LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 11-06-2007, 09:19 PM   #1
moxieman99
Member
 
Registered: Feb 2004
Distribution: Dabble, but latest used are Fedora 13 and Ubuntu 10.4.1
Posts: 425

Rep: Reputation: 147Reputation: 147
Deleting hidden lines in Wondows XP registry -- How?


I picked up a cheap laptop (Dell Inspiron 1000) with Windows XP Home Edition, SP 1. I do NOT have the OEM CD.

I did all the Microsoft security and SP2 updates and then downloaded RootKit Revealer also. Ran that.

RKR says that there is a hidden line in the Registry at HKLM/System/ControlSet001/Services. Google says that the line (asc3550i) is indicative of general malware (there is a revealed line of asc3550p, but that seems to be clean).

I can't find the offending malware file under any of its given possible names, but that is beside the point. Question is this: How can I edit hidden lines in the windows registry file? I can't even find the Windows Registry to begin with, but regedit doesn't help me al all.

I will eventually see about dual booting the thing with Fedora (linux for laptops web site seems to show that Core 3 or above will work), but I can't let a rootkitted lappy on the web.

How can I edit registry lines that are "hidden?"

Thanks,

Moxieman
 
Old 11-06-2007, 09:38 PM   #2
Simon Bridge
LQ Guru
 
Registered: Oct 2003
Location: Waiheke NZ
Distribution: Ubuntu
Posts: 9,211

Rep: Reputation: 198Reputation: 198
Quote:
I can't let a rootkitted lappy on the web
This is right. Thank you for considering other web users.

Of course, once in dual-boot, you could adopt a policy of only using fedora when online. This will save you greif in the long run. Meanwhile - that rootkit:

Removing rootkits in windows usually involves third-party tools.
http://searchwindowssecurity.techtar...086474,00.html
http://searchwindowssecurity.techtar...086476,00.html
 
Old 11-07-2007, 07:07 AM   #3
moxieman99
Member
 
Registered: Feb 2004
Distribution: Dabble, but latest used are Fedora 13 and Ubuntu 10.4.1
Posts: 425

Original Poster
Rep: Reputation: 147Reputation: 147
Quote:
Originally Posted by Simon Bridge View Post
Meanwhile - that rootkit:

Removing rootkits in windows usually involves third-party tools.
http://searchwindowssecurity.techtar...086474,00.html
http://searchwindowssecurity.techtar...086476,00.html
------------------
Thanks, I read the sites, but like I said, I ran RootKit Revealer and it detected this hidden line in Registry. How and where can I find concealed lines in the registry so I can delete them? Visible lines I can edit with regedit, but regedit doesn't touch concealed lines.

Edit -- Found it: Little bugger's in WINDOWS/System32/Config Thanks all,

Last edited by moxieman99; 11-07-2007 at 07:15 AM. Reason: Additional information
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
deleting specified lines in a huge text file ruh31 Linux - General 10 06-30-2006 03:34 AM
Deleting the lines from a file using shell scripts sharad Linux - General 1 05-22-2006 03:17 AM
An easy way of deleting lines from multipe files? delawhere Linux - General 2 04-02-2004 11:58 AM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 02:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration