Author Topic: Unable to Delete ALL Specified Values  (Read 6264 times)

0 Members and 1 Guest are viewing this topic.

So2L

  • Guest
Unable to Delete ALL Specified Values
« on: December 11, 2012, 06:39:52 AM »
Hello Everybody,
I'm *NEW* & I really need your Help

I got a FBI Moneypak Virus Last Week & totally locked me out of Windows 7, it must of been an Updated Version and I got rid of it except the Registry Keys.  Avast FREE don't detect the keys I think but Malwarebytes Anti-Malware found these Keys.
 
Registry Values Detected: 3
 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (PUM.UserWLoad) -> Data: C:\Users\So2L\LOCALS~1\Temp\msjemt.cmd -> Delete on reboot.
 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (Trojan.Ransom) -> Data: C:\Users\So2L\LOCALS~1\Temp\msjemt.cmd -> Delete on reboot.
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|6484 (Trojan.Agent) -> Data: C:\PROGRA~3\LOCALS~1\Temp\msicrtz.com -> Delete on reboot.
 
The Keys keep on comming back. I tried to delete them manually but it says Unable to Delete ALL Specified Values. My PC is 4 Months old.
Now My PC is starting to reboot itself every 25 min or so. When I 1st got the virus I rebooted in SafeMode and ran MalwareBytes to get rid of the main
 Virus so I could get back to Windows then I got AVAST Free and Ran it and found nothing.
 Do you need me to post a Log or something? I had Nortons Internet Security 2012 & Windows Defender but My Nortons Expired last month. I didn't have any protection for a
 Month. I know I'm a Dummy for Surfing The Net without Protection but I caught the Moneypak Virus a week ago and Norton's was Expired at the Time. I had to reboot in Safemode & ran MalwareBytes & It found the Virus & got it out because I was locked out of Windows then when I got back into Windows I unistalled Nortons and installed Avast Free. I asked My sister and she said it might be a rootkit or something. I will try everything you can help with. Thank You Very Much.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Unable to Delete ALL Specified Values
« Reply #1 on: December 11, 2012, 06:47:47 AM »
Please attach your logs. (AdwCleaner, MBAM, OTL and aswMBR..!!)
Instructions: http://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Unable to Delete ALL Specified Values
« Reply #2 on: December 11, 2012, 07:36:54 AM »
malwarebytes is designed to work best in normal mode...
so only run it in safe mode if there is a problem...