unable to install/run antivirus/antispy software

Discussion in 'Malware Help (A Specialist Will Reply)' started by chantdown, Oct 17, 2009.

  1. chantdown

    chantdown Private E-2

    hey all. I few days ago I tried to run a complete virus scan using AVG (as I do every few weeks) and clicking "Scan" did nothing at all. Thinking that was strange I tried to run SUPERAntiSpyware and I got the error message:
    "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item." I then tried to run Adaware and got a similar message, so I think it's safe to say that I have some kind of malware on my machine (which is running Windows XP).

    I've been working through the READ & RUN ME FIRST Malware Removal Guide, but I'm not having any luck with step 6.

    I uninstalled Antispyware so that I could try a fresh install with the most current version, but it won't let me reinstall, giving me the error message:
    "Error 1321. Windows installer has insufficient privileges to modify this file: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe."

    Malwarebytes Anti-Malware seemed to install okay, but when I tried to run a scan it terminated itself after a few seconds. Now when I try to run the program, I get the same error message I first noticed:
    "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

    I was able to run combofix.exe, RootRepeal and MGtools successfully (I think) and logs are attached accordingly.

    thanks in advance for any help you might be able to offer...
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Try doing the following :
    Download this Win32kDiag(If on your desktop - Right click and choose copy / then Open my computer, click on the C drive and in the window paste it there) and save to C:\Win32kDiag.exe. You must save it here!!!!

    Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log.
    C:\win32kdiag.exe -f -r


     
  3. chantdown

    chantdown Private E-2

    Okay, thanks. I've taken your advice re the desktop and I've cleaned it up. Is it okay to leave a few shortcuts to folders and files on there, or should it be just links to programs?

    I have attached the Win32kDiag.txt log as requested.

    I should probably mention that in between now and my original post I was able to properly uninstall AVG 8.5 (thanks to the "remove programs" part of CCcleaner which removed this when Control Panel couldn't) and I can now run Malwarebytes and SUPERAntiSpyware. I have attached logs accordingly but they didn't seem to find anything.

    I should also probably mention that I currently don't seem to be able to install windows updates, and I also can't delete C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe no matter how hard I try...
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Shortcuts are just links to programs, which is what you want on your desktop.

    Is the only problem you are having the inability to remove spybot and get updates?

    Have you installed a new AV program?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  5. chantdown

    chantdown Private E-2

    ok thanks. MGlogs.zip attached as requested.

    my inital problems (inability to run antivirus and antispy apps) have now all gone, and I'm now even able to install windows updates again. it appears that I have my system pretty much back to normal, although I still can't remove C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

    yes, I have installed a new AV program - I'm now running Avira instead of AVG, and so far so good. I'm running the free ZoneAlarm as my firewall... is this sufficient, or would I do better running another program instead?

    thanks again.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That file is not showing in your logs. If you are still having problems with it, please post in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds