Results 1 to 3 of 3

Thread: Can't delete registry entry !! (suspected virus / trojan attack !)

  1. #1
    Join Date
    Sep 2004
    Posts
    57

    Can't delete registry entry !! (suspected virus / trojan attack !)

    Today i did a registry scan and came across some suspicious entries. Currently i am trying to delete those entries using regedit but i am getting an error message saying "Unable to delete all specified values". In my case that registry entry is located at HKEY_Local_Machine->System- ControlSet002->Enum->ROOT->LEGACY_xxx (Where xxx is the name of program) . Is there any other workaround that i can try to delete the suspicious registry???

  2. #2
    Join Date
    May 2011
    Posts
    378

    Re: Can't delete registry entry !! (suspected virus / trojan attack !)

    I think that the registry you are trying to delete might be in use by operating system. That's why you are getting that error, as far as i am aware regedit sometime leaves behind stuffs related to MS. Anyways you can download and install hijackthis or ccleaner for getting rid of that registry entry. I dont think that you will be able to delete it by some other workaround. Just try out any of the program that Ive suggested and post back the result you get.

  3. #3
    Join Date
    May 2012
    Posts
    92
    HKEY_Local_Machine->System- ControlSet002->Enum->ROOT->LEGACY_xxx (Where xxx is the name of program)
    Can you just let me know the name of the program???

    I have found that above error occurs in below situation:

    The Registry key might be based upon a legitimate process which might be running and/or
    is protected.
    1. The Registry key might be based upon malicious code which might be present in your system protecting the key from removal.
    2. The Registry key might be based malicious code which might have changed permissions on the key.
    3. The Registry key might be using invalid characters like NUL character.


    In case the issue is due to permission than you can try below steps for getting it back.
    • Right-Click on "LEGACY_xxx" > choose "Permissions" > Highlight "Everyone" or "Administrator" or your account > checkmark the box for Allow "Full Control" > click on "Advanced" > un-check box for "Inherit from parent..." and "Replace permission entries on all child objects..."
    • Once you have made these changed click on aooly, click on ok and try deleting LEGACY_xxx" again.

Similar Threads

  1. TabProcGrowth registry entry
    By Dimensioner in forum Windows Software
    Replies: 3
    Last Post: 27-02-2011, 12:16 AM
  2. how to unblock Suspected Attack Site in Mozilla firefox
    By Dakshina in forum Networking & Security
    Replies: 4
    Last Post: 18-09-2010, 09:49 PM
  3. Cannot delete Trojan.FakeAV!gen14 virus
    By Balamani in forum Networking & Security
    Replies: 4
    Last Post: 08-01-2010, 05:30 AM
  4. incorrect Src Root Domain Srv entry in registry
    By kyosang in forum Active Directory
    Replies: 4
    Last Post: 11-02-2009, 11:59 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,558,459.42704 seconds with 17 queries