<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: Avira finds hidden registry entries&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20375906</link>
<description></description>
<language>en</language>
<pubDate>Sat, 11 Feb 2012 06:08:24 EDT</pubDate>
<lastBuildDate>Sat, 11 Feb 2012 06:08:24 EDT</lastBuildDate>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20391966</link>
<description><![CDATA[BlaZe X posted : thanks for the link I have posted my log in castlecops. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20391966</guid>
<pubDate>Sat, 26 Apr 2008 17:18:39 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20390048</link>
<description><![CDATA[redwolfe_98 posted : blaze, here is a link to a forum at "castlecops" where "experts" can help you with analyzing the GMER scan-results:<br><br>&raquo;<A HREF="http://www.castlecops.com/f233-Rootkit_Revelations.html" >www.castlecops.com/f233-Rootkit_&middot;&middot;&middot;ons.html</A><br><br>alternatively, you could post in DSLReports' "cleanup" forum and see if any of the experts, there, have any suggestions.. here is a link for the forum:<br><br>&raquo;<A HREF="/forum/cleanup">Security Cleanup</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20390048</guid>
<pubDate>Sat, 26 Apr 2008 05:37:08 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20389786</link>
<description><![CDATA[BlaZe X posted : Hi redwolfe, I ran a scan with gmer and this is what it found for the registry portion:<br><br>---- Registry - GMER 1.0.14 ----<br><br>Reg             HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40                                                             <br>Reg             HKLM\SOFTWARE\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F1F61}\InProcServer32                                    <br>Reg             HKLM\SOFTWARE\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F1F61}\InProcServer32@oaklgcffoomoodagbbadblbhlbffjc     0x69 0x61 0x6C 0x65 ...<br>Reg             HKLM\SOFTWARE\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F1F61}\InProcServer32@naklmdmgnchnoppccdacnndjgjek       0x6A 0x61 0x69 0x65 ...<br><br>---- EOF - GMER 1.0.14 ----<br><br>So does this mean that avira is correctly flagging this entry and I should still ignore it? thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20389786</guid>
<pubDate>Sat, 26 Apr 2008 02:33:12 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20385860</link>
<description><![CDATA[redwolfe_98 posted : if the regkey, supposedly, is "hidden", i don't see how you were able to find it in the registry, unless it is not really hidden.. if it is not really hidden, then why did antivir flag it..<br><br>i would do a scan with "GMER" and see if it flags anything.. <br><br>i also think that you should discuss this issue in the avira forum, so that, if there is a problem with antivir's rootkit-scanner, it is brought to their attention..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20385860</guid>
<pubDate>Fri, 25 Apr 2008 13:15:21 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20381739</link>
<description><![CDATA[bcastner posted : PE = "Portable Executable"<br>&raquo;<A HREF="http://en.wikipedia.org/wiki/Portable_Executable" >en.wikipedia.org/wiki/Portable_Executable</A><br><br>Sorry for the use of jargon.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20381739</guid>
<pubDate>Thu, 24 Apr 2008 18:53:40 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20381343</link>
<description><![CDATA[Trel posted : <div class="bquote"><small>said by <a href="/profile/693977" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=693977');">bcastner</a>:</small><br><br>Since there is no reference to a PE type of file, the entry is harmless.<br><br>It looks to me to be a lookup table.  For example, I might use the registry as a scratchpad to hold configuration settings.<br><br>It most assuredly is not a rootkit reference, and most assuredly is not an active threat.  There is not there, there.  The fact that it is hidden is the only interesting thing about it; but there is nothing particularly interesting about that either.  If I was using the registry to record, say GUI settings, I likely would hide it so that all those who love to run registry cleaners did not zap the parameter lookup table storage area.<br><br>Without a PE reference, there is no harm and no foul.<br><br>Take the CLSID:  {EB763CD6-EB61-CF33-466E-3849D06F1F61}<br>And use that value to <b>search</b> HKLM and HKCU to see if there are additional entries that lead to something intelligible.<br><br> </div>What do you mean when you say PE?  I'm not familiar with that term in this context.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20381343</guid>
<pubDate>Thu, 24 Apr 2008 17:38:11 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20380751</link>
<description><![CDATA[BlaZe X posted : I've searched for that value, there are no other entries that point to anything. I will take your word that its probably not a rootkit and i'm just being a little too paranoid about it. thanks for the help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20380751</guid>
<pubDate>Thu, 24 Apr 2008 16:00:42 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20379220</link>
<description><![CDATA[bcastner posted : Since there is no reference to a PE type of file, the entry is harmless.<br><br>It looks to me to be a lookup table.  For example, I might use the registry as a scratchpad to hold configuration settings.<br><br>It most assuredly is not a rootkit reference, and most assuredly is not an active threat.  There is not there, there.  The fact that it is hidden is the only interesting thing about it; but there is nothing particularly interesting about that either.  If I was using the registry to record, say GUI settings, I likely would hide it so that all those who love to run registry cleaners did not zap the parameter lookup table storage area.<br><br>Without a PE reference, there is no harm and no foul.<br><br>Take the CLSID:  {EB763CD6-EB61-CF33-466E-3849D06F1F61}<br>And use that value to <b>search</b> HKLM and HKCU to see if there are additional entries that lead to something intelligible.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20379220</guid>
<pubDate>Thu, 24 Apr 2008 11:28:15 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20377688</link>
<description><![CDATA[Trel posted : <div class="bquote"><small>said by <a href="/profile/446800" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=446800');">BlaZe X</a>:</small><br><br><div class="bquote"><small>said by <a href="/profile/693977" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=693977');">bcastner</a>:</small><br><br>Open Regedit and navigate to:<br><br>HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F1F61}<br><br>What DLL or other program is referenced there?<br><br>The key is this value:  {EB763CD6-EB61-CF33-466E-3849D06F1F61}  I do not have a Google hit on it, but that is not definitive of anything.<br><br>Look with regedit under the root key above and see if you can find a reference to something that is searchable.<br> </div>There are no references to this when go to this key. Also trying to open InProcServer32 folder gives me an error - "cannot open InProcServer32: Error while opening key"<br><br><div class="bquote"><small>said by <a href="/profile/700992" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=700992');">Trel</a>:</small><br><br>Do you use Daemon tools?<br> </div>I do use daemon tools and i know it uses a type of rootkit technology but can they be related to these key? I have used sophos anti-rootkit scanner before and it leads to this key.: \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf40 which I know is related to daemon tools. <br> </div>I'm not sure, I just know Daemon Tools shows up in some scanners.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20377688</guid>
<pubDate>Thu, 24 Apr 2008 00:40:31 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20377610</link>
<description><![CDATA[BlaZe X posted : <div class="bquote"><small>said by <a href="/profile/693977" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=693977');">bcastner</a>:</small><br><br>Open Regedit and navigate to:<br><br>HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F1F61}<br><br>What DLL or other program is referenced there?<br><br>The key is this value:  {EB763CD6-EB61-CF33-466E-3849D06F1F61}  I do not have a Google hit on it, but that is not definitive of anything.<br><br>Look with regedit under the root key above and see if you can find a reference to something that is searchable.<br> </div>There are no references to this when go to this key. Also trying to open InProcServer32 folder gives me an error - "cannot open InProcServer32: Error while opening key"<br><br><div class="bquote"><small>said by <a href="/profile/700992" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=700992');">Trel</a>:</small><br><br>Do you use Daemon tools?<br> </div>I do use daemon tools and i know it uses a type of rootkit technology but can they be related to these key? I have used sophos anti-rootkit scanner before and it leads to this key.: \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf40 which I know is related to daemon tools. <div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20377610?c=1300552&ret=L2ZvcnVtL3IyMDM3NjQzMy54bWw%3D"><IMG class="apic" BORDER=0 TITLE="183975 bytes" WIDTH=600 HEIGHT=378 SRC="/r0/download/1300552.thumb600~f3ccdd27d2000e3f9255a7e3e2c48800/1.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20377610</guid>
<pubDate>Thu, 24 Apr 2008 00:16:33 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20376433</link>
<description><![CDATA[Trel posted : <div class="bquote"><small>said by <a href="/profile/446800" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=446800');">BlaZe X</a>:</small><br><br>Avira finds two hidden registry objects. Can they be possible rootkits? i tried a google search i haven't found anything on them. I also posted in the avira forums, I didn't really get much input about what it can be. They mentioned a software called studio 9 uses hidden registry entries but I never installed this software. What else could it be?<br><br>Heres what it finds: <br><br>Starting search for hidden objects.<br>HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F<br>1F61}\InProcServer32\oaklgcffoomoodagbbadblbhlbffjc<br>[INFO] The registry entry is invisible.<br>HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F<br>1F61}\InProcServer32\naklmdmgnchnoppccdacnndjgjek<br>[INFO] The registry entry is invisible.<br>'315899' objects were checked, '2' hidden objects were found.<br> </div>Do you use Daemon tools?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20376433</guid>
<pubDate>Wed, 23 Apr 2008 20:08:30 EDT</pubDate>
</item>

