Avatar of ajdratch
ajdratch asked on

Can't remove registry key

I removed a virus from a Windows 7 64 bit computer. There is a registry key that I cannot remove that I think came from this virus. It is HCLM/system\currentcontrolset\services\gupdate\parameters. When I right click and select permissions it says "requested security information is either unavailable or can't be displayed"

I have tried running  psexec -i -d -s \regedit  as administrator but still can't get to it.

Can't get to it in safe mode or with all non MS services disabled.

I tried using subinacl  and followed these instructions https://www.experts-exchange.com/askQuestion.jsp?taid=86
Windows 7

Avatar of undefined
Last Comment
bnei

8/22/2022 - Mon
Pradeep Dubey

you can do it from recovery option also.

Boot the machine with the windows7 DVD and start command prompt by pressing Shift+F10 key.

now open registry and load the system registry key. Delete the key and unload the system key again.

Reboot machine into safe mode.
ASKER
ajdratch

I did that and the key does not show up. I guess this means something is loading it at boot up?
Pradeep Dubey

okay run ccleaner and check for the startup items. it will show everything.. and from there you can locate that registry and do more.

www.ccleaner.com 

I'm using v 4.03.4151
Your help has saved me hundreds of hours of internet surfing.
fblack61
Mohammed Khawaja

Run regedt32 and take ownership of the key and then delete it.
aadih

Yes. A virus. May not show up in CCleaner startup items (great idea, however), if it is a rootkit infection.

Could you share the name of the virus you cleaned up?  Was it ZeroAccess (or its other variants)?
jcimarron

Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
BillDL

ajdratch

Open Device Manager.

Start button > Control Panel.
If viewing as Details or small icons, click the "System and Security" link then click on "Device Manager"under the "System" heading in the new window.
If viewing large icons, just double-click on "Device Manager"

Alternatively, open Device Manager from the command prompt:    devmgmt.msc

Click the View menu, then click the "Show Hidden Devices" option.
Expand the section named "Non-Plug and Play Drivers".

Do you see one in there named "GUpdate"?

If so, Right-Click on it and choose "Properties", then open the "Drivers" tab.
Take a note of that it says under "Service Name", "Display Name", the path to the file that shows when you click the "Driver Details" button, and what is showing in the Startup Type field in the same tab.

Post the details here.  It may be possible to just uninstall this service after booting into the Administrator account.
McKnife

The key does not show because "currentcontrolset" is always refers to the control set that is currently loaded. Offline, no set is loaded. It will be control set 001.
ASKER CERTIFIED SOLUTION
bnei

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
McKnife

Feedback, please
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
ASKER
ajdratch

I have not been able to get reconnect to that computer. I should have access to it later this week
ASKER
ajdratch

This took care of it
aadih

Great. You got it working. :-)
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
bnei

Glad you got her done!