Windows cannot access the specified device,path, or file. Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by DACS4, Aug 23, 2009.

  1. DACS4

    DACS4 Private E-2

    Hello. New up here.:wave

    I have spent 12+ hours trying to solve a few problems on our home PC.:cry

    Here's are some facts:

    - Home PC
    - Running Windows XP Home Edition SP3
    - We have the dreaded PC Antispyware 2010 issue
    - We have CCleaner & Regcure and I can run both without problems
    - Downloaded Malwarebytes' Anti-Malware to remove the PC Antispyware
    - I get the "Windows cannot" message when I try to run Malwarebytes
    - I have tried to run Malwarebytes in SAFE Mode and cannot..get same message
    - Other icons on my desktop that no longer have the normal icon are:

    iTunes, Word, Quicktime

    However..iTunes, Quicktime, and Word can all be opened.

    I have also tried the exe fix utilities and none have helped.

    Here's an interesting thing....if I remove Malwarebytes, re-download, and re-install, and I can get it to launch...once I start scan it gets hung, and after 30 sec closes itself out..and then I can no longer access it.:confused
    It's as though something knows it's running and intercepts it.

    Need less to say my frustration level is through the roof.

    Thoughts? Suggestions? :cry
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. DACS4

    DACS4 Private E-2


    Wow..that was a fast reply. Thanks for pointing me in the right direction here. Much Appreciated.:highfive
     
  4. DACS4

    DACS4 Private E-2

    Read R&R, Able to download, Unable to run anything

    Hello.

    After reading the R&R, Java cleanup and install, successfully downloading each tool, I tried to run each tool one at a time. None were successful. :cry

    The only thing I was able to do is generate the MGLog.zip file which I have attached here. If there was more for me to do before posting my MGlog then I apologize...please advise.:-o

    If this was the correct next step then I await more info form experts here.

    No success running:

    SuperAntiSpyware
    Malwarebytes
    ComboFix
    RootRepeal

    I'm still seeing the messages for PC Antispyware 2010 and it continues to install by itself and I continue to Remove it via Add/Remove Programs. I'm fairly sure Malwarebytes will successfully remove this but I cannot run mb.exe and perform a scan. When I initially download it.. the scan does start and after 20-30 seconds simply closes itself out. Wierd.

    Anxiously awaiting feedback and/or next steps....

    Thx in advance.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are extremely infected. So let's get to work.

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    -
    Now run Ccleaner to clean out only temp files and nothing else!

    Now see if you can run the other scans and attach any logs you can get.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  6. DACS4

    DACS4 Private E-2

    Yikes! ok..

    I did get the succes message about adding the below to the registry.

    Ran avenger and I have the .txt fil attached.
    Ran Ccleaner and cleaned out temp files only.

    Unable to run an other scans. I was able to get a few started and then it looks as though I simply ran our of RAM to be used and couldn't get any further.

    Ran MGTools and have .zip file attached for today's run.

    Assuming we have more work to do here...awaiting further instructions...

    Thank you!

    Dave
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes we still have a lot to do.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now go to start / run / and type in:
    cmd
    now type in this and hit enter:
    copy C:\WINDOWS\SYSTEM32\DLLCACHE\beep.sys C:\WINDOWS\SYSTEM32\DRIVERS\beep.sys
    then type in exit to close the prompt.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    -
    Now run Ccleaner to clean out only temp files and nothing else!

    Now see if you can run any of the other scans : SAS and MBAM
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. DACS4

    DACS4 Private E-2

    ok...a little better but certain there is more to do here.

    1.) Got success message on registry update
    2.) Ran CCleaner and removed temp files only
    3.) Successful run of SAS...24 items identified and removed
    4.) Could not run MBAM..got message cannot accesss it
    5.) Could not get a successful COmbofix run so unable to attached log. Instead of have attached a screen shot of where it got stuck
    6.)MGlog for today attached.

    Thanks,

    Dave
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your runkeys log is basically empty. Did you get any error messages when you ran the getlogs.bat?

    Use windows explorer to find and delete:
    C:\Documents and Settings\D. Rowe\Local Settings\Application Data\xajexoku.bat
    C:\WINDOWS\gojuq.dat
    C:\WINDOWS\SYSTEM32\gamamygum.dat

    Now download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe file.

    Attach the new MGLogs.zip Make sure it runs to completion.
     
  10. DACS4

    DACS4 Private E-2

    Saw a bunch of Access denied messages when I ran getlogs.bat both today and last time it ran but nothing that appeared to be an error.

    Deleted the 3 files you mentioned, downloaded latest version of MGTools and ran .exe.

    Updated MGLOG zip file attached.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    Now:
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  12. DACS4

    DACS4 Private E-2

    Ran XPsp3bu.exe

    Logs attached...

    Is there any hope ? Are we slowly getting through it?

    Thanks,

    Dave
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are getting there.

    Now do the following:

    • Please save Win32kDiag file to your desktop.
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished,
      there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    "%userprofile%\desktop\win32kdiag.exe" -f -r


    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:

    • the new log from Win32kDiag
    • C:\MGlogs.zip
     
    Last edited: Sep 21, 2009
  14. DACS4

    DACS4 Private E-2

    Done. Both logs attached. Glad to hear we are getting closer.

    Thanks so much. :wine

    Dave
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try this:

    Using Inherit to correct program execution permissions issues

    Copy and paste Inherit.exe to the same directory where the following files are located:
    C:\MGTools
    then drag C:\MGTools\analyse.exe to the tool and drop it:
    when finished click OK. You may remove the Inherit.exe from the directory.

    Now, after running the C:\MGtools\GetLogs.bat file, attach:

    * Log from inherit
    * C:\MGLogs.zip
     
    Last edited: Sep 21, 2009
  16. DACS4

    DACS4 Private E-2

    Hi. New MGLog zip attached. I didn't know the name of the Inherit log so could not attach it? What is it called ? Where should it be?

    Dave
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry....must have had a brain lapse. There is no log. The program is designed to have you drop any program exe that is not allowing you to run it due to permission problems. At this point you look clean.

    You can use windows explorer to find and delete these:
    C:\WINDOWS\Tasks\ISP signup reminder 1.job"
    C:\WINDOWS\Tasks\ISP signup reminder 2.job"
    C:\WINDOWS\Tasks\ISP signup reminder 3.job

    Tell me what issues you are still having.
     
  18. DACS4

    DACS4 Private E-2

    Deleted the 3 files you mentioned inlast post.;)

    I successfully ran Malwarebytes and cleaned up whatever it found.:-D

    I still have icons on my desktop that act as though they are not being recognized by the actual program...for example...none of the MS Word docs on my desktop have the MS Word icon with the 'W'. Itunes icon is not the normal one...instead it is a blank white window icon. Any ideas on this?

    Thx,

    Dave
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Icons can get corrupt with some infections. The thing to do is to right click the icon, click properties and then click find target. If it doesn't take you to the exe file, then you can delete the icon. Then go to the file and create a new icon for it. You can pursue this in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds