Garbage Entry

drunkardswalk_at_earthlink.net
Date: 01/31/04


Date: Fri, 30 Jan 2004 18:05:50 -0700

Some time back I ran across a registry entry on one machine under
HKLM\Software in which the key and all its subkeys were apparently garbage.
Now, two things immediately occurred to me. One, this might be a Trojan or
virus hiding itself; and two, it might not be garbage, but encrypted material,
possibly legitimate. I run with FIPS 140 enabled, and certificates set up
correctly, but don't have anything (so far as I know) encrypted under EFS.
Besides, EFS doesn't stash anything like this in the Local Machine hive, so
far as I'm aware, anyway.

Anyone able to give me a tell on this one? I know of no valid registry key
that looks like this. All of the subkeys are apparently garbage in both the
name and value sections. I exported the key and deleted it from the registry
with no apparent ill effects. I'd post the exported key for examination, but
not without knowing what its contents actually are, as you can all well
understand.

Thanks in advance for any help anyone can offer.

Reid Sweatman
Elder Orangutan what's in Charge of da Code Monkeys



Relevant Pages

  • Re: Spooler SubSystem App continuously crashing
    ... Since you did not install Lexmark printer, I modify the steps as following, ... If you use Registry Editor incorrectly, ... View the list of subkeys. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Spooler SubSystem App continuously crashing
    ... Since you did not install Lexmark printer, I modify the steps as following, ... If you use Registry Editor incorrectly, ... View the list of subkeys. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Spooler SubSystem App continuously crashing
    ... If you use Registry Editor incorrectly, ... View the list of subkeys. ... Verify that the Print Spooler service is running. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Spooler SubSystem App continuously crashing
    ... about Spooler SubSystem App when you start the computer. ... If you use Registry Editor incorrectly, ... Start Microsoft Windows Explorer, and then delete all the files and the ... View the list of subkeys. ...
    (microsoft.public.windows.server.sbs)
  • Re: Registry Editor
    ... Structure of the Registry ... The term hive describes a body of keys, subkeys, and values that is rooted ... Keys contain subkeys and entries. ...
    (microsoft.public.windowsxp.configuration_manage)