A friend of mine called me a few days ago to look at his computer. His desktop icons and taskbar were all missing. Upon hitting ctrl+alt+del and looking at his running process, I noticed that explorer.exe was missing.
I then opened a command prompt, went to the windows directory and entered explorer.exe to get explorerer to run. I was greeted with a message saying "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item".
I then entered a cacls command at the prompt (cacls explorer.exe /p david:f)and then was able get explorer running again. However, right clicking on the desktop makes the destop/taskbar disappear. Trying to open the control panel makes it disappear also.
I then installed Spybot from a thumbdrive. Spybot installed but would not run past the initial loading in process. As soon as a scan started, it would crash to the desktop.
I then installed Malwarebytes' Anti-Malware. It started to scan the first time but crashed to the desktop after a few seconds. Any further attempt to run it result in the "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item" message. Issuing a cacls command for the .exe of this program does not seem to help.
My friends kids attempted to fix this also and I see combo fix on the desktop but I do not see an installation of it on the C: drive.
I installed Hijackthis to get a log file. It starts the scan but crashes to the desktop after getting almost complete. After running it once, I cannot access it again without getting a "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item" message. Issuing a cacls command from a cmd prompt does allow me to use it again however.
I installed gmer to get a log file to post. Again, much like Hijackthis, it starts the scan and runs for about ten minutes then crashes to the desktop. It will not run again without generating a "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item" message. Issuing a cacls command from a cmd prompt does allow it to run again but it still crashes to the desktop.
Here is a list of process that are running on the machine at bootup:
mscipevc.exe
wmiapise.exe
wdfmgr.exe
svchost.exe (7 times)
spoolsv.exe
lsass.exe
winlogon.exe
csrss.exe
TeaTimer.exe
taskmgr.exe
chcp.com
explorer.exe
System
System Idle Process
When I first got the computer to my house to attempt to fix it, I tried to boot into safe mode. Safe mode would not work. I had to modify the computers registry to get safe mode to work again. However, running any of the above programs in safe mode still produces the same results.
If I boot off of a Windows XP cd and start the repair console, I have two options to work in: One is called MiniNT, the other is Windows XP Home.
The computer runs Windows XP Home with SP2 installed.
Computer details:
Gateway 507 GR
Pentium 4 w/ HT @ 3 Ghz
800 Mhz FS, 512 MB Ram
Thanks for any help!
I was able to get a Rootrepeal log to run. Here it is:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/09/08 14:17
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: aujasnkj.sys
Image Path: C:\DOCUME~1\david\LOCALS~1\Temp\aujasnkj.sys
Address: 0xA960D000 Size: 84352 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAA1FF000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8B70000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA9926000 Size: 49152 File Visible: No Signed: -
Status: -
Name: win32k.sys:1
Image Path: C:\WINDOWS\win32k.sys:1
Address: 0xF8966000 Size: 20480 File Visible: No Signed: -
Status: -
Name: win32k.sys:2
Image Path: C:\WINDOWS\win32k.sys:2
Address: 0xAA3AE000 Size: 61440 File Visible: No Signed: -
Status: -
Hidden Services
-------------------
Service Name: kbiwkmethoehfl
Image Path: C:\WINDOWS\system32\drivers\kbiwkmnsdpmqss.sys
==EOF==
=======================
Edit
Because you added a post to your own topic, it would have appeared to volunteer analysts that you were already being assisted as they look for topics with no response.
If you still need help,
The Waiting Room
Post here if still waiting for help in the Malware Forum, (AFTER) FOUR days
I then opened a command prompt, went to the windows directory and entered explorer.exe to get explorerer to run. I was greeted with a message saying "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item".
I then entered a cacls command at the prompt (cacls explorer.exe /p david:f)and then was able get explorer running again. However, right clicking on the desktop makes the destop/taskbar disappear. Trying to open the control panel makes it disappear also.
I then installed Spybot from a thumbdrive. Spybot installed but would not run past the initial loading in process. As soon as a scan started, it would crash to the desktop.
I then installed Malwarebytes' Anti-Malware. It started to scan the first time but crashed to the desktop after a few seconds. Any further attempt to run it result in the "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item" message. Issuing a cacls command for the .exe of this program does not seem to help.
My friends kids attempted to fix this also and I see combo fix on the desktop but I do not see an installation of it on the C: drive.
I installed Hijackthis to get a log file. It starts the scan but crashes to the desktop after getting almost complete. After running it once, I cannot access it again without getting a "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item" message. Issuing a cacls command from a cmd prompt does allow me to use it again however.
I installed gmer to get a log file to post. Again, much like Hijackthis, it starts the scan and runs for about ten minutes then crashes to the desktop. It will not run again without generating a "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item" message. Issuing a cacls command from a cmd prompt does allow it to run again but it still crashes to the desktop.
Here is a list of process that are running on the machine at bootup:
mscipevc.exe
wmiapise.exe
wdfmgr.exe
svchost.exe (7 times)
spoolsv.exe
lsass.exe
winlogon.exe
csrss.exe
TeaTimer.exe
taskmgr.exe
chcp.com
explorer.exe
System
System Idle Process
When I first got the computer to my house to attempt to fix it, I tried to boot into safe mode. Safe mode would not work. I had to modify the computers registry to get safe mode to work again. However, running any of the above programs in safe mode still produces the same results.
If I boot off of a Windows XP cd and start the repair console, I have two options to work in: One is called MiniNT, the other is Windows XP Home.
The computer runs Windows XP Home with SP2 installed.
Computer details:
Gateway 507 GR
Pentium 4 w/ HT @ 3 Ghz
800 Mhz FS, 512 MB Ram
Thanks for any help!
I was able to get a Rootrepeal log to run. Here it is:
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/09/08 14:17
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: aujasnkj.sys
Image Path: C:\DOCUME~1\david\LOCALS~1\Temp\aujasnkj.sys
Address: 0xA960D000 Size: 84352 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAA1FF000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8B70000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA9926000 Size: 49152 File Visible: No Signed: -
Status: -
Name: win32k.sys:1
Image Path: C:\WINDOWS\win32k.sys:1
Address: 0xF8966000 Size: 20480 File Visible: No Signed: -
Status: -
Name: win32k.sys:2
Image Path: C:\WINDOWS\win32k.sys:2
Address: 0xAA3AE000 Size: 61440 File Visible: No Signed: -
Status: -
Hidden Services
-------------------
Service Name: kbiwkmethoehfl
Image Path: C:\WINDOWS\system32\drivers\kbiwkmnsdpmqss.sys
==EOF==
=======================
Edit
Because you added a post to your own topic, it would have appeared to volunteer analysts that you were already being assisted as they look for topics with no response.
If you still need help,
The Waiting Room
Post here if still waiting for help in the Malware Forum, (AFTER) FOUR days
Last edited by a moderator: