Solved

Got "Access Denied" while trying to install malwarebytes

Posted on 2012-03-26
14
1,391 Views
Last Modified: 2016-11-23
Greetings mates,

I have some sticky situations here.

First, all my files under Start are gone.

Only icon left there is Solitaire.

Second, when I attempted to install malwarebytes, I was unable to.

Half way through the install, I get "Access Denied" and the install stops.

I know there are some virus/malware invasions on my PC.

Any ideas how to get things back on the laptop again?

Not that it matters but it is dell insprion, running windows 7 home edition.

I tried system restore.

It was successful in terms of running but nothing was restored or fixed.

Thanks alot in advance
0
Comment
Question by:sammySeltzer
14 Comments
 
LVL 4

Assisted Solution

by:kdubendorf
kdubendorf earned 72 total points
ID: 37769414
Can you put it into Safe Mode with Networking (hit F8 at startup) then try to load Malwarebytes?   Then run Malwarebytes in Full Scan mode.
0
 
LVL 28

Author Comment

by:sammySeltzer
ID: 37769436
I tried that already. got same "access denied" error.
0
 
LVL 32

Assisted Solution

by:willcomp
willcomp earned 72 total points
ID: 37769438
Try these instructions from younghv: http://www.experts-exchange.com/Software/Internet_Email/Anti_Spyware/A_6209-Windows-XP-Vista-Recovery-rogue-Desktop-icons-missing-Empty-program-files.html

If you still cannot run any malware removal programs or still have hidden files, let us know.
0
 
LVL 32

Expert Comment

by:willcomp
ID: 37769442
Ooops. That article is by rpggamergirl, not younghv. Sorry about that rpg!
0
 
LVL 16

Assisted Solution

by:l33tf0b
l33tf0b earned 72 total points
ID: 37769444
Try renaming malware bytes to a random.exe and try running again.   You are running as admin right?
0
 
LVL 28

Author Comment

by:sammySeltzer
ID: 37769518
sorry guys. Everything you suggested, I have attempted but still same access denied error.

I reminder that I have os windows 7.
0
 
LVL 1

Assisted Solution

by:DrMadAxe
DrMadAxe earned 71 total points
ID: 37769805
Open in safe mode as layed out above.

You will need to make sure you are the administrator. Do the steps outlined above and rename the malwarebytes file to something else but make sure you add the .exe .

From there right click on it and "run as administrator"

see if that works.

If not download superantispyware and try that as well. It may find the problem and fix and then you can also add malware bytes afterwards and use both for scans.

Let us know how you fair. http://www.superantispyware.com/download.html
0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 29

Assisted Solution

by:Sudeep Sharma
Sudeep Sharma earned 71 total points
ID: 37769860
Though it is mentioned in the article posted above by willcomp, however I would still like to emphasize. Did you tried TheKiller yet?

Right click on the tool and select "Run as Administrator", then run RogueKiller in the same manner.

Once done try to install MalwareBytes by again doing Right Click on the installer and selecting "Run As Administrator".

Thanks
Sudeep
0
 
LVL 5

Assisted Solution

by:9660kel
9660kel earned 71 total points
ID: 37770541
The key instruction from the article by younghv, (posted by willcomp) is the fixNCR.reg.

It replaces the infected registry keys that block install and administrative activities. That needs to happen first, and may need to be repeated if the pest regenerates. Then run thekiller, rogue killer, or rkill, to stop infected processes from interfering with the rest of the removal process.

I recommend that you download all apps from a clean computer, rename the files to something random, or at least shorten them to keep the infection from interfering, and burn them to optical media. USB sticks are very convenient, but can be a risk for spread of infection.
0
 
LVL 28

Author Comment

by:sammySeltzer
ID: 37771960
Thanks guy.

I was going to take my laptop with me to work today so I can continue working on it but i forgot it.

I will try the steps enumerated above.

But just so you guys know, I did try renaming malwarebytes to random.exe - no help.

I was able to install superantispyware successfully, ran it successfully but for some strange reason(s), it did *not* find anything other than cookies.

I started by running fixNCR.reg, then killer.

In short, I pretty much followed your instructions.

I will try again when I get home later this evening and then post back.
0
 
LVL 38

Accepted Solution

by:
younghv earned 71 total points
ID: 37772068
My recommendation is to always use the IE "Save As" function when downloading the various anti-malware tools. It is my understanding that downloading and renaming will not work to trick the malware.

In all cases you are better off using a clean computer to download the tools you need, then burning them to CD (best) or Thumb Drive - using the new names - then carrying them to the infected computer.
0
 
LVL 28

Author Comment

by:sammySeltzer
ID: 37772170
It is my understanding that downloading and renaming will not work to trick the malware.



i will have to agree with you here. Even after renaming the file, once you click to run it, the original file name is exposed again anyway.

I was working off of Thumb Drive.
0
 
LVL 28

Author Comment

by:sammySeltzer
ID: 37779848
sorry guys but I have gotten myself into a bigger mess.

I tried to follow the instructions and may have done something silly as right now, I can't even log into the laptop without getting a new error:

Group policy Client Service failed the logon. Access Denied"

I have googled this problem and everything I tried has failed.

I am able to log in via safe mode though but could do nothing from there.

I also found that out when I try checking the radio button that says, "Show hidden files and folders"

When I click apply and Ok, it reverts back to Do NOt show hidden files and folders.

I am bushed, really.
0
 
LVL 28

Author Comment

by:sammySeltzer
ID: 37832666
I ended up deleting the profile and recreating it, in the process, losing all data.

Thanks all for your help.
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Today, still in the boom of Apple, PC's and products, nearly 50% of the computer users use Windows as graphical operating systems. If you are among those users who love windows, but are grappling to keep the system's hard drive optimized, then you s…
Find out what Office 365 Transport Rules are, how they work and their limitations managing Office 365 signatures.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now