PC Review


Reply
Thread Tools Rate Thread

How to delete rogue registry key and all its subkeys and values?

 
 
=?Utf-8?B?Qm9iIEppbQ==?=
Guest
Posts: n/a
 
      17th Jun 2005
After running HHD Software's USB Monitor for the first time, it creates the
following registry key:

HKLM\Software\Microsoft\Shared Tools\??

Of course, the ?? could be anything. No matter what I do, I can't erase
this subkey. Regedit won't do it, Regedt32 won't do it, I've tried
programmatically with a short program in Visual Studio and it won't do it,
reg.exe won't do it. I've also tried deleting the entire parent key (Shared
Tools) which works for all the subkeys except this one.

In Sysinternals' Registry Monitor, I can see the program accessing this set
of keys at startup. I don't know what it's doing, but I just want to stop.
How can I get rid of it?
 
Reply With Quote
 
 
 
 
insanity2k4@gmail.com
Guest
Posts: n/a
 
      17th Jun 2005
Get yourself a copy of RegSeeker here:

http://www.hoverdesk.net/freeware.htm

It's freeware and it works quite well. It backs up everything it
determines to be a rogue entry, so if it should happen to delete
something it shouldn't have, you can restore it. From personal
experience, however, that has never happened.

 
Reply With Quote
 
=?Utf-8?B?Qm9iIEppbQ==?=
Guest
Posts: n/a
 
      17th Jun 2005
"(E-Mail Removed)" wrote:

> Get yourself a copy of RegSeeker here:
>
> It's freeware and it works quite well. It backs up everything it
> determines to be a rogue entry, so if it should happen to delete
> something it shouldn't have, you can restore it. From personal
> experience, however, that has never happened.


This program was also not able to delete the key. It was able to delete
everything else in Shared Tools, though, just like regedit.
 
Reply With Quote
 
insanity2k4@gmail.com
Guest
Posts: n/a
 
      19th Jun 2005
Interesting, never seen it fail... Well, how familiar are you with
NTFS permissions? If you know what those keys are and can get to them,
take ownership of them (Security tab, Advanced button, Owner tab), then
apply the change. Go back out to the Security tab and explicitly
define your account to have Full Control over the objec, and apply the
change. Go back under the Advanced button, check the box that says,
"Replace permission entires on all child with entries shown here that
apply to all child objects" and hit apply. Now you should be able to
delete the keys no problem.

If you're still unable to axe those keys, that can mean one thing and
one thing only -- you have a virus or spyware on your box that is
actively running, preventing those keys from being tampered with. If
my first paragraph doesn't work, look through all of your running
processes and determine what, if anything, is the problem -- and also
keep in mind that it is possible to completely hide processes from Task
Manager.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot delete a registry key (or subkeys) --- ??? notaguru Windows Vista General Discussion 9 30th Oct 2007 12:49 AM
Enumerate registry keys, subkeys, and values paulo@home.com Windows XP General 6 22nd Nov 2006 03:42 PM
Description of Microsoft Windows Defender configuration registry subkeys Bill Sanderson MVP Security Networking 0 10th Nov 2006 01:35 AM
Deleting registry subkeys and values =?Utf-8?B?Q2xpbnQgQjI=?= Windows XP General 3 8th Sep 2005 08:39 PM
Cannot delete registry values Knack Anti-Virus 2 10th Mar 2004 04:56 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:05 PM.