Jump to content

Restrictions & PUM.Hijack.

Recommended Posts

I was doing a screenshot of a youtube clip and trying to paste it into paint, when I tried to save the file to my pictures I got a window error "This operation has been cancelled due to restrictions in effect on this computer. Please contact you system administrator." All of a sudden Malwarebytes started to quarantine some PUP's. When I go into My Computer/This PC I cannot see any of my 3 disk drives. I have my OS and a few programs such as my browser on my SSD and the rest are split between two HDDs.


So at the moment file explorer grants me no access to my documents at all...I tried to plug in my usb drive, the system did it's beep sound to detect the drive, but nothing shows up in My Computer/This PC, and the folder doesn't autoload either. I do have Avast Free as well as spyware blaster and spybot s&d.  Did I get a virus? What happened? How can I fix this?


Please help :(





Malwarebytes Anti-Malware



Scan Date: 6/17/2014

Scan Time: 10:38:44 AM


Administrator: Yes



Malware Database: v2014.06.17.05

Rootkit Database: v2014.06.02.01

License: Premium

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled


OS: Windows 8.1

CPU: x64

File System: NTFS

User: Cummings


Scan Type: Threat Scan

Result: Completed

Objects Scanned: 266778

Time Elapsed: 5 min, 29 sec


Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled


Processes: 0

(No malicious items detected)


Modules: 0

(No malicious items detected)


Registry Keys: 0

(No malicious items detected)


Registry Values: 0

(No malicious items detected)


Registry Data: 5

PUM.Hijack.Run, HKU\S-1-5-21-3870333655-2615791586-3426683706-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|NoRun, 1, Good: (0), Bad: (1),Replaced,[0683f287fc7fee487649205521e33fc1]

PUM.Hijack.DisplayProperties, HKU\S-1-5-21-3870333655-2615791586-3426683706-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|NoSetActiveDesktop, 1, Good: (0), Bad: (1),Replaced,[e7a20b6ef08b082e91abc2b39d67d927]

PUM.Hijack.Explorer, HKU\S-1-5-21-3870333655-2615791586-3426683706-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|NoSetFolders, 1, Good: (0), Bad: (1),Replaced,[bdcce9902259bb7bd9ad2351af55c937]

PUM.Hijack.TaskManager, HKU\S-1-5-21-3870333655-2615791586-3426683706-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM|DisableTaskMgr, 1, Good: (0), Bad: (1),Replaced,[d1b87405bcbf8aac69b5b0c790745da3]

PUM.RightClick.Disabled, HKU\S-1-5-21-3870333655-2615791586-3426683706-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\POLICIES\MICROSOFT\INTERNET EXPLORER\RESTRICTIONS|NoBrowserContextMenu, 1, Good: (0), Bad: (1),Replaced,[3e4b1564740762d4d5828be7d82cd52b]


Folders: 0

(No malicious items detected)


Files: 0

(No malicious items detected)


Physical Sectors: 0

(No malicious items detected)




Link to post
Share on other sites

Hi,SemperAye, and :welcome:



It seems as if you have been infected with something, and those Hijack attempts that MBAM has already removed may be an indication of something worse on your system.


I suggest that you read the following topic http://forums.malwarebytes.org/index.php?showtopic=119858 and then decide upon your course of actions, and select the appropriate link there, and then follow the instructions in the new page.


Good luck!

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.