It is currently Tue Sep 01, 2026 4:32 pm


DSO Exploit Vs. DSOStop2

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

DSO Exploit Vs. DSOStop2

Postby goodtaste » Thu Jul 08, 2004 1:32 am

Hi Brad!
GeekGirl told me to come to you for this. So, here I am. A few days ago I got re-infected again (inspire of having a firewall, Norton Antivirus, SpywareGuard and SpywareBlaster.) I came to realize the attacks were coming through my emails. GeekGirl and others adviced me and I followed as well as I could. Now I'm not using my view pane, etc. But I still have DSO Exploit. Now, yesterday, after getting an error, I looked around for some technical advice and downloaded DSOStop2. Unpacked it well, followed the instructions. I thought it would take care of the problem. I crashed.
This morning, the machine didn't want to boot up, it froze and gave me a bloe screen. I got the impression DSOStop2 and DSO Exploit are having a brawl. One is trying to get rid of the other. HijackThis expired, but GeekGirl told me to download it again. So here's my log. Do you see something? I can't tell a difference.

Logfile of HijackThis v1.98.0
Scan saved at 5:24:02 PM, on 7/7/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKUFIND.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\HPZTSB05.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER PROFESSIONAL\POPUPSTOPPERPROFESSIONAL.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb05.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER PROFESSIONAL\POPUPSTOPPERPROFESSIONAL.EXE"
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O21 - SSODL: AUHook - {BCBCD383-3E06-11D3-91A9-00C04F68105C} - C:\WINDOWS\SYSTEM\AUHOOK.DLL

I hope all these adventures are really schooling me!

One more question. You mentioned Panda. I went to their website and looked around. You cannot have two of those can you? Is either Norton or Panda, not both, right?

Thanks for your help as always! :cool:
http://www.ieasysite.com/Delicioso
Mediterranean/Caribbean-style cooking for vegans and vegetarians
http://www.frontiernet.net/~rexfam
Great Christian encouragement for cloudy days.
User avatar
goodtaste
Geek
Geek
 
Posts: 35
Joined: Tue Jun 15, 2004 1:00 am
Location: USA

Thanks given:0
Thanks received:0
Top

Postby brad » Thu Jul 08, 2004 1:41 am

Give me a few........ I'll get back
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

DSO Exploit Vs. DSOStop2

Postby goodtaste » Thu Jul 08, 2004 1:46 am

Thank you!!!!
http://www.ieasysite.com/Delicioso
Mediterranean/Caribbean-style cooking for vegans and vegetarians
http://www.frontiernet.net/~rexfam
Great Christian encouragement for cloudy days.
User avatar
goodtaste
Geek
Geek
 
Posts: 35
Joined: Tue Jun 15, 2004 1:00 am
Location: USA

Thanks given:0
Thanks received:0
Top

Postby robbro » Thu Jul 08, 2004 1:53 am

DSO exploit is harmless and think they are going to fix it on the new spybot update says something about it on this site if you want to look http://forums.net-integration.net/index ... 28&t=15308 sorry if it dont help but dnt think its any harm to ur pc anyways,Rob. opps and here http://forums.net-integration.net/index ... opic=17159 soz if i butted in :S u was talking to brad and found another link that says ignore it too http://www.majorgeeks.com/vb/archive/index.php/t-35471.
User avatar
robbro
Executive Geek
Executive Geek
 
Posts: 751
Joined: Sun Jan 18, 2004 1:00 am
Location: UK , London

Thanks given:0
Thanks received:0
Top

Postby brad » Thu Jul 08, 2004 11:04 am

brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby Herm862001 » Thu Jul 08, 2004 5:45 pm

User avatar
Herm862001
Senior Geek
Senior Geek
 
Posts: 101
Joined: Wed Apr 14, 2004 1:00 am
Location: Pa

Thanks given:0
Thanks received:0
Top

DSOStop2 Vs. DSO Exploit

Postby goodtaste » Fri Jul 09, 2004 1:24 am

http://www.ieasysite.com/Delicioso
Mediterranean/Caribbean-style cooking for vegans and vegetarians
http://www.frontiernet.net/~rexfam
Great Christian encouragement for cloudy days.
User avatar
goodtaste
Geek
Geek
 
Posts: 35
Joined: Tue Jun 15, 2004 1:00 am
Location: USA

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Fri Jul 09, 2004 3:24 am

Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron