troubleshooting Question

Can't remove registry key

Avatar of ajdratch
ajdratch asked on
Windows 7
14 Comments1 Solution1364 ViewsLast Modified:
I removed a virus from a Windows 7 64 bit computer. There is a registry key that I cannot remove that I think came from this virus. It is HCLM/system\currentcontrolset\services\gupdate\parameters. When I right click and select permissions it says "requested security information is either unavailable or can't be displayed"

I have tried running  psexec -i -d -s \regedit  as administrator but still can't get to it.

Can't get to it in safe mode or with all non MS services disabled.

I tried using subinacl  and followed these instructions
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 14 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 14 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros