Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Windows Registry - Nasty Games of Hide & Seek

ISC LogoFor the past 2 days, the Internet Storm Center (ISC) shared a warning on long registry key values that can be made hidden from REGEDIT by malware making removal more complicated than in the past. 

The ISC is offering a free Registry Search Tool.  This neat new tool will locate the registry key values greater than 255 characters in length.

Windows Registry - Nasty Games of Hide & Seek
http://isc.sans.org/diary.php?date=2005-08-24
http://isc.sans.org/diary.php?date=2005-08-25

ISC Registry Search tool -- locates long key values
http://isc.sans.org/LVNSearch.exe

QUOTE: We have started to see some possible reports of malware which utilizes this concealment technique in the wild.  Products that have been reported to be able to query/report/delete/etc these keys:

AppSense Environment Manager
HiJackThis v1.99.1 (SCAN function)
HiJackThis v1.99.2 (in development)
Stillsecure SafeAccess
Sysinternals Autoruns (mixed reports)
Regedt32 (Win2k)

Comments

clonedvd said:

Load balancing solutions for servers optimize the operations that fall within the design and parameters of the server. The solutions ensure the availability of quality application twenty four hours a day, seven days a week. The solutions ensure efficient

# March 22, 2008 8:39 PM

Registry Cleaner said:

Mark Russinovich\'s technical blog covering topics such as Windows troubleshooting, technologies and security. / p This Blog About Email Syndication RSS 2. 0 Atom 1. 0 Search Go Tags No tags have been created or used yet. Archives February 2008 (1) January

# July 8, 2008 7:09 PM

program pro game rip said:

I finally got around to fixing the errors that were in this blog caused by using MS Word as my editor, (I finally got around to looking at my blog and seeing them). It seems, and I should have known this, that the curly double close quote isn\'t compatible

# July 19, 2008 11:10 AM