PDA

View Full Version : Question about Registry Protection


Rasheed187
December 8th, 2007, 09:21 PM
Hi,

I wonder if it´s really necessary to monitor this regkey, and with that I mean, if malware modifies this key, can it be an immediate threat? Even when no malicious processes are running?

-{ Quote: "HKLM\SOFTWARE\Classes\CLSID\*\InProcServer32" }-

http://www.sophos.com/virusinfo/analyses/trojbckdrwf.html

Rasheed187
December 15th, 2007, 10:30 AM
Hello,

Anybody out there? ::)

Mrkvonic
December 15th, 2007, 10:56 AM
Hello,
Not really sure what to tell you. Anything in the registry can potentially be subverted to serve the borg. But if you control your machine, you have nothing to worry about.
Mrk

Rasheed187
December 15th, 2007, 12:18 PM
The thing is, this regkey is often used by legitimate apps, and it´s possible that when installing tools you may have to respond to about 30 alerts, without even having a clue if this may be malicious or not. If I´m correct it´s used to register ActiveX controls, and if you deny these things apps will most likely not function correctly. So that´s why I wondered if allowing this key to be modified, could be a problem. I mean, just some dll/ocx file on disk can´t do any harm, not?