PDA

View Full Version : win32.klez and reg keys (W2K)



erinol
04-27-2002, 11:44 AM
I recently was infected with win32.klez.e@mm. I finally managed to get rid of it, but it didn't get rid of the registry keys that the virus created. They are under HKEY_LOCAL_MACHINE/SYSTEM/CONTROLSET001/ROOT/

The keys are listed as "Legacy_wink*" It tells me that it can't delete/read/modify the keys due to an error in performing the operation. How can I delete these keys? I already deleted the other locations of Wink* in the registry, as instructed, but if possible I'd like to remove these keys as well.

Thanks in advance for any assistance that can be provided.

erinol

jdharm
04-29-2002, 07:57 PM
Have you tried this in safe mode?

If that doesn't work try to open the registry using regedt32 instead of regedit. Highlight the key and go to the Security menu. Registry keys have permissions in Win2K, just like files do, so make sure you have full permission to edit these keys.

Josh

"It is easier to stay out than get out."