unable to open .exe files

Discussion in 'Malware Help (A Specialist Will Reply)' started by serafin11, Dec 19, 2008.

  1. serafin11

    serafin11 Private E-2

    Hi
    I'm curently working through your clean up procedure because of being unable to open .exe files (almost all) i can only run these tests from safe mode,both spybot and malwarebytes say they cannot remove all problems and will finish aftr a restart, when i reboot into normal mode i get a message saying that these programs are not being allowed to run, what should i do?

    Thanks
     
  2. serafin11

    serafin11 Private E-2

    Hi
    Big problems with the message 'windows cannot access the specified device, path or file, you may not have apprpiate permission to access the item'
    Have read alot on this about ie settings and looking into regit or zonealarm but i cannot access any of these, my computer is one of the very few which will open, also unable to install any programs or start any of my spyware or anti virus

    running xp sp2

    Since then i have completed your cleaning instructions as best i can, i had some problems,
    i can only work in safe mode otherwise nothing will open
    when trying to install Superantispy i got the alarm of 'win installer service could not be accessed' in safe mode
    on rebooting to normal mode i again get the 'cannot access' message for spybot and malwarebytes which prevents them starting to complete there removal task
    spybot has one bug it cannot fix - myway.mywebsearch

    logs are attached as requested

    Any help greatly appreciated

    Thanks
     

    Attached Files:

  3. serafin11

    serafin11 Private E-2

    Sorry, forgot to mention how it all happened

    for about a month now the pc has been very slow

    the no access problem has arisen before but has always cleared on a reboot

    about a week ago outlook express started starting up into a different window from normal, usually found a way back, but stuck for the last few days

    when everything stopped working i was about to load another .avi onto realplayer

    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    In safe boot mode you attach logs for the user account named Administrator. I tend to doubt this is the account that you are having problems with in normal boot mode. If I am correct then the logs are really not of too much use to us since we need logs from the user accounts having problems. I see all the below user accounts. Do they all have the same problem?

    Code:
    Is Admin? | Username
    ------------------
       Yes    | Administrator
       Yes    | Dad
       Yes    | Grace
       Yes    | Joshua
       Yes    | Mummy
       Yes    | Sophie
    Why is everybody set to administrator? I assume that some of these users are children?? They should not have admin priviledges.

    In normal boot mode, can you:
    1. run Windows Explorer by right clicking Start and selecting Explore?
    2. can you run anything from icons on your Desktop by double clicking them?
    3. if you click Start, Run, and enter cmd and click OK, does a command prompt window open?
    4. if you click Start, Run, and enter regedit and click OK, does the Windows Registry Editor open?
    Did you knowlingly install the below?
    c:\program files\SparkleBox\tbSpar.dll
     
  5. serafin11

    serafin11 Private E-2

    Hi

    Thanks but the problem is corrected now, it was something to do with zonealarm.

    I did put on sparklebox, why do you ask?

    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because it is a program that is what is called debateable or questionable when it comes to determining if it is malware or not.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds