Killing asp Trojans ---- disabling ADODB. STREAM

Source: Internet
Author: User

Iceberg
How to disable ADODB. STREAM
I have seen many web Trojans use this to list file directories. Some ASP Trojans use CLASSID to create Script objects,
If you know how to ban this object, you should be able to block the ASP Trojan completely,
Like SHELL execution is disabled
-------------------------------------------------------
Obtain the CLASSID based on the value of HKEY_CLASSES_ROOTADODB.StreamCLSID,
On my XP server, it should be the same on each host.

Find the dll corresponding to this ActiveX according to the value of HKEY_CLASSES_ROOTCLSID \ InprocServer32.
My XP is C: Program FilesCommon FilesSystemadomsado15.dll

Then regsvr32/s/u "C: Program FilesCommon FilesSystemadomsado15.dll"

So we uninstalled ADODB. STREAM.
---------------------------------------------------------
Your method is obviously feasible, but it will unload the entire ado (probably ).
If there are some ado applications on the machine, problems may occur.

If HKEY_CLASSES_ROOTADODB.StreamCLSID is deleted, OK ????
The dll is retained better.
---------------------------------------------------------
What is the relationship between the ASP Trojan running on the server and the IE patch?
ASP trojan uses FSO, ADODB. STREAM, and a DICTIONARY script object. I think the most important thing is that the first two are not the first two objects. Is there a way for ASP Trojan to run?
--------------------------------------------------------
Disabled ??
My 2000sp4, xp sp1, and xp sp2 can all use adodb. stream.
Probably, it is not allowed to be called by IE, even if the security level is reduced.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.