Jump to content

MalwareBytes and HiJackThis Install but won't Scan


Recommended Posts

I have tried both MalwareBytes and HiJackThis, they install and launch OK but when run scan they both closes immediatley then I get a windows (Windows cannot access specified device, you may not have permissions to access them) error if I try to launch again. I have tried to run them from a CD and I get a runtime error with MalwareBytes and HiJackThis scans quickly then closes. I am going to try running ComboFix next and see if I can at least find out what this is. Any help or suggestions would be greatly appreciated.

Link to post
Share on other sites

I have a similar issue. The user went to a random site and ended up with "Advanced Virus Remover" Pretty impressive looking.

I have tried the following with no avail:

Disabled all startup and services.

Reboot to safe mode.

Took ownership of directory thinking permissions were changed.

Reinstall Mbam in safe mode and then start scan, gets through 1 file and poof gone! permissions error returns "Windows cannot access specified device, path, or file. You may not have the appropriate permissions to access the item." when starting mbam.exe.

When not in safe mode cannot run regedit, task manager.

Current running processes in safe mode (show process from all users):

taskmgr.exe

explorer.exe

svchost.exe

svchost.exe

svchost.exe

lsass.exe

services.exe

winlogon.exe

csrss.exe

smss.exe

System

System Idle Process - User Name - System

Regedit does run in safe mode.

Current entries in HKLM\Software\Microsoft\Windows\CurrentVersion\Run:

C:\Windows\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto - This should just be to bring up the Config utility on startup.

Any thoughts?

TIA,

Tom

Link to post
Share on other sites

Greetings.

To get you fixed up please follow the instructions here:

I'm infected - What do I do now?

And post your logs in a new topic here:

Malware Removal - HijackThis Logs

Please be sure not to install any software or use any removal or scanning tools exept those that you are

instructed to by the expert who will be assisting you as doing so can make their job much more difficult.

note: if for some reason you are unable to run some or any of the tools in the first link, then skip that step and move on to the next one.

If you can't even run HijackThis, then just post here: Malware Removal - HijackThis Logs describing your issues and an expert will reply with further instructions.

I hope I was helpful. Good luck and safe surfing. :)

Link to post
Share on other sites

Maniac,

Thanks for the info. I probably should start another thread for the issue I have but as mentioned Mbam and HJT doesn't run so we can't post a log file from it.

I have removed the drive and put in another workstation and I am scanning it there. I will post the results.

Thanks,

Tom

Greetings.

To get you fixed up please follow the instructions here:

I'm infected - What do I do now?

And post your logs in a new topic here:

Malware Removal - HijackThis Logs

Please be sure not to install any software or use any removal or scanning tools exept those that you are

instructed to by the expert who will be assisting you as doing so can make their job much more difficult.

note: if for some reason you are unable to run some or any of the tools in the first link, then skip that step and move on to the next one.

If you can't even run HijackThis, then just post here: Malware Removal - HijackThis Logs describing your issues and an expert will reply with further instructions.

I hope I was helpful. Good luck and safe surfing. :)

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.