Re: CWS/DSO Exploit

From: Bruce Chambers (bruce_a_chambers_at_h0tmail.com)
Date: 10/01/04


Date: Thu, 30 Sep 2004 20:45:25 -0600

Mark wrote:
> Sorry if this goes through twice but I don't think it did
> the first time I tried to send it. Does anyone know how
> to get rid of this CSW thing???? I had it on my desk top
> PC about a year ago and eradicated it with a malware
> program called CWS Shredder, in conjunction with SpyBot
> and Adaware (can't even install Adaware at this time).
> SpyBot finds it and deletes it (always finds 5 incidents
> of DSO Exploit and 2 of CoolWWWSearch, and yes I am
> immunizing), but it's back within like five minutes.
> This is no only a home page hijacker but it also does not
> allow certain pages to load (can't check my Hotmail, for
> example). I did a search for CWS Shredder and it seems
> the author has given up on defeating this thing and no
> longer offers updates. Does anyone know of another
> program I might want to try to get rid of this thing? TIA
>
> Mark

    The DSO exploit was patched long ago by IE Cumulative Update
MS02-015, in March of 2002. If you've installed this specific patch,
or any subsequent IE Cumulative Updates, or IE Service Pack 1, you're
safe. It would appear that the latest version of Spybot S&D is only
checking for Internet zone settings in the registry that could be used
as work-around protection, and not for the presence of any corrective
patches. Hopefully, the makers of Spybot will soon fix this bug.

 MS02-015 March 28, 2002 Cumulative Patch for Internet Explorer
http://support.microsoft.com/default.aspx?scid=kb;EN-US;319182

    If you like, you can test your system for this particular
vulnerability at this web site:
http://www.grey.com/security/advisories/gm001-ie/

    The makers of SpyBot S&D have acknowledged the problem and will
fix it on their next update:
http://www.safer-networking.org/index.php?page=paragraphs&detail=currentfaqs

    In the meantime, in SpyBot S&D, click Mode > Advanced > Settings >
Ignore Products > Security > DSO Exploit, to turn off the false alarm.

    Some people have reported that the Spybot Detection rules dated 30
Aug 04, when used with SpyBot S&D 1.3, will fix this problem.
However, I've had inconsistent results with that particular detection
update; sometimes it reads clean, then later it will once again find
the DSO problem, and then it will read clean again, all on the same
machine, with no other changes made.

-- 
Bruce Chambers
Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html
You can have peace. Or you can have freedom. Don't ever count on 
having
both at once. - RAH


Relevant Pages

  • Re: SpyBot Search & Destroy Update 31/12/03
    ... I have gone to it a few times since I saw your post and Spybot ... this is the first time this as ever happened. ... "siljaline" wrote in message ... > latest updates by using the online> update feature. ...
    (microsoft.public.security)
  • Re: trojansssssss
    ... Spybot S&D has an install routine - run ... First update it ("Search for updates"), ... Spyware Warrior: ... Don't install software based upon advice ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Updates from Tunica?
    ... Either way, I want to find somewhere that updates, ... > that is a little more familiar with the players. ... MARK HANNA $ 135,000 ... 74 JOHN D'AGAOSTINO $ 27,000 ...
    (rec.gambling.poker)
  • Re: Off Topic Post
    ... Mark, Bruce has it right. ... There is no code on the default blank page beyond the HTML ... My suggestion is that you deny the registry change and immediately ... as well as the Spybot check. ...
    (microsoft.public.access.forms)
  • Re: Brief poll, your preferred spyware?
    ... You can still get the updates. ... > HiJackThis (the ultimate spyware removal tool. ... >> widely known that AdAware and Spybot are the current big two...and ... >> McAfee now has one. ...
    (microsoft.public.windowsxp.general)

Loading