StatCounter User Forum  
StatCounter Free web tracker and counter

Go Back   StatCounter User Forum > Webmaster > Lounge (non-StatCounter related topics here!)

Reply
 
Thread Tools Display Modes
  #1  
Old 09-28-2005, 02:17 AM
howard howard is offline
Senior Member
 
Join Date: Jun 2005
Location: Eureka, California
Posts: 657
Default Spamware Plays Hide and Seek

Spamware Plays Hide and Seek:

For the past month, the Intenet Storm Center (ISC) has been issuing a warning about very long registry key values which malware can hide on your system, making detection difficult, even for AdAware and HijackThis.

The ISC is now offering a free registry search tool called LVNSearch, which will locate hidden registry key values which are too long to be anything but malware. Here are two articles. The download is on the second:
http://isc.sans.org/diary.php?date=2005-08-24
http://isc.sans.org/diary.php?date=2005-08-25

Although the ISC says Autoruns from SysInternals will not catch all these long file names, it will catch some, and it will do other things. Autoruns and its command line partner, Autorunsc, works on Win XP systems, and is available for free download here:
http://www.sysinternals.com/utilities/autoruns.html

LVNSearch is in exe format and Autoruns is a zip file. They are both small, and download fast.

----
Reply With Quote
  #2  
Old 09-28-2005, 03:29 AM
jonra01 jonra01 is offline
Master Member
 
Join Date: Feb 2005
Location: Mississippi
Posts: 3,636
Default

I downloaded this utility and ran it. I found some things I didn't know were loading. These are things that didn't show up in hijackthis. It works very well. I like it.
__________________
John
Reply With Quote
  #3  
Old 09-28-2005, 03:54 AM
webado's Avatar
webado webado is offline
Moderator
 
Join Date: Apr 2004
Location: Montreal, Quebec, Canada
Posts: 28,145
Default

Well, what am I finding on that second page for the download?

Quote:
Sorry. The page you requested could not be found.
So much for that then.
__________________
Christina
>>Forum Moderator<<

Please do not PM me for support. The forum is here for that.
Reply With Quote
  #4  
Old 09-28-2005, 05:06 AM
howard howard is offline
Senior Member
 
Join Date: Jun 2005
Location: Eureka, California
Posts: 657
Default

Christina,

Two thirds of the way down the page, just under:

FILE: (3584 bytes)

is the download link (the link ends in .exe)

I just checked the link - it's loading now. Must have been due to the storm or something - or maybe they have scumware they don't know about.. hehe

Howard
__________________
HumSites uses StatCounter
Reply With Quote
  #5  
Old 09-28-2005, 05:09 AM
webado's Avatar
webado webado is offline
Moderator
 
Join Date: Apr 2004
Location: Montreal, Quebec, Canada
Posts: 28,145
Default

Hmmmm.... I'll try again then.

That's the one I was trying to get.



LOL! They had the link messed up with a
in it: http://isc.sans.org/LVNSearch.exe



Quote:
Searching HKEY_CLASSES_ROOT
Searching HKEY_LOCAL_MACHINE
Searching HKEY_USERS
Searching HKEY_CURRENT_CONFIG
Found 0 problematic values
Done!
So I guess I'm clean then
__________________
Christina
>>Forum Moderator<<

Please do not PM me for support. The forum is here for that.
Reply With Quote
  #6  
Old 09-28-2005, 12:11 PM
howard howard is offline
Senior Member
 
Join Date: Jun 2005
Location: Eureka, California
Posts: 657
Default

Quote:
Originally Posted by chrisooc
So I guess I'm clean then
I got the same result. Good thing we don't surf much.

Howard
__________________
HumSites uses StatCounter
Reply With Quote
  #7  
Old 09-28-2005, 03:29 PM
Sharron's Avatar
Sharron Sharron is offline
Moderator
 
Join Date: Feb 2005
Posts: 7,058
Default

It (LVNsearch) found something on my lap top. Dont' know what it means! HELP!

Searching HKEY_CLASSES_ROOT
Searching HKEY_LOCAL_MACHINE
Searching HKEY_USERS
HKEY_USERS\S-1-5-21-102005887-3956953012-760838127-1007\Software\Bradbury\TopStyle\3.0\SavedCombo\Fin dText\[img]Inventory,%20Purchasing%20and%20Procurement%20Serv ices%20and%20Solutions%20-%20Software%20for%20Small%20Businesses,%20by%20Out buy_files/taste7.jpg[/img]
<img src="Inventory,%20Purchasing%20and%20Procurement%2 0Services%20and%20Solutions%20-%20Software%20for%20Small%20Businesses,%20by%20Out buy_files
Searching HKEY_CURRENT_CONFIG
Found 1 problematic value
Done!


OUTBUY? what is going on?
Reply With Quote
  #8  
Old 09-28-2005, 03:43 PM
Sharron's Avatar
Sharron Sharron is offline
Moderator
 
Join Date: Feb 2005
Posts: 7,058
Default

Well I opened regedit and surprisingly enough there are several entries there related to websites I have worked on in the past.

Now I am trying to figure out how to backup my reg files. Can I just delete those files from the registry?
Reply With Quote
  #9  
Old 09-28-2005, 04:00 PM
rotarysteve rotarysteve is offline
Master Member
 
Join Date: Aug 2005
Location: Ohio
Posts: 1,501
Default

NO, gosh NO,

I mean you can, but the registry entry you entered, doesn't seem to point to any programs.

I believe that each file, jpg, .exe .php etc. has a registry entry.

You can really damage you computer if your not careful with the registry. I have messed with mine in the past and have been successful, but be very,very careful.

Steve
Reply With Quote
  #10  
Old 09-28-2005, 04:05 PM
rotarysteve rotarysteve is offline
Master Member
 
Join Date: Aug 2005
Location: Ohio
Posts: 1,501
Default

P.S.

You can make a copy of the registry, and you should do so before doing any edits. Also, I can't remember right now on the how, but if you do edits and the computer doesn't restart correctly, there is a way to restore the registry automatically, with out the back-up copy.

But, a further note is that every single file on your computer is in the registry, all of your bookmarked pages are in there, all of your preferences, EVERYTHING is in that registry.

Just be careful if you mess with it as you can really trash programs, etc....


Steve
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:27 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.