
Spybot - Search && Destroy process list report, 12/2/2004 10:51:39 AM

PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 212 (1988) C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
PID: 216 (1988) C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
PID: 224 (1988) C:\WINDOWS\system32\sstray.exe
PID: 232 (1988) C:\Program Files\FaxTalk NetOnHold\FTNOHMgr.EXE
PID: 256 (1988) C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
PID: 264 (1988) C:\Program Files\MSN Messenger\MsnMsgr.Exe
PID: 424 ( 920) wdfmgr.exe
PID: 580 ( 920) C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
PID: 592 ( 920) C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
PID: 780 ( 4) \SystemRoot\System32\smss.exe
PID: 852 ( 780) csrss.exe
PID: 876 ( 780) \??\C:\WINDOWS\system32\winlogon.exe
PID: 920 ( 876) C:\WINDOWS\system32\services.exe
PID: 932 ( 876) C:\WINDOWS\system32\lsass.exe
PID: 1088 ( 920) C:\WINDOWS\System32\Ati2evxx.exe
PID: 1100 ( 920) C:\WINDOWS\system32\svchost.exe
PID: 1172 ( 920) svchost.exe
PID: 1312 ( 920) C:\WINDOWS\System32\svchost.exe
PID: 1364 ( 920) svchost.exe
PID: 1404 ( 920) svchost.exe
PID: 1832 ( 920) alg.exe
PID: 1840 ( 920) C:\WINDOWS\system32\spoolsv.exe
PID: 1864 ( 876) C:\WINDOWS\system32\Ati2evxx.exe
PID: 1988 (1896) C:\WINDOWS\Explorer.EXE
PID: 2484 ( 920) C:\WINDOWS\System32\svchost.exe
PID: 3564 (1988) C:\Program Files\Internet Explorer\iexplore.exe
PID: 3820 (1988) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe





I read the information given by Spybot on this DOS security hole, and I have two questions remaining: 1)How do I delete/get rid of what's in my registry. 2)How do I plug the security hole?

Note: Spybot makes a back up of my registry, so can I switch out the back up for the registry that I have now?



thanks,

klutz
__________________
Pray for the troops, my brother: SPC. Nathan Hillaker HHS 1-182 FA SECFOR Acting Armorer "Rocket Cops"


Desktop:
NZXT Lexa|A8n5x|Opteron 165 Denmark x2 1.8ghz|2048 Patriot PC3200|Sapphire x800GTO2|70gig SeaGate 'Cuda|FSP AX500-A 500w PSU|NEC 3200 A DVD-Burner|IBM (black) 19" UXGA CRT flat screen|Logitec Headphones|Logitec MX Duo (700)

(still to come) New Vid Card| Monitor|Keyboard|Mouse
Laptop:
Dell Insperon (Notebook) 5150| 3.06 P4| 512mb pc2700|GeForceFX Go 5200|15.4" @ 1400x1040|USB 2.0| 30 GB HD|
Klutz_atlantis is offline   Reply With Quote
Old 12-02-2004, 11:05 AM   #2
mrmister1
Member (1 million bit!)
 
mrmister1's Avatar
 
Join Date: Feb 2003
Location: NY
Posts: 1,163
Have you tried deleting them from Spybot?
__________________
Black X-Dreamer Case | Intel Pentium 4 2.66 GHz | Intel D845PESVL | 512 MB PC2700 DDR-SDRAM | WD 120 GB Special Edition | Pioneer 16x DVD-ROM | Mitsumi 3.5-inch 1.44 MB | ATi Radeon 9800 Pro | Creative Labs Sound Blaster Live! 5.1

mrmister1
mrmister1 is offline   Reply With Quote
Old 12-02-2004, 11:06 AM   #3
Klutz_atlantis
Member (9 bit)
 
Join Date: Apr 2002
Location: Michigan-DA Thumb
Posts: 288
Send a message via MSN to Klutz_atlantis
Do you mean purge them?


kltuz
Klutz_atlantis is offline   Reply With Quote
Old 12-02-2004, 11:07 AM   #4
mrmister1
Member (1 million bit!)
 
mrmister1's Avatar
 
Join Date: Feb 2003
Location: NY
Posts: 1,163
I beleive that's what it's called.
mrmister1 is offline   Reply With Quote
Old 12-02-2004, 11:08 AM   #5
Klutz_atlantis
Member (9 bit)
 
Join Date: Apr 2002
Location: Michigan-DA Thumb
Posts: 288
Send a message via MSN to Klutz_atlantis
Yeah, I've tried that, but it didn't work.

klutz
Klutz_atlantis is offline   Reply With Quote
Old 12-02-2004, 11:11 AM   #6
mrmister1
Member (1 million bit!)
 
mrmister1's Avatar
 
Join Date: Feb 2003
Location: NY
Posts: 1,163
Did it give you an error?
mrmister1 is offline   Reply With Quote
Old 12-02-2004, 11:13 AM   #7
Klutz_atlantis
Member (9 bit)
 
Join Date: Apr 2002
Location: Michigan-DA Thumb
Posts: 288
Send a message via MSN to Klutz_atlantis
No, I went to recovery, then hit the butten "Purge Selected Items."

thanks for the help

klutz
Klutz_atlantis is offline   Reply With Quote
Old 12-02-2004, 11:15 AM   #8
mrmister1
Member (1 million bit!)
 
mrmister1's Avatar
 
Join Date: Feb 2003
Location: NY
Posts: 1,163
So, what did happen when you pressed the button? Did it show them as deleted, but not actually delete them?
mrmister1 is offline   Reply With Quote
Old 12-02-2004, 11:19 AM   #9
Klutz_atlantis
Member (9 bit)
 
Join Date: Apr 2002
Location: Michigan-DA Thumb
Posts: 288
Send a message via MSN to Klutz_atlantis
Ok, let me update you mrmister1. While we've been chatting I went through the registry and deleted the 5 files manually, and I worked. For some reason when I hit "Fix selected problems" I wouldn't do it, so I just dbl clicked the reqistry icon next to each DSO and deleted it that way and then rescanned, and now it says it's ok.

