1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Trojan Horse Downloader.Agent.AS

Discussion in 'Security and Privacy' started by MinnesotaMike, 2004/12/14.

Thread Status:
Not open for further replies.
  1. 2004/12/14
    MinnesotaMike

    MinnesotaMike Geek Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,396
    Likes Received:
    3
    I was asked to help my son's friend with his XP system. He wanted the system reloaded, but I thought I'd clean it up first to see if that would help. While running scans, I found numerous viruses (7) and spyware (over 1000!). The Downloader trojan keeps popping up though. Well, it did. I had updated and ran AVG, Panda ActiveScan, HijackThis, Ad-Aware, and Spybot on their system (and each profile). I even installed their hard drive in my system and scanned with Norton's AV. I fixed/deleted everything that was recommended. Everything is coming up clean, but I'm afraid the nasty bugger will pop up again. Is there any way to verify that this trojan is gone? I want to make sure before I send it back. I would rather not have to reload the system to wipe this thing out. They are not very computer smart and I know I would end up putting all their settings back in, if they even remember what they were.

    One thing that does keep coming up, with Spybot. I have 5 entries for DSO Exploit. They are all listed as "Data Source object exploit ". It keeps fixing them and they are right back. The entries are:

    HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

    HKEY_USERS\S-1-5-21-2699212658-2020728613-4264678088-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

    HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

    HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3


    This system does have SP2 installed, if that matters. Any suggestions would be appreciated!

    Mike
     
  2. 2004/12/14
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Mike - the DSO Exploit was a glitch in Spybot. The problem is real but very minor and Spybot says it makes it go away but in fact the first release of v1.3 really didn't so you see it every time.

    They released v1.31 (beta I think) that took care of things but pulled that version. The v1.4 (also beta but stable from my experience and from what I read) is the way to go if you don't want to see the same 5 DSO Exploit entries poping up every time you run the app.
     
    Newt,
    #2

  3. to hide this advert.

  4. 2004/12/14
    WhitPhil

    WhitPhil Inactive

    Joined:
    2002/01/07
    Messages:
    599
    Likes Received:
    4
    If you are uptodate on your IE security patches, you don't have to worry about the exploits.
    And, you can make them go away in SpyBot by adding them to your ignore list.
     
  5. 2004/12/14
    MinnesotaMike

    MinnesotaMike Geek Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,396
    Likes Received:
    3
    Thanks for the replies! I won't worry about the DSO entries. Any thoughts on the trojan?

    Mike
     
  6. 2004/12/14
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Thoughts on the Trojan
    - I don't like any of them
    - I think it is probably, almost certainly, gone after the steps you've taken
    - Short of a format/reinstall I don't know of any way to be 100% certain it is gone
     
    Newt,
    #5
  7. 2004/12/14
    MinnesotaMike

    MinnesotaMike Geek Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,396
    Likes Received:
    3
    That's kind of what I figured, but it's nice to hear it from somebody else. Thanks!

    Mike
     
  8. 2004/12/14
    WhitPhil

    WhitPhil Inactive

    Joined:
    2002/01/07
    Messages:
    599
    Likes Received:
    4
    Ensure that all MS Security patches have been applied, and practice safe surfin'!
     
  9. 2004/12/14
    MinnesotaMike

    MinnesotaMike Geek Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,396
    Likes Received:
    3
    All patches have been applied. The second part, "practice safe surfing' ", is probably the culprit. It's hard to teach that to kids that aren't yours though. :( Maybe if I start charging, that will do the trick! :D
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.