By Scott M. Fulton, III, Betanews
When Betanews reported last June about occurrences of the infamous "Black Screen of Death" (KSoD) in Windows Vista, a reader wrote to suggest to us that we might have only considered the matter so important this late in the game because suddenly it happened to us. A similar opinion may be appropriate for British security firm Prevx, which now says it has "exonerated" last month's set of Patch Tuesday updates from Microsoft as the cause of what it called last night a "crop" of KSoD incidents.
Early Tuesday evening, Prevx director of malware research Jacques Erasmus reported on his company's blog that he and his team have made "significant progress in determining specific triggers of the black screen event." Specifically, it determined that a side-effect accidentally discovered over three years ago by none other than SysInternals' Mark Russinovich (now with Microsoft), led to instances where Windows' product activation inadvertently triggered the black screen. When a System Registry entry of String type is supposed to be terminated by a null character (0) but isn't, the result is that the entry itself may disappear from REGEDIT, Windows' well-known Registry Editor. Such an entry may also trigger KSoD conditions.
But that much has been public knowledge for as long as Russinovich has been distributing his "cool" registry key hider tool. Nevertheless, Prevx now has come around to believing that non-terminated Registry entries to be the cause of KSoD problems, not some strange and allegedly unpublicized change in the "rules" for Access Control Lists that a patch may not have followed.
Erasmus may have had some help in reaching this conclusion from Microsoft. In a statement to Betanews late this afternoon, security response communications lead Christopher Budd told us, "Our comprehensive investigation has shown that none of the recently released updates are related to the behavior described in the reports. While we were not contacted by the organization who originally made these reports, we have proactively contacted them with our findings."
So if Prevx wasn't really sure that ACLs were at the root of the KSoD problem, exactly what does its free fix tool, released yesterday, do? This evening, Erasmus suggested that at the very least, it does nothing bad. "We apologize to Microsoft for any inconvenience our blog may have caused," he wrote. "This has been a challenging issue to identify. Users who have the black screen issue referred to can still safely use our free fix tool to restore their desktop icons and task bar."
Prevx's earlier story led to the BBC reporting a rash of KSoD incidents afflicting specifically Windows 7. The evidence of such a rash may have just disappeared, which doesn't exactly mean the problem has gone away. It does mean we can reset the panic button now.
Copyright Betanews, Inc. 2009


Will Microsoft slapping “7” on the rebranded Windows Mobile (now Windows Phone) OS be enough to counter Google’s Linux for mobile phones? It’s easy to expand the Microsoft vs. Google antithesis to Windows Phone and Android – proprietary vs. open source, paid vs. free, Windows vs. Linux, etc. Most would ... (
More and more open source pieces of software are compatible with the Windows operating system, according to statistics from the Geeknet network. Asked by Microsoft to deliver a perspective over Windows’ position in relation to the open source ecosystem, Geeknet revealed that, at the end of 2009, over 82% of open source pieces of software ... (
A new release of Microsoft’s visual programming language designed for building games is now available for download for customers running Windows. Just as the previous versions of the game development platform, Kodu is still cooking in the Redmond ovens. In this regard, Build 1.0.34.0 is labeled as a Technical Preview release, this even though when it announced the P... (
According to Google, Internet Explorer 8 comes in last place out of the world’s most popular five browsers in the race for JavaScript conformance. Christian Plesner Hansen, Google software engineer, is basing this conclusion on the results that IE8, Firefox 3.6, Opera 10.50, Chrome 4 and Safari 4 got in the company’s Sputnik JavaScript ... (
Leave a Reply
You must be logged in to post a comment.