Windows 10: A ransom virus has deleted my windows defender registry

Discus and support A ransom virus has deleted my windows defender registry in AntiVirus, Firewalls and System Security to solve the problem; Yesterday i've been hit by ransomware virus. I could log in to my pc but some of my files were encrypted. It took control of my kaspersky any virus... Discussion in 'AntiVirus, Firewalls and System Security' started by Muhammed Abdel-Hami, Jan 11, 2019.

  1. A ransom virus has deleted my windows defender registry


    Yesterday i've been hit by ransomware virus.

    I could log in to my pc but some of my files were encrypted.

    It took control of my kaspersky any virus and windows defender.

    I tried clean install then tried to scan my pc using windows defender but it appears that the virus deleted WD registry files


    What should i do to fix this and to be sure that i don't have the virus anymore ?

    :)
     
    Muhammed Abdel-Hami, Jan 11, 2019
    #1
  2. djbbenn Win User

    New Trojan that Demands a Ransom

    There is a new virus out there discovered by virus hunters known as "Cryzip". The Trojan encrypts your files and then demands a $300 ransom for the decryption password to get your files back. After encrypting the files, the virus leaves a nice step-by-step guide of how to go about paying the ransom off. It's supposedly spread through email Spam, and has successfully evaded anti-virus scanners.

    Source: eWeek
     
    djbbenn, Jan 11, 2019
    #2
  3. Cannot turn on Windows Defender virus protection

    I had the same sort of symptoms. In the Windows Security Center, under Virus and threat protection, it said "Your virus & threat protection is managed by your organization."


    A ransom virus has deleted my windows defender registry wm5Jc.png


    I note you mentioned the Registry Keys under HKLM/SOFTWARE/Microsoft/Windows Defender. Nice spotting, but it seems like there is another key that is causing the problem for some users.

    Steps to a solution:

    1. Press the Windows key and type "regedit"
    2. On the regedit icon that appears, right-click and select Run as Administrator.
    3. Navigate to the folder located at HKLM\SOFTWARE\Policies\Microsoft\Windows Defender (You can paste this into the address box at the top of the window, or navigate manually using the side directory structure)
    4. In this folder, there are probably two keys. Right-click and Delete the DisableAntiSpyware key.
    5. Exit regedit, and return to the Windows Defender settings screen (refresh it if necessary). Windows Defender should have the scan options available and working.

    Solution adapted from here, with a much more detailed solution here.
     
    MechtEngineer, Jan 11, 2019
    #3
  4. A ransom virus has deleted my windows defender registry

    Windows Defender realtime scanning will not switch on - it detects another anti-virus product.

    Windows Defender realtime scanning will not switch on, and the message suggests there is another anti-virus product present but if there is it does show up in Window 10 UI.

    The long story is that I am troubleshooting a problem with application software. The manufacturer suggest removing Bitdefender because there product is incompatible. I thought I would give this a try, if only to element Bitdefender as a cause.

    Firstly, I upgraded from Bitdefender 2016 to 2017 to see if that made a difference. The application still failed so I decided to try removal.

    • I used the standard uninstall to remove Bitdefender 2017, rebooted but Windows Defender would not start realtime protection because another product was providing realtime protection
    • I download the uninstall application for Bitdefender 2017, ran it then rebooted but Windows Defender would not start realtime protection because another product was providing realtime protection
    • I checked the file system and all Bitdefender files have been deleted.
    • I check the registry and found a couple of references to Bitdefender Wallet, then deleted these.
    • I rebooted but Windows Defender would not start realtime protection because another product was providing realtime protection
    • I reran the uninstall application for Bitdefender 2017 then rebooted but Windows Defender would not start realtime protection because another product was providing realtime protection.
    I can find no traces of Bitdefender so I wonder why Windows Defender detects another anti-virus software. I've check other posts but couldn't find additional steps for uninstalling an anti-virus software. Any suggestions?

    Moved from Windows 10
     
    SystemOfTheWorld, Jan 11, 2019
    #4
Thema:

A ransom virus has deleted my windows defender registry

Loading...
  1. A ransom virus has deleted my windows defender registry - Similar Threads - ransom virus has

  2. Windows Defender - Virus and Threat Protection - Threat service has stopped

    in AntiVirus, Firewalls and System Security
    Windows Defender - Virus and Threat Protection - Threat service has stopped: Hi, I recently had malware on my pc and windows defender was unable to remove it. I used some malware removers (rogue killer, unhackme and awdcleaner) and got rid of the malware. But in the process I think I also removed MsMpeng.exe which if the exe file of windows defender...
  3. Ransom virus attack

    in AntiVirus, Firewalls and System Security
    Ransom virus attack: Hi sir i am working at my computer when i saw a windows update pop up then i say my all files convert to .udjvu and encrypted please help me this pc is my office pc. I lose my job if data not give back to him[IMG]...
  4. Windows defender Virus Protection

    in AntiVirus, Firewalls and System Security
    Windows defender Virus Protection: I had uninstalled Third Party Antivirus Software after its validy After that I can not able to switch on Windows Defender Virus Protection . It is showing message your virus and protection is managed by your organization Pl help to restore the setting by switching on...
  5. Windows defender saying that my program is a virus

    in AntiVirus, Firewalls and System Security
    Windows defender saying that my program is a virus: Hi, i want to publish my program to friends or more and for they will can download the program they need to turn off windows defender how can i remove this or do code or something that will download like a regular prgoram....
  6. My Computer Has An Ugly Virus

    in AntiVirus, Firewalls and System Security
    My Computer Has An Ugly Virus: I'm going to try to give as much information as possible so please bare with me when it comes to length. I have an hp Envy dv7 64 bit. I've had it for about 4 years. I hadn't had it long before my son accidentally kicked it off a crate that I have it sitting on for well...
  7. ransome ware

    in AntiVirus, Firewalls and System Security
    ransome ware: i have had 2 threatening emails stating they know my password which they give, but not the complete one.they say they have hacked my emails and other files and they want payment in dollars to stop it. should this have been picked up by defender?...
  8. Defender Quar'd Virus but I can't find it & delete it

    in Windows 10 Support
    Defender Quar'd Virus but I can't find it & delete it: I have a new mini pc. Updated it and Defender found a virus. But when I got to delete it the system doesn't show it anywhere. Does Defender AUTO DELETE and then forget to tell you? [img] 113095
  9. My computer has a virus

    in AntiVirus, Firewalls and System Security
    My computer has a virus: So there's two issues: 1) My computer has a virus with the svcvmx program and anything related to it. My antivirus won't start or download. I've tried everything possible I could but nothing is happening. 2) My Internet will connect but there's no Internet. I've tried...
  10. Windows registry - I cannot delete a user file in the registry

    in Windows 10 Support
    Windows registry - I cannot delete a user file in the registry: In the last week I have been redirected to a hijacked site that says "that your computer has been hijacked and you will not be able to save your files, then it says do not shutdown" Well, that's exactly what I do is I disconnect from the internet, and then I can close...