CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

Deleting AppInit_DLLs registry key after applying MS...

 
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
gahbmwM5

Cadet
Cadet


Joined: Jan 06, 2006
Posts: 3
Location: USA

PostPosted: Fri Jan 06, 2006 5:54 am    Post subject: Deleting AppInit_DLLs registry key after applying MS...
Reply with quote

Official patch is ok...?

Hello,

I just wanted to make sure that I'm interpreting this correctly, as I 'did apply' ilfak's wmffix.exe 1.2 a couple of days ago on my single user WinXP SP2 Home laptop...

I have reviewed the WMF Exploit FAQs section (updated by Paul), and was able to successfully remove the wmffix.exe 1.2 through my Add/Remove section, then rebooted and applied the Official MS patch, but I read this section of FAQs and was curious:

#14 # Are any changes made to the Registry?

The installer injects this DLL to processes in the system using the following registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs

I deleted this \AppInit_DLLs key (which showed a blank value after using the wmffix.exe 1.2 uninstaller, and was still present after applying the Official MS patch...

Is this fine? Just want to make sure that this 'key is no longer needed'

Thanks for all the work to ilfak & Paul... Smile

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Jan 06, 2006 6:10 am    Post subject:
Reply with quote

You could have left it blank, but that's fine.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
gahbmwM5

Cadet
Cadet


Joined: Jan 06, 2006
Posts: 3
Location: USA

PostPosted: Fri Jan 06, 2006 6:24 am    Post subject:
Reply with quote

Paul wrote:
You could have left it blank, but that's fine.


Hi Paul,

Very good, as that is what I thought, but sometimes I 'read too much into events'...lol

Thanks for the prompt reply, as I have 'made this Forum' be known on some other sites where there is some confusion...

What better way to obtain 'accurate info' then from a MS-MVP Windows Security (yourself) and from the author of the various wmffix.exe patches,.msi installers, ect and vunerability checker, ilfak (himself)...there is no better, reliable source.

Very Happy

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Jan 06, 2006 6:33 am    Post subject:
Reply with quote

Why thank you, and welcome to CC. Here is a better explanation:

CastleCops Link/HijackThis.html#o20

So you can see normally the value is left blank.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
gahbmwM5

Cadet
Cadet


Joined: Jan 06, 2006
Posts: 3
Location: USA

PostPosted: Fri Jan 06, 2006 9:33 pm    Post subject:
Reply with quote

Paul wrote:
Why thank you, and welcome to CC. Here is a better explanation:

CastleCops Link/HijackThis.html#o20

So you can see normally the value is left blank.


Very good Paul and thanks again...

I added it back again as a string value: {Data = blank}

Name Type Data

AppInit_DLLs REG_SZ

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Jan 06, 2006 10:47 pm    Post subject:
Reply with quote

Ok no worries... you've done well either way. Very Happy


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Metallica

Site Moderator
Premium Member

Joined: Dec 11, 2002
Posts: 4909
Location: Netherlands
Moderators MVP Premium

PostPosted: Sun Jan 08, 2006 11:42 am    Post subject:
Reply with quote

I have a few questions about this registry entry:

- Is it correct that the patch adds an extra space before it's entry in the AppInit_DLLs value in the registry?

- If so, does it only do this when another value is present on install or is this default behavior

- Is it correct that the extra space does not get removed at uninstall?

Not that it does any harm, but we found kit left behind on some occasions and in one of them AdWatch got in a loop where it kept asking at every boot if the change was OK.

Thanks for any answers you may be able to provide.

Regards,

Pieter


_________________
MS-MVP Consumer Security
Back to top
View users profile Send private message Visit posters website
ilfak

Hexblog Host


Joined: Jan 03, 2006
Posts: 21
Location: Belgium

PostPosted: Sun Jan 08, 2006 9:57 pm    Post subject:
Reply with quote

Yes, there is might be a space character left after unistalling the hotfix. It does no harm because the system ignores white space in this key. You may safely accept the changes.

Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Sun Jan 08, 2006 10:01 pm    Post subject:
Reply with quote

In my particular case using 1.3 on XP there is no space, as an added FYI.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Display posts from previous:   
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Hexblog All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer