Reports: Long Registry Names Could Hide Malware | eWeek

Reports: Long Registry Names Could Hide Malware

Écrit par
Larry Seltzer
Larry Seltzer
Aug 29, 2005
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Reports on the Full-Disclosure research list and by the SANS Internet Storm Center indicate a common bug in software that interacts with the Windows registry. The bug could allow malicious programs to hide values there, obscuring evidence of their presence on the system.

The problem involves registry values with names between 256 and 260 characters long, although there may be additional problems with names at the outer limits of length restrictions for Microsofts and other registry editors. As the Full-Disclosure report indicates, the existence of such a key can hide not only its own presence, but also other values in the same key.

The Full-Disclosure report demonstrated the effect in the Microsoft Registry editing program that comes with Windows. Further research by the Internet Storm Center indicated several other programs, including security-related programs, are similarly-incapable of seeing or modifying these values.

/zimages/6/28571.gifClick hereto read more about rootkits spawning new malware.

The main security concern relates to the “Run” keys, which are specific keys that contain the names and locations of programs that Windows should load at boot- and login-time. By using a value name greater than 256 characters, a malicious program could possibly hide its presence from security software, which usually checks these keys for malicious use.

The use of such a key could not stop the security software from scanning the file system and finding the programs being loaded through these registry keys, and it could not stop intrusion prevention and other behavior-monitoring software from taking note of the fact that a value was being written to the Run keys, an action that usually raises red flags.

/zimages/6/28571.gifClick hereto read more about the coming of malware.

The Internet Storm Center notes many programs that cannot read the keys, including Lavasofts Ad-Aware (no version specified), the Microsoft AntiSpyware Beta and WinDoctor v. 7.00.22. Other tools, including other versions of Microsoft registry tools, behave appropriately.

Advertisement

The Internet Storm Center page also includes links to a free tool that searches a computers registry for value names that could cause the problem noted in the reports.

/zimages/6/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.