RegCreateKeyEx failed; code 5

Solved
Thread Status:
Not open for further replies.
  1. Phantom Lord

    Phantom Lord New Member Bronze Member

    Joined:
    Jun 12, 2009
    Posts:
    27
    Likes Received:
    0
    Local time:
    06:13
    My System
    Loading...

    Hi guys!! I open a new post 'cause i searched on the forum for similar ones but i haven't found one that corresponds exactly to my problem. When I install programs (specifically K-Lite Megapack, but it happened with other programs too), before the installation terminates, suddenly an error message appears, saying

    Error creating registry key:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\KLiteCodecPack_is1

    RegCreateKeyExFailed; code 5.
    Accesso negato [Denied Access... i have Windows in italian :p]

    I searched for this problem on some forums and they all say it may be a permission problem, so i checked the permissions on regedit but they seem to be ok. I tried to specify my own user name, even though my profile already has the administrators' permissions, but it was useless.
    But before posting i read your prework instructions ad installed Malwarebytes, and it didn't give any problems. Please help me :eek:Z
  2. Smokeycheech

    Smokeycheech Well-Known Member Elite Member PCHF $Donator

    Joined:
    Dec 18, 2005
    Posts:
    6,521
    Likes Received:
    848
    Location:
    Skynet HQ (kinda near PCHF bunker)
    Local time:
    05:13
    My System
    Loading...

    Hello Phantom Lord, and welcome to PCHF! :)

    We have a great team of techs here who I am sure will be able to help you with your problem promptly!

    You say that you followed the prework link - great!

    Would it be possible for you to post the corresponding logs anyway?
    One of our security team may pick something up in it that you or I might miss ;)

    I look forward to you response!

    Regards,

    Smokeycheech :D
  3. Phantom Lord

    Phantom Lord New Member Bronze Member

    Joined:
    Jun 12, 2009
    Posts:
    27
    Likes Received:
    0
    Local time:
    06:13
    My System
    Loading...

    Well, I have some logs but I don't understand which one do you mean... the hjt or malwarebytes' one?

    (p.s. i talked to my tech now and he says it may be a firewall conflict... what do you think about that?)

    thanx ^^
  4. Smokeycheech

    Smokeycheech Well-Known Member Elite Member PCHF $Donator

    Joined:
    Dec 18, 2005
    Posts:
    6,521
    Likes Received:
    848
    Location:
    Skynet HQ (kinda near PCHF bunker)
    Local time:
    05:13
    My System
    Loading...

    I am not so sure about it being a firewall conflict, but I by no means an expert in this area!

    If you could copy and past both the Hijackthis and Malwarebytes logs we can get a technician to look them over and this will give us a better idea as to what is going on ;)

    Regards,

    Smokeycheech :D
  5. Phantom Lord

    Phantom Lord New Member Bronze Member

    Joined:
    Jun 12, 2009
    Posts:
    27
    Likes Received:
    0
    Local time:
    06:13
    My System
    Loading...

    This is the Malwarebytes' log file. It is in italian, so I translate the lines talking about positives.

    Malwarebytes' Anti-Malware 1.37
    Versione del database: 2265
    Windows 5.1.2600 Service Pack 3

    12/06/2009 13.58.28
    mbam-log-2009-06-12 (13-58-28).txt

    Tipo di scansione: Scansione completa (C:\|)
    Elementi scansionati: 276400
    Tempo trascorso: 1 hour(s), 18 minute(s), 40 second(s)

    Processi delle memoria infetti: 0
    Moduli della memoria infetti: 0
    Chiavi di registro infette: 0
    Valori di registro infetti: 0
    Elementi dato del registro infetti: 1 [Infected Registry Items]
    Cartelle infette: 0
    File infetti: 1 [Infected Files]

    Processi delle memoria infetti:
    (Nessun elemento malevolo rilevato)

    Moduli della memoria infetti:
    (Nessun elemento malevolo rilevato)

    Chiavi di registro infette:
    (Nessun elemento malevolo rilevato)

    Valori di registro infetti:
    (Nessun elemento malevolo rilevato)

    Elementi dato del registro infetti: [Infected Registry Items]
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Cartelle infette:
    (Nessun elemento malevolo rilevato)

    File infetti: [Infected Files]
    c:\system volume information\_restore{eb17c91d-6f24-4899-93e1-d643b10b0f84}\RP941\A0487096.exe (Malware.Tool) -> Quarantined and deleted successfully.


