Changes

Microsoft Windows Registry Security

1,352 bytes added, 21:16, 23 December 2014
The following lines were added (+) and removed (-):
== Startup Programs ==Software that is third-party which is loaded when Windows is loaded, or a user logs in can be stored in the registry.  The following two registry keys are responsible for loading these auto-start programs.# HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run# KEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunIn the first the program would start on user login, and only for that user.  The second will load for any user when the Windows session begins.A common example of a startup program is GoogleUpdate.exe which is added by Google software such as the Google Chrome web browser.  The key pair looks like this:* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Google Update* REG_SZ "C:\Documents and Settings\nicole\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /cAlthough GoogleUpdate.exe is generally considered benign, the risk is in what a virus hacker can do to disguise malware.  The developer of a virus, being aware that people ignore GoogleUpdate.exe, may replace it will a virus using the same name.  In this event, the virus is auto-loaded with Windows and the user sees only what is perceived to be the harmless GoogleUpdate program.  Because GoogleUpdate runs silently in the background (TSR) there is no interface, also a trait of a virus.
Bureaucrat, administrator
16,192
edits