Re: What are these "Impersonate" keys about?



SueInCincy wrote:

As to the Why, please see the post in the similar question I just made today.

OK. Those particular files (and registry entries) are safe; they're a normal part of Windows. (Of course, malware could also create registry entries that would look similar, but these ones are OK.)

In this context, "Impersonate" is a technical term referring to a normal part of the way the operating system works - if you're interested there's some information about it here:

<http://en.wikipedia.org/wiki/Token_%28Windows_NT_architecture%29>

As to your wider problem, I did have one other thought - theoretically it is possible for a compromised USB or firewall device to take control of a computer simply by being plugged into it. I think you mentioned having an external disk drive, and you probably have various other external devices too; perhaps one of them has been compromised?

If you can find any evidence that this is the case, there will almost certainly be quite a number of security researchers interested to examine the device in question; if there's malware out there actually using this vulnerability people will want to know more about it. There have been no known attacks, but the vulnerability has been known about for several years.

Harry.
.



Relevant Pages

  • Re: Need substitutes for AVG and AdAware
    ... exploiting a vulnerability in the way certain file types are handled. ... The point being that when malware is presented to you in such an obvious ... their win-98 system, that's hardly a reason to "upgrade" to XP just so ...
    (alt.comp.anti-virus)
  • Re: Need substitutes for AVG and AdAware
    ... ...or by exploiting the "human nature" vulnerability of users. ... that trojans are probably the way that *most* malware gets executed. ... to execute those from people they *do* know. ...
    (alt.comp.anti-virus)
  • Re: A Hijacking Problem
    ... There is NO RootKit in this. ... | indentified malware has already downloaded and installed a lot of other ... installation of WinAntivirus Pro, ... "There is a security vulnerability from the Blackworm virus. ...
    (alt.computer.security)
  • Re: Need substitutes for AVG and AdAware
    ... exploiting a vulnerability in the way certain file types are handled. ... was the last time your AVG detected a virus on your system? ... Do you think you can handle malware that comes ... but FX 2.0 lacks continuing vulnerability fixes. ...
    (alt.comp.anti-virus)
  • Re: Ridding yourself of FTP malware
    ... > frequently installed by various different kinds of malware. ... > but any vulnerability that allowed the ... > If you don't apply the patches, there's not much more we can do. ... > certainly can't force all the machines running Windows to load a particular ...
    (microsoft.public.security)