Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista - Rouge Process I cannot get rid of.

Reply
 
Old 03-14-2008   #11 (permalink)
SG


 
 

Re: Rouge Process I cannot get rid of.

Mike & Malke


Sorry I hadn't responded in quite some days now. I want go into details, but
just to let you both know I've been really sick since Thanksgiving and some
days are unbearable. For the last week or so I've been in and out of the
Hospital, but I'm at home now feeling a little better. Soon as I get a
chance I'll let you both know how or if I can fix this problem.

--
All the best,
SG

ALEX NICHOL
(1935-2005)
http://www.aumha.org/alex.htm
You will never be forgotten my friend

"Malke" <malke@xxxxxx> wrote in message
news:%23I$iP5igIHA.5780@xxxxxx
Quote:

> Mikep wrote:
>
Quote:

>>
>> I was able to assign myself full control of a key in a
>> CurrentControlSet\Enum .... entry. Right click on the key, select
>> permissions and add. Then enter your user name in the 'object names to
>> select' --- then check the 'full control' box.
>
> Yes, Mike - but presumably you're not working on an infected computer and
> SG
> is. That does make a big difference. I've had viruses/malware make it so I
> absolutely could not take ownership of a registry key and where the only
> way I could kill it was from outside the OS. I think SG is in the same
> boat
> with his client's machine; but he wants to figure out where the "block" is
> because he's that kind of guy (and I mean that in an admiring way).
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers
> www.elephantboycomputers.com
> Don't Panic!

My System SpecsSystem Spec
Old 03-14-2008   #12 (permalink)
Malke


 
 

Re: Rouge Process I cannot get rid of.

SG wrote:
Quote:

> Mike & Malke
>
>
> Sorry I hadn't responded in quite some days now. I want go into details,
> but just to let you both know I've been really sick since Thanksgiving and
> some days are unbearable. For the last week or so I've been in and out of
> the Hospital, but I'm at home now feeling a little better. Soon as I get a
> chance I'll let you both know how or if I can fix this problem.
>
It's nice of you to post back although one never really expects to hear from
most people on Usenet, so please don't give it another thought. Concentrate
your energies on what's really important - your health. I'm very sorry that
you've been ill and wish you a speedy recovery.

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!
My System SpecsSystem Spec
Old 03-31-2008   #13 (permalink)
SG


 
 

Re: Rouge Process I cannot get rid of.

Malke,

Wanted to post my results back to you and MikeP.
I was able to get rid of the AMWXRYTJRQBV.EXE and four others that I found
in the Registry. However, I could only delete the branch that ended with the
file names themselves, their were 4 each ,but this did get rid of the
Processes running. The following Branch still remains, but no harm to the
system and the files are gone as with the Registry entries. Still not sure
why I cannot delete anything under this LEGACY Branch or how it was written
to, but the system is fine and in the end is all that matters. Sorry it took
so long to reply, I've posted a few reply's in these groups the past few
weeks, but still not up to par as of yet. Getting a little better each day
and hope the coming months will bring me back to once again feeling like a
human :>)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY]

--
All the best,
SG

Is your computer system ready for Vista?
https://winqual.microsoft.com/hcl/

"Malke" <malke@xxxxxx> wrote in message
news:ua8XENhhIHA.5204@xxxxxx
Quote:

> SG wrote:
>
Quote:

>> Mike & Malke
>>
>>
>> Sorry I hadn't responded in quite some days now. I want go into details,
>> but just to let you both know I've been really sick since Thanksgiving
>> and
>> some days are unbearable. For the last week or so I've been in and out of
>> the Hospital, but I'm at home now feeling a little better. Soon as I get
>> a
>> chance I'll let you both know how or if I can fix this problem.
>>
>
> It's nice of you to post back although one never really expects to hear
> from
> most people on Usenet, so please don't give it another thought.
> Concentrate
> your energies on what's really important - your health. I'm very sorry
> that
> you've been ill and wish you a speedy recovery.
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers
> www.elephantboycomputers.com
> Don't Panic!
My System SpecsSystem Spec
Old 03-31-2008   #14 (permalink)
Malke


 
 

Re: Rouge Process I cannot get rid of.

SG wrote:
Quote:

> Malke,
>
> Wanted to post my results back to you and MikeP.
> I was able to get rid of the AMWXRYTJRQBV.EXE and four others that I found
> in the Registry. However, I could only delete the branch that ended with
> the file names themselves, their were 4 each ,but this did get rid of the
> Processes running. The following Branch still remains, but no harm to the
> system and the files are gone as with the Registry entries. Still not sure
> why I cannot delete anything under this LEGACY Branch or how it was
> written to, but the system is fine and in the end is all that matters.
> Sorry it took so long to reply, I've posted a few reply's in these groups
> the past few weeks, but still not up to par as of yet. Getting a little
> better each day and hope the coming months will bring me back to once
> again feeling like a human :>)
>
> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY]
>
I'm glad to hear you're on the mend. As for the legacy keys, try taking
ownership of them or delete them from outside the OS.

Take care,

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!
My System SpecsSystem Spec
Old 03-31-2008   #15 (permalink)
SG


 
 

Re: Rouge Process I cannot get rid of.

Hi Malke,

I think I tried taking ownership, but can't remember. I'll give this a try
and see what happens.

