republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Avira finds hidden registry entries
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
AVG 8.0 Web Shield necessary? »
« Anti-Spyware Coalition Probes Data Pimping (Phorm, NebuAd)  
AuthorAll Replies


bcastner
Premium,VIP,MVM
join:2002-09-25
Chevy Chase, MD
clubs:
·Verizon Online DSL


1 edit
reply to BlaZe X
Re: Avira finds hidden registry entries

Since there is no reference to a PE type of file, the entry is harmless.

It looks to me to be a lookup table. For example, I might use the registry as a scratchpad to hold configuration settings.

It most assuredly is not a rootkit reference, and most assuredly is not an active threat. There is not there, there. The fact that it is hidden is the only interesting thing about it; but there is nothing particularly interesting about that either. If I was using the registry to record, say GUI settings, I likely would hide it so that all those who love to run registry cleaners did not zap the parameter lookup table storage area.

Without a PE reference, there is no harm and no foul.

Take the CLSID: {EB763CD6-EB61-CF33-466E-3849D06F1F61}
And use that value to search HKLM and HKCU to see if there are additional entries that lead to something intelligible.

--
============
MS-MVP 2004 - -2008, ASAP Member
Users Helping Users


BlaZe X

join:2001-08-07
Brooklyn, NY
I've searched for that value, there are no other entries that point to anything. I will take your word that its probably not a rootkit and i'm just being a little too paranoid about it. thanks for the help.


Trel
Good Evening
Premium
join:2002-10-08
Hillsborough, NJ

reply to bcastner
said by bcastner See Profile :

Since there is no reference to a PE type of file, the entry is harmless.

It looks to me to be a lookup table. For example, I might use the registry as a scratchpad to hold configuration settings.

It most assuredly is not a rootkit reference, and most assuredly is not an active threat. There is not there, there. The fact that it is hidden is the only interesting thing about it; but there is nothing particularly interesting about that either. If I was using the registry to record, say GUI settings, I likely would hide it so that all those who love to run registry cleaners did not zap the parameter lookup table storage area.

Without a PE reference, there is no harm and no foul.

Take the CLSID: {EB763CD6-EB61-CF33-466E-3849D06F1F61}
And use that value to search HKLM and HKCU to see if there are additional entries that lead to something intelligible.

What do you mean when you say PE? I'm not familiar with that term in this context.


bcastner
Premium,VIP,MVM
join:2002-09-25
Chevy Chase, MD
clubs:
PE = "Portable Executable"
»en.wikipedia.org/wiki/Portable_Executable

Sorry for the use of jargon.
Forums » Up and Running » Security » SecurityAVG 8.0 Web Shield necessary? »
« Anti-Spyware Coalition Probes Data Pimping (Phorm, NebuAd)  


Friday, 27-Nov 22:38:11 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [121] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [70] TiVo Sees Record Customer Losses
· [68] In-Flight Internet Headed For Bumpy Landing?
· [63] Verizon CEO: Hulu Will Be Dead Soon
· [60] Thanksgiving Open Thread
· [38] EFF Wages War On Fine Print
· [38] ICANN Slams DNS Redirection
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· Newegg Black Friday Sale started [Users Find Hot Deals]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· 5 hour energy for diabetic [General Questions]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Speedtest server [TekSavvy]