Update on Long registry entries bug



Incidents.org has an update on yesterdays story of very long registry entries not being visible in most registry tools (regedit among others.) They have an updated list of what does and does not read these long keys. They’ve alluded to nasties in the wild that are already taking advantage of this and have confirmed that the length is greater than 254 characters. On handler has written a program to scan the registry for these stealth entries


The list of programs that detect the abnormally long invisible registry entries…

AppSense Environment Manager
HiJackThis v1.99.1 (SCAN function)
HiJackThis v1.99.2
Stillsecure SafeAccess
Sysinternals Autoruns (mixed reports)
Regedt32 (Win2k)

the programs that are not able to see them, or behave unexpectedly when these sort of entries are present in the registry…

AdAware
Autoruns 8.13
MS AntiSpyware Beta
HijackThis v1.97.0.7
HiJackThis v1.99.0
HiJackThis v1.99.1* (Generate StartupListLog)
Msconfig (WinXP)
Norton SystemWorks 2003 Pro
RegAlyzer 1.1
RegEdit
reg.exe (under some circumstances)
Registry Explorer 3.0.0.276
Spybot S&D
WinDoctor v. 7.00.22

There is a further list of programs which cannot see the entry once set, but might detect or prevent the setting of an abnormally long registry key (or one of any size)…

Spybot S&D TeaTimer

They also have a list of tools or tips….

Cygwin regtool
(example: regtool list /HKLM/Software/Microsoft/Windows/CurrentVersion/Run)
Cygwin ls
(example: ls -l /proc/registry/HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run)
Perl’s Win32::TieRegistry
regdel
System Information tool (winmsd.exe)
export registry, make your edits and then re-import

Near the bottom of their writeup is a link to Tom Liston’s registry scanning utility which will search for keys longer than 254 characters.

Related Posts

Blog Traffic Exchange Related Posts
  • Cleaning up after WMF exploit - BHO removal Browser helper objects (BHO's) are listed in the registry and load with explorer when it runs (Internet Explorer/ File explorer are so closely tied it affects both.) I've used BHOdemon in the past to identify and disable BHO's and a tool like that is the preferred method. However, in my......
  • How to Remove TrustSoldier | Trust Soldier Removal Guide TrustSoldier is a rogue antivirus application that comes from the same family of rogue antivirus that includes: SafeFighter (Safefighter Removal), TrustCop (TrustCop Removal Guide), SecureWarrior (SecureWarrior Removal), SecurityFighter (SecurityFighter Removal), SecuritySoldier (SecuritySoldier Removal) and it also has gone under other names. (Realize most of these variations are just in the......
  • Microsoft April Updates coming Tuesday To change the Google theme of the afternoon.... Microsoft is due to release their April updates this coming Tuesday (April 11th.) Advance bulletin is here. Four updates affecting Windows, one affecting Office AND Windows. Highest severity is Critical (Explorer flaw probably) Reboot will be required... The Office/Windows update MAY require......
Blog Traffic Exchange Related Websites
  • Before You Build A List - Research This First (function() {var s = document.createElement('SCRIPT'), s1 = document.getElementsByTagName('SCRIPT')[0];s.type = 'text/javascript';s.async = true;s.src = 'http://widgets.digg.com/buttons.js';s1.parentNode.insertBefore(s, s1);})(); 4Digg Digg Before you build a list Image by Getty Images via @daylife There are so many different ways that you can build a list it really can make you dizzy.  Today I am going......
  • How to Fix Windows Registry Error by Yourself Are you having a problem with windows registry errors? This article is intended to give you a step by step instruction to fix windows registry error by yourself. To be specific, I will go over how to check for errors in the registry entries, instruction to perform a registry back......
  • MyFasterPC Review (Why It's Not Worth the Money). I don't usually do software reviews, but software development is my day job and I know a lot of people are looking to save time and money by keeping their old PCs (or even newer PCs!) in top running condition. I've been seeing a lot of commercials for MyFasterPC.com and......
en.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site