Anitivirus, Antispyware, Internet Explorer, and other Programs won't Open

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Learner17, May 18, 2013.

  1. Learner17

    Learner17 Private E-2

    Through use of my operating system, Windows Vista, on my notebook computer, I am not able to "open" or use many programs including "Internet Explorer" browser, SUPERAntiSpyware, Avira Anitivirus, Adobe Reader, etc. The message that I am getting or receiving states the following: "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

    I checked the "user controls" and noticed that all "user controls" are checked with the box indicating "allowed", except the last one. I'm not sure that this is the problem or cause of the problem.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    If you attempt to run things in safe boot mode, what happens. Also what happens if you shutdown your protection software? Can you run any programs at all? Does CTRL-ALT-DEL bring up Task Manager

    What exactly are you referring too?
     
  3. Learner17

    Learner17 Private E-2

    I think it may help to download one the utility programs that scans, checks for infections, removes infections, and adjusts or resets computers for continued access to software programs or downloading programs.

    I was thinking one method may be to save a utility software program to my "jump" drive, then attempt to download onto my infected computer. I'm not sure that this will work, but this isrolleyes a plan that I was considering.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer any of my questions!
    Well if you are now saying that you have the ability to run programs, then do the below.

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:


    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual update Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only RogueKiller and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run the rest of the READ & RUN ME FIRST instructions on the infected account.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  5. Learner17

    Learner17 Private E-2

    Responses on Questions

    I'm not able to open "pdf" files sent through email

    If I shutdown my protection software,I am still not able to open a "pdf" attachment sent through email.

    On the question about Task Manager, I am able to open Task Manager in safe boot mode. I should be able to open Task Manager in non-safe boot modes as well.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Responses on Questions

    Please follow the instructions in the READ & RUN ME FIRST link.
     
  7. Learner17

    Learner17 Private E-2

    I am having problems downloading the Defogger software program. It does not allow me download the Defogger software program.
     
  8. Learner17

    Learner17 Private E-2

    Re: "Problem with Defogger"

    I'm not able to download the Defogger software program.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just skip it and continue. Or use another PC to do the downloads if downloading of the tools is a common problem. See the helpful notes # 2 in my second post.
     
  10. Learner17

    Learner17 Private E-2

    Re: "not able to Open or Download Files"

    I am not able to open or download files such as "pdf" files and other software programs. I have attached log reports on the results.

    In safe or non-safe mode, I am not able to open or download files such "pdf" attachments through email and I am not able to download any files.

    With Task Manager, it does work and I am able to close software programs.
     

    Attached Files:

  11. Learner17

    Learner17 Private E-2

    Re: "...not able to Open or Download Files"

    I've included another file, since the limit is five. This is a follow-up to the previous email.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: "not able to Open or Download Files"

    I see you had a problem running MGtools.exe Please answer the below questions:
    1. Exactly where did you run MGtools.exe from?
    2. And did you use right click and select Run As Administrator?
    3. Did you run it in normal boot mode or safe boot mode?
    4. Also was all protection software disabled?
    5. Is User Account Control ( UAC ) disabled as requested in the READ & RUN ME?
    Rerun RogueKiller and run a scan. After it finishes the scan, select the Registry tab and then select any of the below that exist and then click the Delete button.

    Then select the Files tab and if the below exist, click the Delete button again.

    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in original instructions and attach the new log. Is there any change to the problems you were having?
     
  13. Learner17

    Learner17 Private E-2

    Re: "still Problem with Opening or Downloading "pdf" or Downloading a file

    I disabled both antivirus and firewall software and they are still disabled.
    I disabled UAC and did not re-enable UAC.
    In normal boot mode, I attempted to download MGTools program onto my desktop, but this is one of the "download" issues that I'm having. I attempted to generate a report through my USB jump drive. After the first report disappeared, after scanning, I was not able to generate a new report, other than the one provided.

    I retrieved a system log report from the MGTools folder. I'm not sure that this is helpful. Also, I performed the second operation in regards to Roguekiller. I deleted the stated code, re-scanned, re-booted, and the problem has not been corrected.