    Anyway, the problem has not been resolved with the scan...
  6. Phantom Lord

    Phantom Lord New Member Bronze Member

    Joined:
    Jun 12, 2009
    Posts:
    27
    Likes Received:
    0
    Local time:
    06:13
    My System
    Loading...

    This is the HJT log that on the contrary is in english:

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 22.42.05, on 12/06/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmi\Comodo\COMODO Internet Security\cmdagent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmi\Windows Defender\MsMpEng.exe
    C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
    C:\Programmi\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programmi\Comodo\CBOClean\BOCORE.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Programmi\File comuni\Microsoft Shared\VS7Debug\mdm.exe
    C:\Programmi\NetLimiter 2 Pro\nlsvc.exe
    C:\Programmi\NVIDIA Corporation\nTune\nTuneService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Programmi\Raxco\PerfectDisk\PDAgent.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
    C:\Programmi\Raxco\PerfectDisk\PDEngine.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Programmi\Process Lasso\processlasso.exe
    C:\Programmi\Comodo\COMODO Internet Security\cfp.exe
    C:\Programmi\Process Lasso\processgovernor.exe
    C:\Programmi\PeerGuardian2\pg2.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\FirefoxPreloader\FirefoxPreloader.exe
    C:\Programmi\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Programmi\HijackThis\HiJackThis_v2.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/******/*************
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/******/*************
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [ProcessSupervisorGUI] C:\Programmi\Process Lasso\processlasso.exe
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Programmi\Comodo\COMODO Internet Security\cfp.exe" -h
    O4 - HKLM\..\Run: [COMODO System Cleaner SafeDelete] "C:\Programmi\Comodo\System Cleaner\CSC.EXE" //safedeletion
    O4 - HKCU\..\Run: [PeerGuardian] C:\Programmi\PeerGuardian2\pg2.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
    O4 - Startup: AutorunsDisabled
    O4 - Global Startup: AutorunsDisabled
    O4 - Global Startup: Firefox Preloader.lnk = C:\Programmi\FirefoxPreloader\FirefoxPreloader.exe
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Guida alla connessione - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Guida alla connessione - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://************.spaces.live.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/************.cab
    O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.5.0) -
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
    O17 - HKLM\System\CCS\Services\Tcpip\..\{62A29C27-EFCA-4A95-9610-838FEBEF5BA0}: NameServer = 195.110.128.1,212.48.4.11
    O20 - AppInit_DLLs:
    O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.DLL
    O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: BOCore - COMODO - C:\Programmi\Comodo\CBOClean\BOCORE.exe
    O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Programmi\Comodo\COMODO Internet Security\cmdagent.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
    O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Programmi\NetLimiter 2 Pro\nlsvc.exe
    O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Programmi\NVIDIA Corporation\nTune\nTuneService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PDAgent - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDAgent.exe
    O23 - Service: PDEngine - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDEngine.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 7142 bytes
  7. Pancake

    Pancake Well-Known Member

    Joined:
    Jun 1, 2006
    Posts:
    4,104
    Likes Received:
    12
    Location:
    Victoria, Australia
    Local time:
    14:13
    My System
    Loading...

    Ok.Glad it has been fixed..
  8. Phantom Lord

    Phantom Lord New Member Bronze Member

    Joined:
    Jun 12, 2009
    Posts:
    27
    Likes Received:
    0
    Local time:
    06:13
    My System
    Loading...

    Well, it has not been fixed yet, actually... plz don't leave me alone guys :'( (lol)
  9. Pancake

    Pancake Well-Known Member

    Joined:
    Jun 1, 2006
    Posts:
    4,104
    Likes Received:
    12
    Location:
    Victoria, Australia
    Local time:
    14:13
    My System
    Loading...