<item>
<title>Re: Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20376068</link>
<description><![CDATA[bcastner posted : Open Regedit and navigate to:<br><br>HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F1F61}<br><br>What DLL or other program is referenced there?<br><br>The key is this value:  {EB763CD6-EB61-CF33-466E-3849D06F1F61}  I do not have a Google hit on it, but that is not definitive of anything.<br><br>Look with regedit under the root key above and see if you can find a reference to something that is searchable.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Avira-finds-hidden-registry-entries-20376068</guid>
<pubDate>Wed, 23 Apr 2008 18:46:53 EDT</pubDate>
</item>

<item>
<title>Avira finds hidden registry entries</title>
<link>http://www.dslreports.com/forum/Avira-finds-hidden-registry-entries-20375906</link>
<description><![CDATA[BlaZe X posted : Avira finds two hidden registry objects. Can they be possible rootkits? i tried a google search i haven't found anything on them. I also posted in the avira forums, I didn't really get much input about what it can be. They mentioned a software called studio 9 uses hidden registry entries but I never installed this software. What else could it be?<br><br>Heres what it finds: <br><br>Starting search for hidden objects.<br>HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F<br>1F61}\InProcServer32\oaklgcffoomoodagbbadblbhlbffjc<br>[INFO] The registry entry is invisible.<br>HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EB763CD6-EB61-CF33-466E-3849D06F<br>1F61}\InProcServer32\naklmdmgnchnoppccdacnndjgjek<br>[INFO] The registry entry is invisible.<br>'315899' objects were checked, '2' hidden objects were found.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Avira-finds-hidden-registry-entries-20375906</guid>
<pubDate>Wed, 23 Apr 2008 18:18:21 EDT</pubDate>
</item>

</channel>
</rss>

