|
Unable to remove LEGACY_MPR keys
Dear All,
I think my pc is infected with some kind of worm (probably one of the Agobot starins).
When infected, I have explored.exe or rundil16.exe running.
I killed the process using task manager. Then I searched the h/d for these 2 files and deleted it. The worm also infect C:\WINNT\system32\drivers\etc\hosts.
I ran regedit and removed all keys that contain explored.exe or rundil16.exe.
I did some research on web and understand that I suppose to remove some LEGACY_MPR keys.
I searched and found 3 keys:
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_MPR]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_MPR\0000]
"Service"="MpR"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="Windows Login"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\ LEGACY_MPR]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\ LEGACY_MPR\0000]
"Service"="MpR"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="Windows Login"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_MPR]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_MPR\0000]
"Service"="MpR"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="Windows Login"
Now, I am not able to remove these keys. It says "cannot delete LEGACY_MPR: error while deleting key".
Then I thought I should do it in Safe mode. Guess what? I cannot delete these keys too.
So, I tried to download Kugle Regediter 3.0 (Shareware with 30 days trial). First I thought I could remove the keys. But, Wwhen I refresh it, everything is still there.
I think because of this, the worm keep coming back
What shall I do?
Appreciate your help!
________________
YF
|