 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 Reviews:
·Rogers Hi-Speed
3 edits | SPYBOT S&D 1.3 - DSO EXPLOIT GONE! NOTE: ==== THIS IS A MANUAL FIX I USED WITH THE ASSISTANCE OF GREY MAGICS REPORT TO REMOVE THE 2002 DSO EXPLOIT OFF MY SYSTEM, IF MAY JUST REMOVE DETECTION FROM SPYBOT S&D, I CAN NOT SAY IF IT ACTUALLY FIXES THE ISSUE. IT DOES HOWEVER APPLY THE REGISTRY CHANGE CAUSING SPYBOT S&D TO NO LONGER REPORT THE DSO EXPLOIT. IT MAY BE EASIER TO GO ON IGNORING THE ISSUE BY "EXCLUDING" IT, BUT I WANTED TO TO TRY A DIFFERENT APPROACH ============================================================ Anybody notice the exploit reported by Grey Magic is never fixed properly with Spybot Search & Destroy?
Each time you try to run it and fix the affected registry keys (5) they come back!
A MANUAL registry patch did the trick for me. I did it myself. Now Spybot Search & Destroy no longer detects the DSO exploit.
It requires DELETING the original key and replacing the 1004 key with the DWORD as the field, and inserting "3" for the value. This is what Spybot S&D can't do because it can never alter the original key as the value is not DWORD to begin with. But Spybot S&D has a neat feature that can TAKE you to the exact location of the key within the registry. The first time I clicked the registry icon in the far right hand corner... it did not take me there. Instead it just opened up the registry (but not to the exact key). I re-clicked icon in spybot and THEN it took me to the exact key located within the registry.
Change the value of "1004" (DWORD) to 3. Do this for EACH entry Spybot reports. Delete the original key and replace the key "1004" and create the DWORD field with a value of 3.
Does this work for you?  It very well may, and it very well may not. For myself, it did.
Thanks Grey Magic for your help!!  »www.greymagic.com/security/advis···m001-ie/ -- "A man can tell a thousand lies, Ive learned my lesson well, Hope I live to tell the secrets I have learned, till then, It will burn inside of me..." ~ Madonna |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 | Nobody try it or can confirm?  |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 Reviews:
·Rogers Hi-Speed
3 edits | »forums.net-integration.net/index···ic=15308 READ THE ABOVE THREAD... THIS IS AN INVALUABLE RESOURCE AND IT TURNS OUT I FIXED MY REGISTRY CORRECTLY 
What amazes me is there are over 100 unique visitors who have spent the time to read my topic yet nobody cares nor wishes to reply. 
Oh well.  I thought this was of some interest and wanted to help you guys out in fixing the DSO exploit detection problem as so many of you complain about Spybot not being able to fix it.
The fix is now here if you want it? ? |
|
 dadkinsCan you do Blu?Premium,MVM join:2003-09-26 Hercules, CA kudos:18 | reply to Dustyn Nope, the one time I actually removed them, it hosed my XP. Now, the first thing I do is "Exclude" them, don't want to go through that again. |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 Reviews:
·Rogers Hi-Speed
2 edits | Thanks for the info.  Changes were applied yesterday evening and all is working fine.
By the way... your not REMOVING anything, your correcting a registry key by entering in the new updated values. Spybot has NEVER tried to DELETE this DSO exploit. It tries to MODIFY the key. Although the Spybot S&D program makes you think that when the DSO exploit is found, your REMOVING the affected registry key. That is not the case...your simply modifying the key. But it simply fails when using Spybot.
A manual change is safe.  I've performed it on two PC's so far. I hope you may try again.. but try to correct it manually. If not, cool. I just wanted to share my successful results.  -- "A man can tell a thousand lies, Ive learned my lesson well, Hope I live to tell the secrets I have learned, till then, It will burn inside of me..." ~ Madonna |
|
 BubbaGIT-R-DONEPremium,MVM join:2002-08-19 St. Andrews Reviews:
·DIRECTV
·Pickwick Cablevi..
·Comcast
| reply to Dustyn Thanks for taking the time to post your info. This is also whats being recommended @ Spybots Official Forums until a patch is released.
• Thread at Spybot's Forum---> Dso Exploit, Spbot fix but returns
Bubba |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 Reviews:
·Rogers Hi-Speed
2 edits | No prob!  I also provided the same link. Although I found this link only AFTER I provided this fix. Interesting to see I got the fix right!!  I also saw you postings there too.
When you mean a new patch, do you mean one provided by Microsoft? Or by Spybot S&D?
This "user friendly" patch would provide the same exact fix as the one I did on my PC?
Am I correct?  -- "A man can tell a thousand lies, Ive learned my lesson well, Hope I live to tell the secrets I have learned, till then, It will burn inside of me..." ~ Madonna |
|
 keith2468Premium,MVM join:2001-02-03 Winnipeg, MB | reply to Dustyn People may be grateful, but they don't always have time to come back and say thanks.  |
|
|
|
 dadkinsCan you do Blu?Premium,MVM join:2003-09-26 Hercules, CA kudos:18 1 edit | reply to Dustyn Thanks, I'll try a manual change later. |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 Reviews:
·Rogers Hi-Speed
| ..... yes keyword: "CHANGE" 
Cool, I'm sure it will work for you too. 
