Vista Permissions Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kevin Murphy, Nov 24, 2009.

  1. Kevin Murphy

    Kevin Murphy Private E-2

    Hi,
    Anyone ever seen anything like this? It happened suddenly this week. I reverted to my last restore point and it didn't go away.

    While logged on with my user id (Admin user) the following problems are observed. None of these problems are seen while logged on as any other user.
    (1) Creating a “New Folder” is possible but giving it a name is not possible. The name reverts back to “New Folder”
    (2) It is not possible to rename any folder on the computer, but renaming files is possible.
    (3) Installation or removal of any software appears to be impossible. Error message is “Error 1606: Could not access network location %APPDATA%\”
    (4) Adode Reader does not work with error “An internal error occurred”
    (5) Skype does not work. Error message… “The files that Skype needs to work can’t be found. Please download and reinstall Skype to fix this problem.”
    (6) Microsoft Word hangs when trying to save a file. When you open the file again it says, “Your Autocorrect File could not be saved. The file may be read only, or you may not have permissions to change the file.”
    (7) Also Word is giving the message “ Word automatically saved changes to the Normal template. Do you want to load it?”
    (8) All folders are flagged in ‘Properties’ as Read Only. Resetting the flag has no effect it reverts back to Read Only.

    Evendently I have lost permissions and have read only access but everything looks good in the settings.? What's the deal ? Or as they say in Mexico "Que sa dilla?"

    Kevin
     
  2. rustyjack

    rustyjack MajorGeek

    Hi there Kevin, you have obviously gotten some kind of infection and it needs seeing to asap so click on this link READ & RUN ME FIRST. Malware Removal Guide follow all the instructions very carefully and yes it can seem to become very tedious but you have to do this to enable you to get up and running and back to normal again, also another thing when you post the logs asked for, please be very patient, because the malware fighters are really busy and as you may well know this is done by them thoroughly so you don't have any glitches after what has been done !
    Hope this helps you ! ;)
     
  3. Kevin Murphy

    Kevin Murphy Private E-2

    Thanks Rusty,
    Have you seen malware behaving like this before? I have McAfee running and it didn't catch anything. I've been through the Malware Removal Guide before (a couple of times) so I am familiar with it. This time it didn't seem like the previous malware issues I have experienced. Thanks for your support.
    Kevin
     
  4. Kevin Murphy

    Kevin Murphy Private E-2

    Hi
    Enclosed are the files. I found and removed Rogue.PersonalAntiVirus. The problem has not changed. Still no access to %APPDATA%. RoorRepeal log coming in the next email.
    Thanks
    Kevin
     

    Attached Files:

  5. Kevin Murphy

    Kevin Murphy Private E-2

    Here is the RoorRepeal Log....it was too big so I had to .RAR it. Then I had to rename it because .RAR is an invalid file name. Just rename it RRLog.rar
    Thanks
    Kevin
     

    Attached Files:

  6. Kevin Murphy

    Kevin Murphy Private E-2

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good to know you believe it is solved. However based on the below seen in your SUPERAntiSpyware log:
    You were infected and I suggest you run the below which also deals with permissions issues that could be in place.


    • Please save Win32kDiag file to your desktop.
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    "%userprofile%\desktop\win32kdiag.exe" -f -r
     
  8. Kevin Murphy

    Kevin Murphy Private E-2

    Here's the Win32kZDiag.txt .... i guess there may still be problems. I noticed I can't create shortcuts on my desktop any more.

    Thanks
    Kevin
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.
    Uninstall the below old versions of software:
    Java(TM) 6 Update 11
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O9 - Extra button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
    O9 - Extra 'Tools' menuitem: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
    O23 - Service: McAfee Application Installer Cleanup (0111731259165169) (0111731259165169mcinstcleanup) - Unknown owner - C:\Windows\TEMP\011173~1.EXE (file missing)

    After clicking Fix, exit HJT.

    Now we are going to try the beta version of ComboFix which is named KittyFix.exe

    Download KittyFix from http://download.bleepingcomputer.com/sUBs/Beta/KittyFix.exe and save it to your Desktop but do not run it.

    Note: This is a beta version of combofix and might be unstable but tests done so far have proved it works well

    Note: It is important that it is saved directly to your desktop and run from the desktop and not any other folder on your computer.
    • Now Exit/Close/Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Close any open browsers and any other programs you might have running.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as KittyFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the KittyFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of KittyFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds