SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows NT/2000/2003
User Name
Password


Unable to remove LEGACY_MPR keys

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 04-22-2004, 03:44 AM
code64_99 Offline
Junior Member
 
Join Date: Apr 2004
Posts: 3
Unable to remove LEGACY_MPR keys

Dear All,

I think my pc is infected with some kind of worm (probably one of the Agobot starins).

When infected, I have explored.exe or rundil16.exe running.

I killed the process using task manager. Then I searched the h/d for these 2 files and deleted it. The worm also infect C:\WINNT\system32\drivers\etc\hosts.

I ran regedit and removed all keys that contain explored.exe or rundil16.exe.

I did some research on web and understand that I suppose to remove some LEGACY_MPR keys.

I searched and found 3 keys:

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_MPR]
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_MPR\0000]
"Service"="MpR"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="Windows Login"


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\ LEGACY_MPR]
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\ LEGACY_MPR\0000]
"Service"="MpR"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="Windows Login"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_MPR]
"NextInstance"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_MPR\0000]
"Service"="MpR"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="Windows Login"


Now, I am not able to remove these keys. It says "cannot delete LEGACY_MPR: error while deleting key".

Then I thought I should do it in Safe mode. Guess what? I cannot delete these keys too.

So, I tried to download Kugle Regediter 3.0 (Shareware with 30 days trial). First I thought I could remove the keys. But, Wwhen I refresh it, everything is still there.

I think because of this, the worm keep coming back
What shall I do?

Appreciate your help!

________________

YF
Reply With Quote

  #2  
Old 04-22-2004, 08:24 AM
snowmonkey's Avatar
snowmonkey Offline
Registered User
 
Join Date: Jun 2003
Location: Canada
Posts: 3,357
Send a message via MSN to snowmonkey
instead of doing it manually, why do you let a software do it for you. I have used "Spy Sweeper" 30 days trial version and it works awesome, give it a try :
http://downloads-zdnet.com.com/3000-2144-10200144.html

cheers

P.S; after installing the software, allow the software to update itself.
Reply With Quote

  #3  
Old 04-22-2004, 08:40 PM
code64_99 Offline
Junior Member
 
Join Date: Apr 2004
Posts: 3
Quote:
Originally posted by snowmonkey
instead of doing it manually, why do you let a software do it for you. I have used "Spy Sweeper" 30 days trial version and it works awesome, give it a try :
http://downloads-zdnet.com.com/3000-2144-10200144.html

cheers

P.S; after installing the software, allow the software to update itself.


Hi,

Thanks for your suggestion.

I have updated ad-aware and pest patrol installed and I scan it frequently to detect and remove spyware. Unfortunately, the keys cannot be removed by anyone of them. I have Trend antivirus as well, but it can only detect and remove the files I mentioned, not these keys.

cheers!

_______________________

YF
Reply With Quote

  #4  
Old 04-23-2004, 02:23 AM
code64_99 Offline
Junior Member
 
Join Date: Apr 2004
Posts: 3
Quote:
Originally posted by snowmonkey
instead of doing it manually, why do you let a software do it for you. I have used "Spy Sweeper" 30 days trial version and it works awesome, give it a try :
http://downloads-zdnet.com.com/3000-2144-10200144.html

cheers

P.S; after installing the software, allow the software to update itself.


Hi snowmonkey,

I have tried spysweeper, but unable to detect / clean these keys.

I would appreciate more suggestions.

Thank you.

______________

YF
Reply With Quote

  #5  
Old 03-15-2006, 03:22 PM
Jezmy Offline
Registered User
 
Join Date: Mar 2006
Posts: 1
Wink Unable to delete LEGACY_ keys

Hi there all...

Generally, you will find that LEGACY_ keys in the registry cannot be deleted because the are owned by the system or another account, rather than a user (Administrator, etc).

In order to get rid of them you must grab ownership... or at least permission to edit the key.

Use REGEDIT and navigate to the key you want to get rid of, then Right-click and select "permissions".

If you are SURE you want to get rid of the key, click the "Add" button and enter "Everyone" in the "Select users or groups" box and hit return.

Make sure that "Everyone" is selected in the Permissions window. You should have a set of tick-boxes in the lower pane. Tick the box marked "Allow" on the "Full Control" line. (All the boxes below "allow" automatically set themselves). Click "OK" and you should be back at the "normal" regedit screen.

You should now be able to delete the offending key.

Good luck.
Reply With Quote

  #6  
Old 02-10-2007, 01:06 PM
tiertangier Offline
Registered User
 
Join Date: Feb 2007
Posts: 1
Regedt32 not Regedit

If I may interject. Regedit.exe does not have an option to change permissions (assuming you are using Windows 2000(not sure about XP)). However, Regedt32.exe does have that option. I encountered some difficulty when searching for a particular key (HKLM\system\controlset001\enum\root\legacy_flexne t_licensing_service). You may have to find what you are looking for with Regedit.exe and make note of it. Then navigate to that key in Regedt32.exe. When you find it use the Security menu to find the permissions function. I was able to take ownership of and delete the offending key. Thanks for your help.
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
AVG unable to remove fladreamer Windows XP 4 01-08-2005 12:48 PM
Help! Unable to remove spyware Tedr Chit Chat 5 10-27-2004 10:35 AM
Help! Unable to remove Spyware Tedr Software Problems and Useful Utilities 5 09-22-2004 03:42 AM
Help! Unable to remove spyware Tedr Windows 95/98/ME 3 08-23-2004 10:02 AM
Unable to disable start up items (in msconfig) brianabbott Windows XP 3 12-01-2003 07:21 AM



All times are GMT -5. The time now is 03:45 PM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.