Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Windows Vista
Weekly Brief
Daily Technology News
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: Windows BugsViruses & Worms

Is Malware Hiding in Your Windows Registry?

Security company says vulnerability could allow malicious software to lurk undetected.

Elizabeth Montalbano, IDG News Service

Tuesday, August 30, 2005 5:00 AM PDT
Recommend this story?

Security experts have found a vulnerability in the Windows operating system that could allow malware to lurk undetected in long string names of the Windows Registry.

According to a security advisory by Denmark-based IT security company Secunia, the weakness is caused by an error in the Windows Registry Editor Utility's handling of long string names. A malicious program could hide itself in a registry key by creating a string with a long name, which would allow the malicious string and any created after it in the same key to remain hidden, according to Secunia. Keys are stored in the Windows Registry, which saves a PC's configuration settings.

Secunia has confirmed that the vulnerability affects the "Run" registry key, according to the advisory. Malicious strings in this key will be executed when a user logs in to the PC.

Affected Systems

The vulnerability affects Windows XP and Windows 2000 and has been confirmed to exist on fully updated XP systems with Service Pack 2 and Windows 2000 systems with Service Pack 4, according to Secunia.

Microsoft issued a statement on the vulnerability saying it is investigating the weakness and is not aware of any malicious attacks that have exploited it.

Moreover, the company asserted that the vulnerability by itself could not allow an attacker to remotely or locally attack a user's computer. It could only be exploited if the computer had its security compromised in some other way or was already running malicious software.

In its advisory, Secunia provided several solutions to avoid exploitation of the vulnerability, one of which is to ensure that systems have up-to-date anti-virus and spyware detection software installed.

The security company also said it is possible to see the hidden registry strings with the "reg" command-line utility of the Windows Registry, and that the "regedt32.exe" utility on Windows 2000 is not affected by the weakness.


Recommend this story?
Related Searches: malware virus worm news windows

Comments
Latest News
Florida's attorney general said on Thursday the state was seeking to fine Verizon for violating service standards. 16-May-2008
The device, known as the Thunder, is to be sold exclusively through Verizon Wireless in the U.S. and Vodafone abroad. 16-May-2008
Hundreds of Grand Theft Auto IV fans eager to get their hands on a free copy of the game have been targeted by a Trojan virus. 16-May-2008
A security researcher has published a demonstration exploit that takes advantage of the download mechanism in Apple's Safari. 16-May-2008
A fourth unannounced game, being developed by Resident Evil creator Shinji Mikami, is also in the works. 16-May-2008
A flood of voracious ants is heading straight for Houston, taking out computers, radios and even vehicles in their path. 16-May-2008
Maps showing noise levels in towns across England were published on Friday in an attempt to reduce the disruption caused by factories, planes, trains and cars. 16-May-2008
Unveiled at the Konami Gamer's Night on Wednesday, Rock Revolution was confirmed for release on Xbox 360, PS3, Wii, and DS. 16-May-2008
According to NPD data released Thursday, Nintendo sold an incredible 714,000 Wiis last month. 16-May-2008
The former chairman and CEO of PurchasePro.com, a business-to-business software broker that died during the dot-com bust, has... 16-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)