Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unable to delete link #2

Open
chic01taliano opened this issue Feb 7, 2020 · 14 comments
Open

Unable to delete link #2

chic01taliano opened this issue Feb 7, 2020 · 14 comments

Comments

@chic01taliano
Copy link

I have a registry key that I cannot delete. If I try to click on or delete the key, I get the error "An error is preventing this key from being opened. Details: The system cannot find the file specified." If I try to delete the branch, I get a generic "error while deleting key"

The key is "HKU\S-1-5-21-3149309343-1769326203-569191401-1001_Classes\WOW6432Node\CLSID{130F8154-E804-4BD5-A07B-35BE69039715}{A730F6F3-255C-417C-8986-2C578500547E}"

When trying with regln it gives me no output at all. Am i doing it wrong?
Thanks

@tenox7
Copy link
Owner

tenox7 commented Feb 11, 2020

Interesting!

Can you send me the full command for regln?

Also what do you mean by regln gives no output? Are you running it in cmd with admin privileges?

@chic01taliano
Copy link
Author

chic01taliano commented Feb 11, 2020

Can you send me the full command for regln?

regln-64.exe "HKU\S-1-5-21-3149309343-1769326203-569191401-1001_Classes\WOW6432Node\CLSID\{130F8154-E804-4BD5-A07B-35BE69039715}\{A730F6F3-255C-417C-8986-2C578500547E}"

Also what do you mean by regln gives no output? Are you running it in cmd with admin privileges?

PowerShell with Administrator privileges.

regln

@tenox7
Copy link
Owner

tenox7 commented Feb 12, 2020

How do you know that the key {A730F6F3-255C-417C-8986-2C578500547E} is a link? Did you create it with regln?

@chic01taliano
Copy link
Author

chic01taliano commented Feb 13, 2020

How do you know that the key {A730F6F3-255C-417C-8986-2C578500547E} is a link?

I have detected the symlink using this tool

aaa

Their frontpage recommended regln to manipulate such keys.

Did you create it with regln?

It has been created by mp3jam. I know that because i use Total Uninstall in order to monitor and uninstall any software remnants. Total Uninstall was unable to delete the issue key upon uninstalling mp3jam.

@tenox7
Copy link
Owner

tenox7 commented Feb 13, 2020

Oh very interesting. Also never heard of this tool, thank you! I will try to reproduce it myself. However in the mean time I would recommend trying to delete it from 32bit side. I think syswow64 may be the issue. Open up 32bit regedit from c:\windows\syswow64, then find the right key and then use 32bit regln to delete it.

@chic01taliano
Copy link
Author

I've tried the x86 version without success

Immagine1

Is it possible that i'm dealing with a symlink that contains null characters?

Immagine2

Maybe regln doesn't work under those conditions but neither RegDelNull seems to be able to
solve it.

@tenox7
Copy link
Owner

tenox7 commented Feb 15, 2020

I will try to reproduce it. What I would recommend is get procmon from systeinrnals, set the filter for registry and regln.exe only and see if it can show you any errors.

@chic01taliano
Copy link
Author

Nothing seems to be out of the ordinary. Here are the results.

procmonResults.zip

@ScriptingDad
Copy link

I actually resolved the issue just now.
I was trying to figure out the problem and used Procmon as you suggested.
I noticed that I was getting the folder not found from the wrong path. This is the command I used to create the original session.

regln-x64.exe HKU\S-1-5-21-2116825684-2010480077-1094980219-221116\Software\SimonTathem\Putty\Sessions HKU\S-1-5-21-2116825684-2010480077-1094980219-221116\Software\9bis.com\KiTTY\Sessions

After I created the link the first time and it still didn't work (MRemoteNG wasn't working still) I tried deleting the key to try again. What appears to have happened was that it deleted the Sessions key under KiTTY and then I tried recreating the key again which created a key associated to nothing.

HKCU\Software\SimonTathem\PuTTY\Sessions > HKCU\Software\9bis.com\KiTTY\Sessions
# except HKCU\Software\9bis.com\KiTTY\Sessions doesn't exist. 

I recreated the key under Kitty and was able to remove the Sessions key under putty.

@tenox7
Copy link
Owner

tenox7 commented Sep 2, 2020

Awesome thank you. Please also note that it's impossible to create links under HKCU, but I think you noticed that since your regln command line uses HKU.

@tenox7 tenox7 closed this as completed Sep 2, 2020
@chic01taliano
Copy link
Author

I still fail to relate @ScriptingDad 's solution to mine and yet the issue has been closed. Ok.

@tenox7 tenox7 reopened this Sep 2, 2020
@tenox7
Copy link
Owner

tenox7 commented Sep 2, 2020

OK reponened, my apologies I thought this was resolved.
Let me look at it again.

@innocent668
Copy link

I had the same problem as described by @chic01taliano, so I was sceptical that regln would work, but it did. So maybe it got fixed in the meantime. Just wanted to inform you :)

@chic01taliano
Copy link
Author

I do not have such a problem anymore since i've installed a fresh copy of windows but there's been no new update to the software since then. In any case, thanks for chiming in.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants