Malware may hide in Windows registry

Discussion in 'News' started by tripwire45, Aug 30, 2005.

  1. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287

    Malware may hide in Windows registry



    Security experts have found a vulnerability in Windows that could allow malware to lurk undetected in long string names of the Windows Registry. The weakness is caused by an error in the Windows Registry Editor Utility's handling of long string names. A malicious program could hide itself in a registry key by creating a string with a long name, which would allow the malicious string and any created after it in the same key to remain hidden. Keys are stored in the Windows Registry, which saves a PC's configuration settings.

    For the rest of the story, click Here
     
    Certifications: A+ and Network+
porta2_tags:

Comments

    1. ffreeloader
      ffreeloader
      The bit about the underlying architecture of 98 being kept isn't true. You do have to keep a licensed copy of 9x and a key around. I have an upgrade copy of Win2K and I've completely blown away my Win 2K install several times. All that happens on a re-install after a disk format is that the Win 2K install asks to see the 98 disk and key. Once it is shown that it installs Win 2K on a blank hard drive with no underlying 98 system whatsoever.
    2. Phoenix
      Phoenix
      Freddy, my mistake for not splitting my post up a tad better
      I was refering to an 'in place' upgrade from say, 98 to 2000, or 2000 to xp, it keeps alot of your old registry and file structure the same so that it doesnt break all your apps (the reason your upgrading) ofcourse this migrates any problems you had with you!

      The media is almost identical bar the previous CD check as you mentioned :)
      me not making myself clear again as usual :)
    3. Bluerinse
      Bluerinse
      Missy I doubt that a computer running Windows 98 will have sufficiently powerful hardware to run Windows 2000 or XP. Windows 2000 is a very stable operating system too, it is far better than XP home and IMHO just as good as XP Pro. I use it on my laptop because it will run on a P3 700 without slowing it down. Unlike XP which is a resource hungry beast. Oh and from experience upgrade versions of operating systems can perform a clean install or upgrade the previous operating system. If you chose to do a clean install I don't think there is a jot of difference whether you use an upgrade CD or the so called full version.

      OEM versions should only be sold with hardware that qualifies ie a new computer etc. Buying an OEM version is not legal in this instance.

      OEM (Original Equipment Manufacturer) products are to be distributed in the following manner:
      a. OEM versions of Microsoft Operating Systems should be distributed with a fully assembled computer system or non-peripheral computer hardware component. A fully assembled computer system consists of a least a central processing unit, a motherboard, a hard drive, a power supply and a case.

      Pete
    4. Phoenix
      Phoenix
      Pete,
      I beg to differ on that final point mate
      I cant recall the exact article, but recent license changes meant that OEM versions could be sold, but had more limitations on the license than a full retail copy
      I know from experiance that we abide quite strictly to licensing terms at work, and we buy OEM licenses for the most part, They can only be installed onto a single system, and are non transferable, also I believe (could be wrong) that they are upgrade only licenses, ie you must of had a full version of an OS previously

      Like i said I cant recall the exact article I read pertaining to this, and so take it with a pinch of salt
      but we passed our software audit with flying colours and we do this at work, as well as the numerous companies in the UK now selling OEM copies, who have other ties to MS in the way of software and hardware distribution (were not talking ebay here)

      Worth delving into a bit more, ill have a looksie
    5. ffreeloader
      ffreeloader
      This I agree with. I'd never do another in-place upgrade from 98 after the the two I've done. I never could get several apps to work correctly afterwards, and what's worse trying to upgrade FAT32 to NTFS on a system partition is a nightmare just waiting to happen. I know several people who say they have done it successfully, but I've tried it twice, and it's been a disaster both times.
    6. Bluerinse
      Bluerinse
      No worries Ryan, let me know what you find. That snippet comes from a doc I recently downloaded off the Microsoft site. It is their text not mine :rolleyes: I will upload it as an atachement so you can read the whole thing...

      Pete

      Attached Files:

    7. Missy
      Missy
      Trip I managed to download 7zip you recommended last night, but when i started to download 'hijackThis' it said it couldn't find winzip32.exe, so i went into my zip file and tryed to open them but it say i need to put a disk in, I dont think they are active.
      So the question do i have 'winzip32.exe' because all my winzip are not active, and why cant 'merijn.org' see my new 7 zip, which i have checked and is in Programs ???
      Missy
    8. Phoenix
      Phoenix
      might be easier if you just re download winzip as the file associates seem to be to that product, and having never used 7zip i cant really talk you though re association

      http://www.winzip.com/betawz.cgi

      beta 10 is out, and there are two versions, including a free one,
      just scroll to the bottom of that page and hit 'download'
    9. tripwire45
      tripwire45
      What he said. :)
    10. Missy
      Missy
      I'm on my second download as i got disconnected when it 80% :-( have removed 7zip so I'll wait and see what happens 'when' download is complete.
    11. Missy
      Missy
      Well Iv'e finally done it, downloaded winzip then 'hijackthis'.
      Have done a full scan and nothing turned up, thank god.
      Just got to read the 5 page doc to tell me how to use it. I know RTFM :-)
      So Cheers to you all. :-)
      Missy
    12. ffreeloader
      ffreeloader
      Missy,

      Post the log. HijackThis isn't going to list out things and flag them as spyware. It doesn't work like a Adaware or an antivirus program.
    13. dee1810
      dee1810
      Hey ffreeloader

      After Missy has sent you her log, please can I send you my log?

      I have been eagerly waiting to see what kind of things i am supposed to be looking for exactly?
    14. tripwire45
      tripwire45
      dee...why don't you start a separate thread in the Security & Viruses forum and post your log there for all of us to take a look at. I don't think ffreeloader meant for you or Missy to send your logs to him personally. I believe the intent was to post them publically in the forums (just do a copy and paste) so we can take a look at the output.
    15. dee1810
      dee1810
      Sorry - Oh how stupid of me!!!

      I completely didn't think about it, did I! Sorry everyone



      ffreeloader - like, I might think you have time :eek: :oops:
    16. tripwire45
      tripwire45
      No worries. :)

    Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.