Registry editing problem

P

Paul Webster

Having recently been cobbled by the rather finely named ‘Lo thuong’
adware pest, I have had some difficulty with one element of the removal
process, anyone have any tips.

First of I killed these running processes in task manager
systemroot+\isrvs\desktop.exe
systemroot+\isrvs\edmond.exe
systemroot+\isrvs\ffisearch.exe

The next stage is to delete the following registry entries,
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\desktop
search
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ffis

Now this is where the problem lies, as they will not delete, all I get
is ‘cannot delete, disk may be full or item may being used by another
applications’ (might not be an absolute verbatim transcript as I’m in a
different building to the affected machine at the moment).
I’m logged on as administrator and have checked everything else that I
can think of, ther is no indication at all that either item is running
or active in any way. The rest of the removal process goes as it should
but of course fails as this step has not been completed!

The next stage was to unregistered these using regsvr32
systemroot+\isrvs\mfiltis.dll
systemroot+\isrvs\msdbhk.dll
systemroot+\isrvs\sysupd.dll

easy enough!

Then find and remove these
HKEY_CLASSES_ROOT\clsid\{5b4ab8e2-6dc5-477a-b637-bf3c1a2e5993}
HKEY_CLASSES_ROOT\clsid\{950238fb-c706-4791-8674-4d429f85897e}
HKEY_CLASSES_ROOT\mfiltis
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\ext\clsid\{5b4ab8e2-6dc5-477a-b637-bf3c1a2e5993}
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\delprot

And any other systemroot\isrvs directories as required

Again, simple enough, but can I hell as like get rid of those two run
entries in HKEY_LOCAL_MACHINE…….!!!

I’d be really grateful for any advice.
 
M

Malke

Paul said:
Having recently been cobbled by the rather finely named ‘Lo thuong’
adware pest, I have had some difficulty with one element of the
removal process, anyone have any tips.

First of I killed these running processes in task manager
systemroot+\isrvs\desktop.exe
systemroot+\isrvs\edmond.exe
systemroot+\isrvs\ffisearch.exe

The next stage is to delete the following registry entries,
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\desktop
search
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ffis

Now this is where the problem lies, as they will not delete, all I get
is ‘cannot delete, disk may be full or item may being used by another
applications’ (might not be an absolute verbatim transcript as I’m in
a different building to the affected machine at the moment).
I’m logged on as administrator and have checked everything else that I
can think of, ther is no indication at all that either item is running
or active in any way. The rest of the removal process goes as it
should but of course fails as this step has not been completed!

The next stage was to unregistered these using regsvr32
systemroot+\isrvs\mfiltis.dll
systemroot+\isrvs\msdbhk.dll
systemroot+\isrvs\sysupd.dll

easy enough!

Then find and remove these
HKEY_CLASSES_ROOT\clsid\{5b4ab8e2-6dc5-477a-b637-bf3c1a2e5993}
HKEY_CLASSES_ROOT\clsid\{950238fb-c706-4791-8674-4d429f85897e}
HKEY_CLASSES_ROOT\mfiltis
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\ext\clsid\{5b4ab8e2-6dc5-477a-b637-bf3c1a2e5993}
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\delprot

And any other systemroot\isrvs directories as required

Again, simple enough, but can I hell as like get rid of those two run
entries in HKEY_LOCAL_MACHINE…….!!!

I’d be really grateful for any advice.
First of all, you need to be doing all this work in Safe Mode. If you
aren't, then try there. Secondly, right-click the recalitrant registry
entries and examine their permissions and attributes. You may be able
to change them from Read Only (if they are) and change permissions
easily to Full Control. You may need to take/change ownership of the
entries. Make sure you are logged in as Administrator and again, do all
malware removal work in Safe Mode.

Malke
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

spware C:\WINDOWS\isrvs\desktop.exe 3
Please help me 1
Antispyware freezes at end of scan 1
Registry Problem 7
Numerous Virus Problems 10

Top