Re: Why you need a registry cleaner



Instead of using "that other" program you can use RunAsSys.exe, yet another handy tool to run interactively under the System account. RunAsSys.exe is available here: http://assarbad.net/de/stuff/temp/ On the english page http://assarbad.net/en/stuff look for localsystem.zip. These are free and "safe" to use for experienced users, keeping in mind that you can do a lot of damage running as the System account, things that you can't do even as an Administrator. When you launch RunAsSys a Command prompt will open and run under the System account, any programs or processes that you open from that command session will also open with the same System account privileges.

The keys were there all the time, you were just not using the System account to run Regedit and open the keys, that is why you weren't seeing anything. The second SAM key is normal, HKEY_LOCAL_MACHINE\SAM\SAM key is also mapped to the HKEY_LOCAL_MACHINE\SECURITY\SAM key. It goes without saying that there is a very good reason for heaving these keys hidden! There is nothing there for users to change and if the keys are tampered with you might not be able to log back on to the machine.

Finally, you could simply have accessed and read the contents of the keys by changing the permissions on the keys to give the Administrator Read permissions, but once again, it is best not to change the permissions unless you know what you are doing and you should return the permissions to their defaults once done.

John

Unknown wrote:

In normal regedit, there is nothing there. I downloaded and installed 'Registrar Registry Manager'. Using that program the 'secret' key appears. Is it truly there or does Registrar Registry Manager just display and or build it? Also in HKLM 'sam' has another 'sam' key under it.
"John John" <audetweld@xxxxxxxxxxx> wrote in message news:%23XTM1A33HHA.5740@xxxxxxxxxxxxxxxxxxxxxxx

How about the HKEY_LOCAL_MACHINE\SAM key? See anything in there?

John

Unknown wrote:


Yes, I read it and tried all methods. Cannot find a thing. In HKLM --security, there is nothing.
"John John" <audetweld@xxxxxxxxxxx> wrote in message news:uYWWAHs3HHA.4584@xxxxxxxxxxxxxxxxxxxxxxx


Did you read the article that Shenan pointed you to? You have to access the registry with the System account to see the contents of the Security and SAM keys.

Another hint: You can use Sysinternals' PsExec to interactively run processes under the System account. The Server Service will have to be running for it to work.

John

Unknown wrote:



I work with the registry often. How do I find it? Are you talking about XP home?.
"Shenan Stanley" <newshelper@xxxxxxxxx> wrote in message news:%23pg6O8o3HHA.1212@xxxxxxxxxxxxxxxxxxxxxxx



Me wrote



What makes you think that they don't. There are many areas of the
registry that are not reveled by regedit. An interesting key is named
"SECRETS"

Unknown wrote:



What secrets key?

Shenan Stanley wrote:



Likely referring to:
http://www.windowsnetworking.com/kbase/WindowsTips/WindowsNT/RegistryTips/Miscellaneous/LSASecrets.html

Unknown wrote:



No such key on my system.

*grin*
Oh - it's there.

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html





.



Relevant Pages

  • Re: import full registry
    ... John John wrote: ... keep getting the error message that some of the ... keys are open so the file can't be imported. ... export, then import, the whole registry. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Unable to delete Registry Items
    ... > While we are on the subject of Legacy keys, ... As they are created these keys inherit ACLs from the ... parent key (which only allow DELETE from the SYSTEM account and thus ...
    (microsoft.public.win2000.registry)
  • Re: CA key pair deposition
    ... Also, if you just want to backup the keys, you can use the MMC ... > The CA runs as the SYSTEM account which implies that the keys are stored ... > the machine store of the local system. ... > the CA), which the "wizzard" generated, could be. ...
    (microsoft.public.win2000.security)
  • Re: Reg Imports
    ... Nope, Full control. ... Tried to import the keys and it says that "Some of the ... privileges since FBA is run in System account. ... called "Permission" set permissions for your account to full ...
    (microsoft.public.windowsxp.embedded)
  • Re: CA key pair deposition
    ... The CA runs as the SYSTEM account which implies that the keys are stored in ... the machine store of the local system. ... third party CSP to store the keys elsewhere of couse. ... which descibes how the wizzard ...
    (microsoft.public.win2000.security)