    I have attached logs for your review.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: "still Problem with Opening or Downloading "pdf" or Downloading a file

    Okay this is part of the problem. MGtools.exe MUST BE RUN from the drive Windows is installed on. You cannot run it from your USB drive. Copy it off of your USB drive to any folder on your C drive ( I assume C is your Window drive ) and run it from there.
     
  15. Learner17

    Learner17 Private E-2

    Re: Problem Opening and Copying MGTools

    I am not sure how to open and copy MGTools. I have had problems trying to figure on how to accomplish this.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. Learner17

    Learner17 Private E-2

    Re: MGTools Log Reports

    I've included a copy of my MGTools log reports. If there is something else, would you let me know?
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not looking like malware is causing your problems. You do have some junkware to remove but it may be that your problems are caused by the security software you have installed and how you have configured them. We will uninstall your security software to see if that helps. Also we will cleanup a bunch of other junk.

    Start by uninstalling all of the below:
    Ask Toolbar
    Dealio Toolbar v4.5
    Java(TM) 6 Update 23
    Java(TM) 6 Update 7
    LiveUpdate (Symantec Corporation)
    McAfee Security Scan Plus
    Norton Internet Security
    Panda Cloud Antivirus
    Yahoo! Search Protection
    ZoneAlarm Firewall
    ZoneAlarm Free Firewall
    ZoneAlarm LTD Toolbar
    ZoneAlarm Security Toolbar
    ZoneAlarm Security

    Do not skip these because later instructions are going to also delete any left over files and folders from them so any that you do not uninstall are going to get broken anyway.




    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R3 - URLSearchHook: (no name) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)


    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Program Files\Ask.com
    C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
    C:\Users\Gabe\AppData\Local\Temp\stobefq\svyfttb\wow.dll
    C:\Program Files\Common Files\Spigot
    C:\Users\Gabe\AppData\Local\Apple\Amazon\chear.dll
    C:\Users\Gabe\AppData\Roaming\Check Point Software Technologies LTD
    C:\Users\Gabe\AppData\Roaming\CheckPoint
    C:\Users\Gabe\AppData\Roaming\Panda Security                       
    C:\ProgramData\0x0304A000.sfl
    C:\ProgramData\CheckPoint
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Cloud Antivirus
    C:\Program Files\CheckPoint
    C:\Program Files\Check Point Software Technologies LTD
    C:\Program Files\Panda Security
    C:\Windows\Temp\*.*
    C:\Users\Gabe\AppData\Local\Temp\*.*
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"=-
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    "{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}"=-
    "{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}"=-
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
    "Tabs"="res://ieframe.dll/tabswelcome.htm"
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchSettings]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Search Protection]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Amazon]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escort.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escortApp.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escortEng.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escorTlbr.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\esrv.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\c]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escortIEPane.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\escort.escortIEPane]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}]
    [-HKEY_USERS\S-1-5-21-2616176451-1575070137-282253741-1000\Software\Ask.com]
    [-HKEY_USERS\S-1-5-21-2616176451-1575070137-282253741-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{83A5C533-9702-4876-BE37-6A946DB0A6E9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BC93D88-8D44-408E-B3AE-1EFA788F09A2}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B1C4DCB1-1CCF-401A-A0C5-622DB52CE488}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{83A5C533-9702-4876-BE37-6A946DB0A6E9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{550BD821-114A-4D97-BCFA-A1D7897A425F}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. Learner17

    Learner17 Private E-2

    I installed Java SE Runtime Environment 7 Update 45. Before this, a dialong box appeared and stated that I needed to update my Java program.

    After installing Java SE Runtime Environment 7 Update 45, I have noticed that the dialog box appears with the title, "User Account Control". A statement follows with "This program needs your permission to open". The next statement states, "If you started this program, contine":
    Java SE Runtime Environment 7 Update 45
    Oracle America, Inc.

    The last statement states:
    "The user account helps stop unauthorized changes to your computer".
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This thread is over 4 months old now and alot may have change. If may become necessary to start over. If you wish to receive help on this computer now, you will have to at least finish the previous instructions and you will have to keep in mind that in the READ & RUN ME we specifically requested that you disable UAC to prevent it from getting in our way.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds