Delete Registry Key when Access Denied

While reading this interesting article about a rootkit installed on a DRM protected Sony CD, I learned this little trick on how to remove registry keys that can't be deleted even under an administrative login.  I always assumed that the Admin accounts could erase bits of the registry owned by Local System, but I guess not.

Article: http://www.sysinternals.com/blog/2005/10/sony-rootkits-and-digital-rights.html

Snippet:

"so I relaunched Regedit in the Local System account using PSExec: psexec –s –i –d regedit.exe. I retried the delete"

 
 
tags: psexec, localsystem, local system,
Related Scribbles:
  • Registry Tools


  • ID: 708
    Author:
    leonard
    Date Updated:
    2018-08-07 17:22:48
    Date Created:
    2005-10-31 15:57:11

    Edit

    Comments?
     >> Leonard Chan's Homepage  >> Scribble Web  >> Delete Registry Key when Access Denied
    leonard.lotus-land.ca is hosted by Perceptus Solutions Inc.