Sysinternals Homepage
Forum Home Forum Home > Sysinternals Utilities > Regmon
  New Posts New Posts RSS Feed: Regmon results Shows Buffer Overflow
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

Regmon results Shows Buffer Overflow

 Post Reply Post Reply
Author
Message Reverse Sort Order
molotov View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 04 October 2006
Online Status: Offline
Posts: 17492
Post Options Post Options   Quote molotov Quote  Post ReplyReply Direct Link To This Post Topic: Regmon results Shows Buffer Overflow
    Posted: 20 February 2009 at 10:10pm
In my case, the behavior was not a problem. Malware was not involved, and neither was a p2p network program.
Daily affirmation:
net helpmsg 4006
Back to Top
pritchie View Drop Down
Newbie
Newbie
Avatar

Joined: 20 February 2009
Location: Lincoln
Online Status: Offline
Posts: 1
Post Options Post Options   Quote pritchie Quote  Post ReplyReply Direct Link To This Post Posted: 20 February 2009 at 9:03pm
I had the same problem on a computer, and it was running supper slow.  I had already cleaned the computer background programs with hijack this, msconfig, ect but something was still running.  Combofix.exe (if you don't know about combofix, just google it) got whatever it was off the computer and now it no longer attempts to access registry HKLM\SYSTEM\ControlSet001\Services\Tcpip\Linkage\Bind and runs considerably faster.
 
I believe it was a p2pnetworking program that causing this problem as that was what combofix removed.
Back to Top
molotov View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 04 October 2006
Online Status: Offline
Posts: 17492
Post Options Post Options   Quote molotov Quote  Post ReplyReply Direct Link To This Post Posted: 19 June 2007 at 10:16am
FWIW, I get the same behavior on the same key - Request is "QueryValue", and 2 of 3 results are BUFFER OVERFLOWs while 1 of 3 is SUCCESS.
Daily affirmation:
net helpmsg 4006
Back to Top
ixuser View Drop Down
Newbie
Newbie


Joined: 19 June 2007
Location: United States
Online Status: Offline
Posts: 3
Post Options Post Options   Quote ixuser Quote  Post ReplyReply Direct Link To This Post Posted: 19 June 2007 at 10:12am
Ok, thanks.
Back to Top
molotov View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 04 October 2006
Online Status: Offline
Posts: 17492
Post Options Post Options   Quote molotov Quote  Post ReplyReply Direct Link To This Post Posted: 19 June 2007 at 10:10am
If this is the only activity that you are suspicious of, I can't say that I would be concerned about it.  Of course, if you are concerned you can always run the appropriate AV / malware scans...
Daily affirmation:
net helpmsg 4006
Back to Top
ixuser View Drop Down
Newbie
Newbie


Joined: 19 June 2007
Location: United States
Online Status: Offline
Posts: 3
Post Options Post Options   Quote ixuser Quote  Post ReplyReply Direct Link To This Post Posted: 19 June 2007 at 9:57am
      Thank you, I understand the reason why the buffer overflow is being generated, simply a small buffer.
      This is showing up in HKLM\SYSTEM\ControlSet001\Services\Tcpip\Linkage\Bind. I had to use xp tcp repair to get my dhcp client to work again. This is why im suspicious that MS Bind module is being replaced by a hacker/trojan/virus/malware, or something to that effect. Any thoughts or ideas? I could be overly suspicious of nothing also.
Back to Top
molotov View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 04 October 2006
Online Status: Offline
Posts: 17492
Post Options Post Options   Quote molotov Quote  Post ReplyReply Direct Link To This Post Posted: 19 June 2007 at 9:47am
Hi, ixuser.
 
Daily affirmation:
net helpmsg 4006
Back to Top
ixuser View Drop Down
Newbie
Newbie


Joined: 19 June 2007
Location: United States
Online Status: Offline
Posts: 3
Post Options Post Options   Quote ixuser Quote  Post ReplyReply Direct Link To This Post Posted: 19 June 2007 at 9:42am

While running regmon, it shows certain registry keys as BUFFER OVERFLOW in the Results column. To me, thats a big issue. How do I take care of these registry entries coming up as Buffer Overflow? Is it the actual executable that needs to be replaced?

Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down