--
All the best,
SG

Is your computer system ready for Vista?
https://winqual.microsoft.com/hcl/

"Malke" <malke@xxxxxx> wrote in message
news:%23B$4KnykIHA.6032@xxxxxx
Quote:

> SG wrote:
>
Quote:

>> Malke,
>>
>> Wanted to post my results back to you and MikeP.
>> I was able to get rid of the AMWXRYTJRQBV.EXE and four others that I
>> found
>> in the Registry. However, I could only delete the branch that ended with
>> the file names themselves, their were 4 each ,but this did get rid of the
>> Processes running. The following Branch still remains, but no harm to the
>> system and the files are gone as with the Registry entries. Still not
>> sure
>> why I cannot delete anything under this LEGACY Branch or how it was
>> written to, but the system is fine and in the end is all that matters.
>> Sorry it took so long to reply, I've posted a few reply's in these groups
>> the past few weeks, but still not up to par as of yet. Getting a little
>> better each day and hope the coming months will bring me back to once
>> again feeling like a human :>)
>>
>> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY]
>>
>
> I'm glad to hear you're on the mend. As for the legacy keys, try taking
> ownership of them or delete them from outside the OS.
>
> Take care,
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers
> www.elephantboycomputers.com
> Don't Panic!
My System SpecsSystem Spec
Old 04-12-2008   #16 (permalink)
SG


 
 

Re: Rouge Process I cannot get rid of. SOLVED

Hi Malke,

Well I finally managed to get rid of the rouge registry branches.
As I stated before nothing I did would let you modify or delete anything
under the
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY]

This afternoon I ran across a Blog by Aaron Stebner that deals with solving
setup errors by using the SubInACL tool to repair Registry permissions.
Although I had no setup errors, it got me thinking about the permissions
part of his article. I followed his steps and ran the reset.cmd he describes
and low and behold even without a reboot I was able to delete all 5 of the
rouge branches without a hitch.
AMWXRYTJRQBV
FLBPKKMMZXYZ
JRBJXZ
NSC
ZWLAMI

His Blog about this is here....
http://blogs.msdn.com/astebner/archi...04/739820.aspx

This is a keeper and just my help many out there with other problems as
well. Glad to have solved this although I had already got rid of the paths
to the EXE's and stopped the services from running. It's just the rouge
Branches bothered me because no matter what I did I could not remove them.

--
All the best,
SG

Is your computer system ready for Vista?
https://winqual.microsoft.com/hcl/

"Malke" <malke@xxxxxx> wrote in message
news:%23B$4KnykIHA.6032@xxxxxx
Quote:

> SG wrote:
>
Quote:

>> Malke,
>>
>> Wanted to post my results back to you and MikeP.
>> I was able to get rid of the AMWXRYTJRQBV.EXE and four others that I
>> found
>> in the Registry. However, I could only delete the branch that ended with
>> the file names themselves, their were 4 each ,but this did get rid of the
>> Processes running. The following Branch still remains, but no harm to the
>> system and the files are gone as with the Registry entries. Still not
>> sure
>> why I cannot delete anything under this LEGACY Branch or how it was
>> written to, but the system is fine and in the end is all that matters.
>> Sorry it took so long to reply, I've posted a few reply's in these groups
>> the past few weeks, but still not up to par as of yet. Getting a little
>> better each day and hope the coming months will bring me back to once
>> again feeling like a human :>)
>>
>> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY]
>>
>
> I'm glad to hear you're on the mend. As for the legacy keys, try taking
> ownership of them or delete them from outside the OS.
>
> Take care,
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers
> www.elephantboycomputers.com
> Don't Panic!
My System SpecsSystem Spec
Old 04-12-2008   #17 (permalink)
Malke


 
 

Re: Rouge Process I cannot get rid of. SOLVED

SG wrote:
Quote:

> Hi Malke,
>
> Well I finally managed to get rid of the rouge registry branches.
> As I stated before nothing I did would let you modify or delete anything
> under the
> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY]
>
> This afternoon I ran across a Blog by Aaron Stebner that deals with
> solving setup errors by using the SubInACL tool to repair Registry
> permissions. Although I had no setup errors, it got me thinking about the
> permissions part of his article. I followed his steps and ran the
> reset.cmd he describes and low and behold even without a reboot I was able
> to delete all 5 of the rouge branches without a hitch.
> AMWXRYTJRQBV
> FLBPKKMMZXYZ
> JRBJXZ
> NSC
> ZWLAMI
>
> His Blog about this is here....
> http://blogs.msdn.com/astebner/archi...04/739820.aspx
>
> This is a keeper and just my help many out there with other problems as
> well. Glad to have solved this although I had already got rid of the paths
> to the EXE's and stopped the services from running. It's just the rouge
> Branches bothered me because no matter what I did I could not remove them.
>
Thanks for the update and the link. Glad to hear everything is going well
now.

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!
My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Failover Guest Cluster -- 'The process cannot access the file becauseit is being used by another process.' Virtual Server
Process ids Vista General
Process count wrong when only one process matches criteria PowerShell
get-process & stop-process by owner PowerShell
Bug? Shouldn't Stop-Process automatically match Id if object is a process? PowerShell


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46