Also? I will bump the post up tomorrow if there are no replies as threads here at the "SECURITY" forum tend to slip off the first page within an hour or so. -- "A man can tell a thousand lies, Ive learned my lesson well, Hope I live to tell the secrets I have learned, till then, It will burn inside of me..." ~ Madonna |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 | -bump-  |
|
 Name GamePremium join:2002-07-07 North Myrtle Beach, SC kudos:6 | said by Dustyn: -bump- 
»www.mcse.ms/message678292.html -- Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kidshttp://www.missingkids.com/ |
|
 dadkinsCan you do Blu?Premium,MVM join:2003-09-26 Hercules, CA kudos:18 | reply to Dustyn Thanks Steele Wolf! So far so good!  |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 Reviews:
·Rogers Hi-Speed
1 edit | reply to Name Game Thanks. 
Microsoft (supposedly) has patched the issue "THEIR WAY". However, Grey Magic, along with Spybot S&D still acknowledge that the DSO exploit remains to be seen as an ongoing issue. Even AFTER the MS FIX. It's just some bad entries in the registry that need cleaned up. (altered) -- "A man can tell a thousand lies, Ive learned my lesson well, Hope I live to tell the secrets I have learned, till then, It will burn inside of me..." ~ Madonna |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 Reviews:
·Rogers Hi-Speed
| reply to dadkins 
I told ya!  I'm so happy it worked.  |
|
 Name GamePremium join:2002-07-07 North Myrtle Beach, SC kudos:6 | reply to Dustyn said by Dustyn: Thanks. 
Microsoft (supposedly) has patched the issue "THEIR WAY". However, Grey Magic, along with Spybot S&D still acknowledge that the DSO exploit remains to be seen as an ongoing issue. Even AFTER the MS FIX. It's just some bad entries in the registry that need cleaned up. (altered)
It is not an on going issue..no matter what they (Grey Magic) acknowledge. 
When you find someone that is patched and has been exploited..let us know. -- Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kidshttp://www.missingkids.com/ |
|
 Name GamePremium join:2002-07-07 North Myrtle Beach, SC kudos:6 1 edit | reply to Dustyn
Also FYI for the Internet..
»www.greymagic.com/security/advis···m001-ie/
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] Change the value of "1004" (DWORD) to 3.
Then read Microsoft's KB article:
How to Enable the My Computer Security Zone in Internet
Options
»support.microsoft.com/?kbid=315933
This tells you how to add My Computer to the Security tab of Internet Options. Doing this lets you modify the security for the My Computer security zone (zone 0) because it won't be hidden anymore (by changing the Value Name "Flags" from a Value Data of "21" to "47").
The "1004" Value Name mentioned in the article from greymagic.com is the "Download unsigned ActiveX controls" setting you can now see in the My Computer security zone. The suggested value of 3 for this setting disables it. Mine was already set to 3 so I don't know if it got set by using Spybot or AdAware to fix the DSO exploit or if Windows XP, IE6, or a Windows Update set it to 3 (disabled).
I don't know why Microsoft decided to use numbers, like 1004, for Value Names of the settings within a security zone rather than something useful, like "Download unsigned ActiveX controls". When you find articles like greymagic.com's, and many others, just telling you to alter the value of an item named "1004", the first thing I start to wonder about is what the hell is a "1004" item.
And that of course you can set yourself in any IE by putting a dot in the disable "Download unsigned ActiveX controls" to give it a value of 3.
 -- Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kids »www.missingkids.com/ |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 4 edits | reply to Name Game If you believe it's no longer an issue, cool.
That is interesting info about the hidden My Computer zone.  |
|
 Name GamePremium join:2002-07-07 North Myrtle Beach, SC kudos:6 | said by Dustyn: If you believe it's no longer an issue, cool.
That is interesting info about the hidden My Computer zone. 
Well that was good info you posted..but i am sure spybot will fix their thingie in the next update..but in anycase I am sure you are OK -- Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kidshttp://www.missingkids.com/ |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 Reviews:
·Rogers Hi-Speed
2 edits |  One more thing I need to ask... is it a good idea to REVEAL the "My Computer" zone for Internet Explorer 6 in Windows XP Pro? I know I would have to make a registry change just as you mentioned to reveal the zone.
Why does Microsoft hide it in the first place? For security reasons? Have you revealed your "My Computer" zone?
Are there any other options that could/should be tweaked for that zone if I decided to reveal the zone? I'm just wondering about if I decided to REVEAL this hidden zone, if it would change anything or mess up something?
Thanks... a lot of questions I know so thanks for your (or anyones) patience! 
~Steele Wolf~  -- "A man can tell a thousand lies, Ive learned my lesson well, Hope I live to tell the secrets I have learned, till then, It will burn inside of me..." ~ Madonna |
|