    Sorry.I read it wrong.I dont think this is a malware problem but lets see what this says.



    Go to http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html
    Answer Yes, when prompted to install an ActiveX component.
    • The program will then begin downloading the latest definition files.
    • Once the files have been downloaded click on NEXT
    • Locate the Scan Settings button & configure to:
      • Scan using the following Anti-Virus database:
        • Extended
      • Scan Options:
        • Scan Archives
          [*]Scan Mail Bases
    • Click OK & have it scan My Computer
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
      [​IMG]

      [​IMG]
    • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
    * Turn off the real time scanner of any existing antivirus program while performing the online scan
  10. Phantom Lord

    Phantom Lord New Member Bronze Member

    Joined:
    Jun 12, 2009
    Posts:
    27
    Likes Received:
    0
    Local time:
    06:13
    My System
    Loading...

    ok i will do that thanx
  11. Phantom Lord

    Phantom Lord New Member Bronze Member

    Joined:
    Jun 12, 2009
    Posts:
    27
    Likes Received:
    0
    Local time:
    06:13
    My System
    Loading...

    ok guys this is the log of kaspersky online:

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0 REPORT
    Sunday, June 14, 2009
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Program database last update: Sunday, June 14, 2009 12:36:24
    Records in database: 2342804
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    C:\
    D:\
    E:\
    F:\
    J:\
    K:\
    L:\
    M:\

    Scan statistics:
    Files scanned: 154318
    Threat name: 1
    Infected objects: 1
    Suspicious objects: 0
    Duration of the scan: 03:50:29


    File name / Threat name / Threats count
    C:\Programmi\Bluetack\Blocklist Manager\Tools\ipscan.exe Infected: not-a-virus:NetTool.Win32.Portscan.c 1

    The selected area was scanned.



    ipscan.exe is detected by many antiviruses/antispywares but seems to be a false positive. I don't know if it is related to the topic. Btw i tried to unload firefox.exe which is loaded by firefox preloader, 'cause the K-Lite installer I took from the original website asked to close firefox.exe. I thought that was the main problem, but the installation still doesn't work. I'm gonna go to Lourdes :D
  12. Pancake

    Pancake Well-Known Member

    Joined:
    Jun 1, 2006
    Posts:
    4,104
    Likes Received:
    12
    Location:
    Victoria, Australia
    Local time:
    14:13
    My System
    Loading...

    Well it looks as if you problem is not malware related...looks as if you will have to look elsewhere.
  13. Phantom Lord

    Phantom Lord New Member Bronze Member

    Joined:
    Jun 12, 2009
    Posts:
    27
    Likes Received:
    0
    Local time:
    06:13
    My System
    Loading...

    well at least I managed in securing the pc :D... so what do you think I can do?
  14. Pancake

    Pancake Well-Known Member

    Joined:
    Jun 1, 2006
    Posts:
    4,104
    Likes Received:
    12
    Location:
    Victoria, Australia
    Local time:
    14:13
    My System
    Loading...

    I will get one of the other tech to see if they can help.
  15. jay2

    jay2 Games developer/shop owner Tech Member Elite Member

    Joined:
    Jun 8, 2008
    Posts:
    1,544
    Likes Received:
    99
    Location:
    in the pic ;)
    Local time:
    05:13
    My System
    Loading...

    Hi.
    Can you do this please
    Start-Run type regedit.
    go to

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Uninstall\KLiteCodecPack_is1

    Right click on the KLiteCodecPack_is1 key and select permissions. See if the username that you are installing with has full permissions on that key
    Also try it with the others from Uninstall.
Similar Threads
Forum Title Date
System Security RegCreateKeyEx Failed: code 5 Jul 31, 2007
System Security RegCreateKeyEx failed; code 5, Access is Denied Nov 29, 2006
System Security Cocreateinstance Failed Malwarebytes 0×80040154 error message Jan 12, 2013
System Security Windows Delayed Write Failed Oct 26, 2011

Thread Status:
Not open for further replies.