I have been working on getting activesync to Exchange 2003 working and was
therefore verifying certificates when I noticed that my XP client to which I
had a partnership had 3 very odd certificate folders.

The three folders are after "Certificate Enrollment Request/Certificates"
and have ASCII characters and Kanji (spelling?) characters intermixed.

This made me start looking through all my certificate folders and I noticed
some odd ones.

In the Certificate Enrollment Request/Certificates there is one named
"FZkC37K9xRLk8364" which reports that is either tampered with or corrupted.

I have attached just the public key to this cert (although I have both the
public and private in the request).

Is my cert-store damaged, or is there something malicious going on?

My machine is Windows XP and is in it's own workgroup, although it often
communicates to a Win2003 DC.

Any advice or investigative suggestions would be most welcome!

-Neil
neilgo(_r#mov3)@xcelar.com


begin 666 Bad or Damaged Cert.p7b
M,((!8 8)*H9(AO<-`0<"H((!43""`4T"`0$Q`# +!@DJADB&]PT!!P&@@@$U
M,((!,3""`1Z@`P(!`@(0^I"N127#AII*`9=_\N:+9S )!@4K#@,"'04`,!LQ
M&3 7!@-5! ,3$$9::T,S-TLY>%),:S@S-C0P'A<-,#(Q,3(P,3 R-# W6A<-
M,#,Q,3(P,38R-# W6C ;,1DP%P8#500#$Q!&6FM#,S=+.7A23&LX,S8T,(&?
M, T&"2J&2(;W#0$!`04``X&-`#"!B0*!@0"S5N-FPP!F<83)A#Y@R3FSM3#X
MP!8H-XA/3"]'K)?EYRX+J(QK1I -Z&D*6_DBM,3'"V&1\PU9B5@#_F][(.XV
M)7J&*I;)(+A8TM=RL9#<Z<Q(@'-&$1FCVUV80*H@98IN/AGXNO_6DI&!H-66
I'1R>8Q+RJZCV<F,@K_X[&FNXFP(#`0`!, D&!2L.`P(=!0`#`@`B,0``
`
end

Re: Windows XP Pro certificate store has a strange cert that may be bad or damanged by David

David
Fri Aug 29 07:51:02 CDT 2003

It may just be a corrup/orphaned request - this can happen. I would not be
concerned at all. Feel free to delete it.

--


David B. Cross [MS]

--
This posting is provided "AS IS" with no warranties, and confers no rights.

http://support.microsoft.com

"Neil" <neilgo_remove_@xcelar.com> wrote in message
news:uvEotg$aDHA.1280@tk2msftngp13.phx.gbl...
> I have been working on getting activesync to Exchange 2003 working and was
> therefore verifying certificates when I noticed that my XP client to which
I
> had a partnership had 3 very odd certificate folders.
>
> The three folders are after "Certificate Enrollment Request/Certificates"
> and have ASCII characters and Kanji (spelling?) characters intermixed.
>
> This made me start looking through all my certificate folders and I
noticed
> some odd ones.
>
> In the Certificate Enrollment Request/Certificates there is one named
> "FZkC37K9xRLk8364" which reports that is either tampered with or
corrupted.
>
> I have attached just the public key to this cert (although I have both the
> public and private in the request).
>
> Is my cert-store damaged, or is there something malicious going on?
>
> My machine is Windows XP and is in it's own workgroup, although it often
> communicates to a Win2003 DC.
>
> Any advice or investigative suggestions would be most welcome!
>
> -Neil
> neilgo(_r#mov3)@xcelar.com
>
>
>