Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
All Other Software
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory monitor motherboard network operating system printer problem ram registry router slow software sound svchost.exe toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Software & Hardware > All Other Software >
Using SpywareBlaster to protect against Sony's rootkit

Reply  
Thread Tools
lotuseclat79's Avatar
Distinguished Member with 21,345 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
16-Nov-2005, 10:19 AM #1
Thumbs up Using SpywareBlaster to protect against Sony's rootkit
How to use SpywareBlaster Tools Custom Blocking button to install protection against Sony's rootkit:

Launch SpywareBlaster v 3.4 (install new release if necessary from:
http://www.javacoolsoftware.com/spywareblaster.html)

Click on Tools in left-hand panel
Click on Custom Blocking button
Click on Add item
Name the new item: SONY
Click Ok
Use copy/paste to Insert CLSID: {4EA7C4C5-C5C0-4F5C-A008-8293505F71CC}
Check the SONY Item box
Click Protect Against Checked Items button
Exit SpywareBlaster (its protection is passive)

Reference: StevieO post #4 in Thread Re: Sony Rootkit and blocking F-4I's ActiveX control CodeSupport CLSID at: http://www.wilderssecurity.com/showt...591#post608591

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction
between a mere artisan or specialist and a real seeker after truth. - Einstein 1944
Imagination is more important than knowledge. - Einstein
Stoner's Avatar
Account Disabled with 47,328 posts.
 
Join Date: Oct 2002
Location: Dayton,Oh
16-Nov-2005, 11:27 AM #2
Good tip

Thanks
Digidave's Avatar
Member with 269 posts.
 
Join Date: Jun 2005
Experience: Intermediate
16-Nov-2005, 12:16 PM #3
Very nice!! Thanx!!
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
16-Nov-2005, 01:38 PM #4
Nice tip
jiml8's Avatar
Senior Member with 2,612 posts.
 
Join Date: Jul 2005
Experience: I've been at this for too long.
16-Nov-2005, 10:17 PM #5
Good tip.
CarlssonMB's Avatar
Senior Member with 823 posts.
 
Join Date: Oct 2004
16-Nov-2005, 10:50 PM #6
Nice

I think Microsoft Anti Spyware users are getting that protection in a new update
hewee's Avatar
Computer Specs
Distinguished Member with 57,923 posts.
 
Join Date: Oct 2001
Location: *Random People Pleaser***Sacra
Experience: Having fun
17-Nov-2005, 03:28 AM #7
Thanks I just added that to my list.
JohnWill's Avatar
Computer Specs
Distinguished Member with 110,212 posts.
 
Join Date: Oct 2002
Location: South Eastern PA, USA
Experience: Advanced age & experience
17-Nov-2005, 04:50 PM #8
I do love it when monumentally stupid corporations get hammered with something like this.
hewee's Avatar
Computer Specs
Distinguished Member with 57,923 posts.
 
Join Date: Oct 2001
Location: *Random People Pleaser***Sacra
Experience: Having fun
18-Nov-2005, 06:27 AM #9
Like to see a big class action where we win big bucks.

Make sony and others think twice next time they want to do anything like this to are PC's.
lotuseclat79's Avatar
Distinguished Member with 21,345 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
18-Nov-2005, 08:04 AM #10
All,

I just ran across the Microsoft Security Response Center Blog which contains an important addition to my first post in this thread - an additional CLSID entry to make like the previous one:

Add: {80E8743E-8AC5-46F1-96A0-59FA30740C51}

to the previous entry. You can probably name it something like SONY1.

-- Tom


Reference: http://blogs.technet.com/msrc/

Hello readers, Mike Reavey here.

There has been a fair amount of attention around the ”Sony XCP software” over the last many days. As you may know from the anti-malware blog, Windows Defender and Windows AntiSpyware Beta have included detection and removal for the rootkit component of this software. However, there are also some questions regarding the Disabling ActiveXActiveX control that was released by Sony to allow the removal of the rootkit. It's been reported that this ActiveX control contains vulnerabilities. We wanted to remind customers that they can block any specific ActiveX control from running in Internet Explorer themselves. To do this, all that’s needed is setting a registry key
entry called a “kill-bit.” Information on how to do this is in the following KB: http://support.microsoft.com/kb/240797. Our investigation shows that this ActiveX control uses the CLSIDs of {80E8743E-8AC5-46F1-96A0-59FA30740C51} and
{4EA7C4C5-C5C0-4F5C-A008-8293505F71CC}. We'd like to remind customers that while they need to be careful when editing the registry, the kill-bit mechanism can help protect them from any risks associated with this ActiveX control. We’ll continue to monitor this issue and provide recommendations as they become available.
-Mike

*This posting is provided "AS IS" with no warranties, and confers no rights.*
posted Thursday, November 17, 2005 9:09 PM by stepto (Comments Off)
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction
between a mere artisan or specialist and a real seeker after truth. - Einstein 1944
Imagination is more important than knowledge. - Einstein
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 12:17 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.