However, I"m still left with one final question: How do I block the hole that the DSOs came through? What patch do I need to download from M$?

thanks again for your help,

klutz
Klutz_atlantis is offline   Reply With Quote
Old 12-02-2004, 11:22 AM   #10
mrmister1
Member (1 million bit!)
 
mrmister1's Avatar
 
Join Date: Feb 2003
Location: NY
Posts: 1,163
It's may not be a hole. It could have been in a file that you downloaded or a website that you visited. Just make sure from now on that you don't go to any suspicious websites or open any unknown files. Also, run AdAware and Spybot regularly.

Also, use Windows update to check for any new updates.
mrmister1 is offline   Reply With Quote
Old 12-02-2004, 11:25 AM   #11
04nmr85
Member (8 bit)
 
04nmr85's Avatar
 
Join Date: Sep 2004
Location: Pennsylvania
Posts: 237
Send a message via AIM to 04nmr85
I've gotten those DSO exploit entries every time i've run Spybot. They keep coming back. It doesn't seem like they really do anything tho so i haven't been to worried about it. I've noticed them on the computers here at school too(ITT Tech in Mechanicsbug, PA). Does anyone know what it is?
__________________
Albatron PX865PE|Intel P4 2.66 ghz|Kingston Value Select 1024mb PC2700|ATI Radeon 9600 XT 128 MB|Onboard Sound|Windows XP Pro|120 GB Seagate SATA 7200 RPM HD|Artec 52 x 24 x 52|Artec 16 x 48| Just-4-PC Game Server Case|Coolermaster Jet4
04nmr85 is offline   Reply With Quote
Old 12-02-2004, 11:27 AM   #12
Klutz_atlantis
Member (9 bit)
 
Join Date: Apr 2002
Location: Michigan-DA Thumb
Posts: 288
Send a message via MSN to Klutz_atlantis
I don't know what it its, but when I hit the reqedit buttion along side the entries (Spybot S&D) it went right the entry and I deleted it manually that way, but for all the computers on such a big network...good luck.

klutz
Klutz_atlantis is offline   Reply With Quote
Old 12-04-2004, 02:42 AM   #13
thefultonhow
Moderator
Staff
Premiere Member
 
thefultonhow's Avatar
 
Join Date: May 2004
Location: Baltimore, MD
Posts: 2,887
Send a message via AIM to thefultonhow
Quote:
Originally Posted by 04nmr85
I've gotten those DSO exploit entries every time i've run Spybot. They keep coming back. It doesn't seem like they really do anything tho so i haven't been to worried about it. I've noticed them on the computers here at school too(ITT Tech in Mechanicsbug, PA). Does anyone know what it is?
The DSO thing is just a bug in Spybot. It's safe to ignore those entries.
__________________
Computer: Dell Latitude E6400 Laptop | Core 2 Duo T9400 (2.53 GHz) | 4 GB RAM | nVidia Quadro NVS 160M | 14" WXGA+ LED-backlit LCD | 250 GB 7200 RPM + 500 GB 7200RPM internal HDDs | DVD Burner | 802.11b/g wireless | Webcam, backlit keyboard | 9-cell battery | E-Port Plus port replicator | Dual Dell UltraSharp 2408WFP 24" widescreens | Windows 7 RC 32-bit

Other: 1992 Infiniti G20 5-speed with SR20VE swap | Palm Pre Smartphone | Sony Alpha A700 Digital SLR with Carl Zeiss 16-80mm f/3.5-4.5 lens, Sigma 18-50mm f/2.8 EX DC lens, Minolta 70-210mm f/3.5-4.5 lens, Sigma EF-500 DG Super flash
thefultonhow is offline   Reply With Quote
Old 12-04-2004, 10:16 AM   #14
glc
Forum Administrator
Staff
Premiere Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 26,021
Why does DSO Exploit return?

DSO-Exploit is a security gap in Internet Explorer, Outlook and Outlook Express. Microsoft did already close this gap with security updates, so with current Windows updates and patches installed, it will no longer be a threat to your system.
Spybot-S&D will still detect the DSO-Exploit, but instead of fixing it for good, it will unfortunately again set an invalid value. Therefore it will again be found with every scan.
This little bug in Spybot-S&D has already been repaired and the respective fix will soon be available as a program update.
glc is offline   Reply With Quote
Reply

Bookmarks

Follow PCMech
Subscribe

Free Weekly Newsletter. Sign up and receive our free report: 20 Tips For Becoming a Technology Power User.

NAME:
EMAIL:

Latest Posts
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT -5. The time now is 10:24 AM.