Registry Editing
Tutorials - Windows
 Manually removing malware entries from  Registry  : registry editing

You can edit the registry by using the windows built in registry editor. Click on Start > Run to open the run command box in XP, whereas in Vista the box is already open. type regedit and press Enter or Ok , that will open the registry editor.

Now Click on Edit > Find. You can use this box to find a particular registry key/ value. In order to do that, copy the last part of the registry keys if they are inside curly braces {}, after the last / (forward slash) and then paste it into this box, or type in the name of the malware in the box and press "Find Next", if the search stops , you should either see a message saying "Finished searching through the registry"or it will stop at that key found. The found item will be displayed in blue selection. You can delete the entire key, that is the entry in the left side of the panel, once you confirm yourself that this key belongs to the malware by looking at the entire key and comparing it with the ones listed here, and by looking at the values that it has created in the right side of the panel. In case you are not sure if you want to remove the key, you can remove the values in the right side panel instead, that will also cripple the functioning of the malware. To delete a key/ value, use the mouse pointer to select it first, then right click on it to see a menu and select delete from it, then say yes to the confirmation alert. Alternately you can press the delete key on the keyboard to delete the selected entry.  You can also use the names of the files / folders created by the malware to search for their associated keys in the registry.

Once you have deleted an entry, press the F3 key on the keyboard to search for the next occurance of the entry, do this till you reach the end of the registry. Now copy the second registry key/ filename and repeat the above procedure. This is a tedious process and takes time  and effort, but there is no better way to make sure the malware is out of your computer. 

 
  
Comments
Add New Search
roland wensel  - twex.exe   |86.168.123.xxx |2009-04-18 13:48:08
I followed your instructions to clear the registry from the twex files, but the
deleting process is unsuccesful, i.e. the deleted binary file is still there,
when I run the registry again.
sanjay   |115.109.13.xxx |2009-04-21 08:58:36
deleting the registry keys does not remove the files on the hard disk. For that
you need to search for the files using windows search utility, and then delete
them
ray  - more clear please   |69.141.27.xxx |2009-04-30 01:46:28
hi mmm br exacly what do i have to delete the defaul or the other files? and if
its default the cant be deleted please be more clear because its really hard to
understand exacly what u really mean thank u
sanjay   |121.246.32.xxx |2009-05-01 10:06:48
registry keys are in the registry, they point to some file or a folder on the
hard disk. You need to delete the registry keys using registry editor, and then
you need to delete the files on the hard disk separately
ray   |69.141.27.xxx |2009-04-30 01:46:38
c
jesus  - protect.ll malware   |216.73.207.xxx |2009-05-02 17:49:33
every time i boot up there are error messages saying that there was 4 files that
couldnt be loaded b/c there missing...but when i searched in the regedit,
protect.dll and autochk.dll were in the registry...do i jut delte those two .dll
files to get rid of the error msgs???
sanjay   |115.109.9.xxx |2009-05-03 02:50:48
use a freeware called CCleaner. Run the Cleaner and Registry menus in it. That
should remove the error messages
Jesus  - Thanks...   |216.73.207.xxx |2009-05-03 18:44:50
Ive done that, but after i reboot my pc it says that my windows xp is not a
genuine copy and that i have been a victim of piracy...do u know why it would do
that...the OS came with my pc???
sanjay   |121.246.34.xxx |2009-07-08 12:18:26
I would advise you to enquire at the shop where you purchased the PC. They
should be able to solve your problem
Will   |68.150.46.xxx |2009-07-08 03:27:41
I accedently deleted The registry folder the malware was in not and not just the
value, now my computer keeps blue screening upon start up no matter what mode i
choose
sanjay   |121.246.34.xxx |2009-07-08 12:13:04
try to do a windows repair installation, if you happen to use XP and have xp
installation disk. Or else you may have to do a complete reinstallation (that
would wipe out all the HD), in case you want to do repair installation, please
see the article about it on this
site
http://comprolive.com/welcome/index.php/tutor
ials/20-windows/51-reinstalling-windows
Write comment
Name:
Email:
 
Title:
 

3.26 Copyright (C) 2008 Compojoom.com / Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."

 
Privacy Policy