Windows cannot access the specified device,path, or file. Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by qts, Jan 20, 2011.

  1. qts

    qts Private E-2

    Hello

    I believe my computer is extremely infected with the Antivirus (2010) bug and I don't have a clue what to do anymore. I've tried downloading SuperAntiSpyware and Malwarebytes but everytime I begin to scan it closes it self out. I've even tried doing this in safe mode Please help.:confused
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. qts

    qts Private E-2

    Hello

    Thanks for replying:)

    I just finished the READ & RUN ME FIRST, and the only log that my computer was able to get was from RootRepeal.

    As I went through the instructions and downloaded SuperAntiSpyware, Malwarebytes, etc; I went on to install them, and as I began to try to scan my computer the scanner just closed down by it self for all of them. Also if I were to try to open them again a message popped up that said, "Windows cannot access the specified, device, path, or file. You may not have the appropriate permissions to access the item."

    I don't have a problem downloading anything I just can't scan anything

    Quentin
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  5. qts

    qts Private E-2

    The only log I couldn't get this time was from SAS because the malware kicked me out again.

    Just in case you needed it I also included the Rkill log.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I see the type of infection you have. I am not going to forget you, but we need to wait for Chaslang's input on this. He has been very busy so please be patient! :)
     
  7. qts

    qts Private E-2

    Thanks, this means were making some progress!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We certainly are, but this may take some time as I am afraid there is no simple fix for this.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  9. qts

    qts Private E-2

    Thanks for replying, the program didn't find any infections but here are the logs.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what you are reading but it sure did. The vbma9589 driver/service is the infection and i found it but it just cannot remove it.

    Bring up Device Manager byright clicking My Computer and selecting Properties. Then click the Hardware tab and then select Device Manager.

    Look under System Devices section, do you see something like [cmz vmkd] or [cmz vmkd] Virtual Bus

    If you find a match to what I said to look for then right click on it and select Disable ( not select Delete at this time )

    Then reboot your PC. After reboot, continue witht the below.




    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
     
    Last edited: Jan 23, 2011
  11. qts

    qts Private E-2

    Alrightty here are the logs you asked for:)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you find the [cmz vmkd] items I mentioned?
     
  13. qts

    qts Private E-2

    Yes I found the file and disabled it successfully.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ok then go back and look again now and if you see it again, this time select Uninstall. Let me know the results.

    Also, how are things currently working?
     
  15. qts

    qts Private E-2

    I just uninstalled the [cmz vmkd] Virtual Bus file successfully.

    And, other than me not having the permissions the open and run an anti-virus scan the computer's working pretty good.:)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps in the below and see how things are afterwards.

    Resetting Registry and File Permissions
     
  17. qts

    qts Private E-2

    I downloaded the program and saved it to my desktop.
    Whenever I tried to install the program the message popped up saying that "I didnt have the appropriate permissions to access the file", and the installation stopped.:cry

    I also tried to just download it without saving it to the desktop but I had the same results.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.
    Now see if you can follow my previous instructions.
     
  19. qts

    qts Private E-2

    After I ran all of the beginning steps I was able to install the registry resetter.:-D:-D

    After I ran that I reset my computer and my Anti-Virus (I have Sophos) was re-enabled again so I just disabled it.

    And below is the log you requested
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so is everything okay now.
     
  21. qts

    qts Private E-2

    I think so! At the moment I'm scanning my computer with SAS.
     
  22. qts

    qts Private E-2

    I was able to fully run SAS, Malwarebytes and ComboFix and get the logs.:-D
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay those show some more was fixed and few letf overs need to be cleaned up.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 21


    Now we need to use ComboFix again but a different way
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure that you directly answer the below question.
    How are things working now?
     
  24. qts

    qts Private E-2

    I was able to run Combofix just like you asked and got both logs.

    "How are things working now?"
    Since my main problem was not being able to complete a full scan and remove viruses, I guess we can say that problem is solved.:)

    Not having any other software problems.

    I also ran 2 recent full scans of SAS and Malwarebytes and have attached them as well.:-D
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also need to inform about the nature of this infection that we have been fixing. Even though it appears that we have found and quite possibly fixed the problem, it is important for you to understand the following.


    This infection is known to be a backdoot trojan.
    • This may allow hackers to remotely control your computer, steal critical system information and download and execute files.
    If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please go to a different known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

    Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC was compromised and there is no way to be 100% sure your computer can be trusted. Some experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. But it is also possible that the the active components have been removed and you are save now. We just don't know if anything information has already been stolen and is just they just have not used it yet.

    Please read these for more information:

    How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
    When Should I Format, How Should I Reinstall


    So while it appears that we have successfully cleaned this computer, I cannot guarantee that it will be 100% secure afterwards which is why you still need to continuously check with financial institutions over the next couple months to make sure that no strange activities occur.
     
  26. qts

    qts Private E-2

    Thanks for the info. So I guess I should just reformat
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's up to you. Personally I don't think it is necessary, but you do still need to check with financial institutions no matter what you decide. While it is true that you cannot be 100% sure that you are clean after an infection like this, it is also true that you really cannot be 100% sure you are clean after connecting to the internet. There are just that many infections out there. What are you going to do, format and reinstall after every surfing session. Of course not. So I think you need to verify that all your accounts have not been hacked yet and check for a couple months ( and you need to do this even if you format ). Then you need to keep your PC properly protected and keep all software properly updated. And you need follow safe surfing habits per my below instructions.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  28. qts

    qts Private E-2

    Will do thanks for all the help.:)
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds