| View previous topic :: View next topic |
| Author |
Message |
smith.p.sean UberTweaker
Joined: 16 Jun 2004 Posts: 1595 Location: orlando, UCF
|
Posted: Thu Jul 29, 2004 1:48 pm Post subject: Spy Bot DSO Exploit |
|
|
| Everytime i scan with Spybot i get 4 DSO exploits that are found, there used to be five but i downloaded a small utility after researching this that patched one of them... This is really annoying, is there anything i can do to fix it and get rid of it??? I looked into it like a couple months ago so perhaps someone can give me newer info on how to get rid of it?? |
|
| Back to top |
|
 |
Google Sponsor
|
Posted: Thu Jul 29, 2004 1:48 pm Post subject: Advertisement |
|
|
|
|
| Back to top |
|
 |
smith.p.sean UberTweaker
Joined: 16 Jun 2004 Posts: 1595 Location: orlando, UCF
|
Posted: Thu Aug 12, 2004 11:20 pm Post subject: |
|
|
| *bumb, perhaps could ne one awnser this??? nathan? ne one? i would really like to know because for the time being i switched to advanced mode in Spy Bot and disabled it. |
|
| Back to top |
|
 |
null_set TweakNOOB

Joined: 22 Sep 2004 Posts: 151 Location: Jersey
|
Posted: Sat Jan 22, 2005 5:16 pm Post subject: |
|
|
yo.
I've had that problem, under the same circumstances as you, it seems. I've isolated it in the registry
HKEY_USERS\S-1-5-21-682003330-1708537768-854245398-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3
I've tried killing it several times. It won't go away.
Anyone else have a clue? _________________ [ ]
chown -R us ./your_base
 |
|
| Back to top |
|
 |
Spiegel SirTweaksabit

Joined: 06 Sep 2004 Posts: 348 Location: Morgan City, LA
|
Posted: Sat Jan 22, 2005 5:29 pm Post subject: |
|
|
my spybot also picks up the 5 DSO exploits every time...nothing else manages to get on my machine, just those 5...  _________________
 |
|
| Back to top |
|
 |
Ham_fisT Lord of the Tweak

Joined: 20 Jun 2004 Posts: 2244 Location: Gone Fishin'
|
Posted: Sat Jan 22, 2005 5:54 pm Post subject: |
|
|
I've googled and read a lot of threads about this, and no one seems to be able to answer the WHY question, they all say to just ignore it  _________________ Yeah....... ok |
|
| Back to top |
|
 |
[KoG]^weaZel TWEAKGURU

Joined: 31 Oct 2003 Posts: 3296 Location: IRC ETG #kog
|
Posted: Sat Jan 22, 2005 7:24 pm Post subject: |
|
|
I have this same problem on just about every computer that I have used SpyBot on. And like others have said I dont know how to get rid of them. _________________ I tweaked and it tweaked back! So I Tweaked some more!
"Barney is like the Michael Jackson of PBS." - James Tybeerious |
|
| Back to top |
|
 |
Fitz Goran TweakNOOB
Joined: 07 Sep 2004 Posts: 53
|
Posted: Fri Jan 28, 2005 11:12 am Post subject: |
|
|
Spybot doesn't fix this problem properly. Instead of changing the 1004 DWORD value to 3 it deletes the dword value and creates an empty string value.
You can fix these problems manually by deleting the 1004 string valueand creating a new dword value, naming it 1004, and settings its value data to 3.
- or -
you can download this update http://www.majorgeeks.com/download4392.html |
|
| Back to top |
|
 |
[KoG]^weaZel TWEAKGURU

Joined: 31 Oct 2003 Posts: 3296 Location: IRC ETG #kog
|
Posted: Sun Jan 30, 2005 12:02 am Post subject: |
|
|
Thank you for the tip Fitz!
And welcome to TweakNews.  _________________ I tweaked and it tweaked back! So I Tweaked some more!
"Barney is like the Michael Jackson of PBS." - James Tybeerious |
|
| Back to top |
|
 |
FroGGer SirTweaksabit
Joined: 18 Sep 2003 Posts: 365 Location: Chicago
|
Posted: Tue Feb 01, 2005 12:08 am Post subject: |
|
|
this is a bit off the subject but I know how you feel. Everytime I run NAV 2004, I get two of each of the following files that will not go away. They are
kill.exe and load.reg. One is a IRC Trojan and the other is a Trojan Horse, and NAV can't delete these and spybot never found them. Do I need a different program to get rid of them. I heard of a program called The Cleaner, but it's payware. Does anyone have it or know if it is good?
thanks _________________ ABIT IC7 MAX 3, Corsair PC4000 Pro, P4 2.6C @3.23 GHz 1:1, 2.5-4-4-7, 2 WD Raptors in RAID 0 |
|
| Back to top |
|
 |
Fitz Goran TweakNOOB
Joined: 07 Sep 2004 Posts: 53
|
Posted: Tue Feb 01, 2005 9:59 am Post subject: |
|
|
FroGGer, have you tried running NAV in safe mode?
Another option is if Norton identifies the trojan goto http://www.sarc.com/avcenter/vinfodb.html and search for the trojan's name. Usually the instructions found there work good for removing trojans. |
|
| Back to top |
|
 |
FroGGer SirTweaksabit
Joined: 18 Sep 2003 Posts: 365 Location: Chicago
|
Posted: Tue Feb 01, 2005 10:08 pm Post subject: |
|
|
Yes I have and Norton identifies it but I can't find instructions on how to delete it. Does NAV get rid of trojans? _________________ ABIT IC7 MAX 3, Corsair PC4000 Pro, P4 2.6C @3.23 GHz 1:1, 2.5-4-4-7, 2 WD Raptors in RAID 0 |
|
| Back to top |
|
 |
Fitz Goran TweakNOOB
Joined: 07 Sep 2004 Posts: 53
|
Posted: Tue Feb 01, 2005 11:07 pm Post subject: |
|
|
Usually NAV can get rid of trojans.
Which trojan is it? |
|
| Back to top |
|
 |
FroGGer SirTweaksabit
Joined: 18 Sep 2003 Posts: 365 Location: Chicago
|
Posted: Wed Feb 02, 2005 12:38 am Post subject: |
|
|
kill.exe and load.reg _________________ ABIT IC7 MAX 3, Corsair PC4000 Pro, P4 2.6C @3.23 GHz 1:1, 2.5-4-4-7, 2 WD Raptors in RAID 0 |
|
| Back to top |
|
 |
FroGGer SirTweaksabit
Joined: 18 Sep 2003 Posts: 365 Location: Chicago
|
Posted: Wed Feb 02, 2005 12:41 am Post subject: |
|
|
And I just checked and they're not quarantined either. They just show up whenever I run it (in safe mode since I always run it in safe mode). _________________ ABIT IC7 MAX 3, Corsair PC4000 Pro, P4 2.6C @3.23 GHz 1:1, 2.5-4-4-7, 2 WD Raptors in RAID 0 |
|
| Back to top |
|
 |
Fitz Goran TweakNOOB
Joined: 07 Sep 2004 Posts: 53
|
Posted: Wed Feb 02, 2005 11:18 am Post subject: |
|
|
| What are the names of the trojans as identified by NAV? |
|
| Back to top |
|
 |
FroGGer SirTweaksabit
Joined: 18 Sep 2003 Posts: 365 Location: Chicago
|
Posted: Wed Feb 02, 2005 1:01 pm Post subject: |
|
|
one is load.reg listed as an IRC Trojan
and the other is kill.exe listed as a Trojan Horse _________________ ABIT IC7 MAX 3, Corsair PC4000 Pro, P4 2.6C @3.23 GHz 1:1, 2.5-4-4-7, 2 WD Raptors in RAID 0 |
|
| Back to top |
|
 |
|