Author Topic: Unable to Delete ALL Specified Values (2)  (Read 15193 times)

0 Members and 1 Guest are viewing this topic.

So2L

  • Guest
Unable to Delete ALL Specified Values (2)
« on: December 12, 2012, 05:41:45 AM »
I'm sorry for the Delay but My PC wont let me Reply to http://forum.avast.com/index.php?topic=111078.0
BUT I did manage to get 3 Log Files, except for aswMBR as it kept getting Hung-up all the time.
Thank You for your Help & Patience.

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: Unable to Delete ALL Specified Values (2)
« Reply #1 on: December 12, 2012, 11:01:52 AM »
hqy and welcome to the forum. a amlware expert will guide you from here when one is online.

about the aswmbr have you tried to run it in safemode?
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Unable to Delete ALL Specified Values (2)
« Reply #2 on: December 12, 2012, 03:16:59 PM »
OK lets kill those bits first and then see if there is a reason that aswMBR hung

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:OTL
O4 - HKU\S-1-5-21-2601973988-1143446372-3340486091-1001..\Run: [] C:\Users\So2L\Local Settings\Application Data\vghd.exe File not found
F3:64bit: - HKU\S-1-5-21-2601973988-1143446372-3340486091-1001 WinNT: Load - (C:\Users\So2L\LOCALS~1\Temp\msjemt.cmd) - File not found
F3 - HKU\S-1-5-21-2601973988-1143446372-3340486091-1001 WinNT: Load - (C:\Users\So2L\LOCALS~1\Temp\msjemt.cmd) - File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 6484 = C:\PROGRA~3\LOCALS~1\Temp\msicrtz.com
@Alternate Data Stream - 5632 bytes -> C:\ProgramData:gs5sys
@Alternate Data Stream - 4096 bytes -> C:\Users\So2L\Documents\desktop.ini:gs5sys
@Alternate Data Stream - 4096 bytes -> C:\Users\So2L\Desktop\desktop.ini:gs5sys
@Alternate Data Stream - 4096 bytes -> C:\Users\Public\Documents\desktop.ini:gs5sys

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Download the latest version of TDSSKiller from here and save it to your Desktop.
 
 
  • Doubleclick on TDSSKiller.exe to run the application


  • Then click on Change parameters.
     

     
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
     
  • Click the Start Scan button.
     
     
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
     

     
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

  • Get the report by selecting Reports

 
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
Please copy and paste its contents on your next reply.

So2L

  • Guest
Re: Unable to Delete ALL Specified Values (2)
« Reply #3 on: December 13, 2012, 01:07:36 AM »
Ok, I did all you asked. I really hope you can find the problem & have a solution.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: Unable to Delete ALL Specified Values (2)
« Reply #4 on: December 13, 2012, 01:10:16 AM »
There may be some delay due to differing time zones and essexboy's availability

It is now after midnight in the UK so essexboy is likely to be in bed now and will be back later today.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

So2L

  • Guest
Re: Unable to Delete ALL Specified Values (2)
« Reply #5 on: December 13, 2012, 01:15:01 AM »
Oh Ok. I'm not going to use My PC untill I can get this resolved. Thank You very much.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: Unable to Delete ALL Specified Values (2)
« Reply #6 on: December 13, 2012, 01:21:50 AM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

So2L

  • Guest
Re: Unable to Delete ALL Specified Values (2)
« Reply #7 on: December 13, 2012, 03:07:20 AM »
Should I run aswMBR in Safemode right now as stated by mikaelrask or should I just wait?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: Unable to Delete ALL Specified Values (2)
« Reply #8 on: December 13, 2012, 03:14:42 AM »
Should I run aswMBR in Safemode right now as stated by mikaelrask or should I just wait?
you may....it will not do any harm as long as you only save the log....dont click any fix buttons  ;)
« Last Edit: December 13, 2012, 03:18:25 AM by Pondus »

So2L

  • Guest
Re: Unable to Delete ALL Specified Values (2)
« Reply #9 on: December 13, 2012, 04:04:23 AM »
Ok, I tried but when I rebooted into Safemode I couldn't find aswMBR on My Desktop. I typed it in The Search Box in The Startmenu in Safemode but couldn't locate it. Edit: Well I just tried to run aswMBR not in Safemode and after 3 min it crashed into a Windows BlueScreen Error.
« Last Edit: December 13, 2012, 09:37:32 AM by So2L »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Unable to Delete ALL Specified Values (2)
« Reply #10 on: December 13, 2012, 06:56:23 PM »
Not a problem on aswMBR that does occur on some systems

The run and F3 keys should now be gone could you confirm that with a fresh MBAM run please

So2L

  • Guest
Re: Unable to Delete ALL Specified Values (2)
« Reply #11 on: December 13, 2012, 09:09:37 PM »
Sure Thanks, &, I have one other Problem I hope you can help me with. Since I got that FBI MoneyPak Virus My PC has been rebooting on its own every 15-30 min or so especially when I'm not at My PC. Is there anyway you can show me a program or something so you can diagnose why its doing that? I'm really Thankful for your Help & everybody that helps me.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Unable to Delete ALL Specified Values (2)
« Reply #12 on: December 13, 2012, 09:12:16 PM »
Sounds like it may be a temperature problem

Download Speedfan and install it. 
Once it's installed, run the program and post here the information it shows. 
The information I want you to post is the stuff that is circled in the example picture I have attached.
If you are running on a vista machine, please go to where you installed the program and run the program as administrator.


(this is a screenshot from a vista machine)

So2L

  • Guest
Re: Unable to Delete ALL Specified Values (2)
« Reply #13 on: December 13, 2012, 09:22:06 PM »
I took a Screenshot. There was a Fireball next to Temp2 I believe but it went away. Edit: Crud, Im so sorry, was I supposed to get SpeedFan v4.38?
« Last Edit: December 13, 2012, 09:24:18 PM by So2L »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Unable to Delete ALL Specified Values (2)
« Reply #14 on: December 13, 2012, 09:25:33 PM »
No its is just that I have not updated my screenshots  ;D

Do you have any dump files in C:\windows\minidumps ?