Wednesday, August 19, 2009

Found this entry in my registry could it be a root kit?

HKEY_CURRENT_USER\Software\SecuRom\!CAUT... NEVER DELETE OR CHANGE ANY KEY]



Antivirus or rootkit detectors have not picked it up as malware.



Found this entry in my registry could it be a root kit?nortin



Yes it is Sony's rootkit. If you search for Securom then you will find tutorials on how to remove it.



http://en.wikipedia.org/wiki/SecuROM



Found this entry in my registry could it be a root kit?pc security



Search your computer for "securom". If nothing shows up (i.e. in Program Files) then delete it.
How to manually remove SonyBMG's Rootkit from your XP machine.



First unplug your source of internet. Then hit ctrl+alt+del, and click the process tab. Find $sys$DRMserver.exe and end this proccess.



Go to start, then run, type in "regedit" and then enter.



Delete these keys:



HKEY_Local_Machine\SYSTEM\CurrentContr...



HKEY_Local_Machine\SYSTEM\CurrentContr...



HKEY_Local_Machine\SYSTEM\CurrentContr...



HKEY_Local_Machine\SOFTWARE\$sys$Refer...



HKEY_Local_Machine\SONYBMG



Go to www.sysinternals.com download pstools, unzip them, and then put them in C:\Windows\System32. Not in a folder, but all the individual files. You will be asked if you want to replace the dll file, and say yes, or yes to all.

No comments:

Post a Comment