lorna Posted June 9, 2005 Report Share Posted June 9, 2005 HiI wrote earlier about problems with parite virus. Every antivirus software I have run (about 10)cannot seem to shift it. I have took all your advice and am greatful but I am still stuck. I have now found that I cannot run most programs I get the message"windows cannot access the specified device, path or file you may not have the appropiate permission......."I gatthered from an eithlier message that it can be got rid of easily thruogh regedit but I nowI cannot run regedit because I get the same message.I tried Hijack this but this will also not run as I get the same message.This is getting prity desperate.....I wanted to reformatt the whole drive and reinstall windows but because I am running a Tablet I would have to buy an external cd drive....aparrantley it will only boot from toshibas own drive and they cost over £200 I would rather thow the machine in the bin.Anyone please?Lorna Quote Link to comment Share on other sites More sharing options...
andsome Posted June 9, 2005 Report Share Posted June 9, 2005 Have you tried here? CLICK HERE Quote Link to comment Share on other sites More sharing options...
nellie2 Posted June 9, 2005 Report Share Posted June 9, 2005 try renaming hijackthis... to something like spykiller Then see if it will run, if yes then post the hijack log it creates as a reply to this thread. Quote Link to comment Share on other sites More sharing options...
andsome Posted June 10, 2005 Report Share Posted June 10, 2005 The offer that I made in a PM still stands. If Hijack this cannot be downloaded, I have run a little experiment, and it can be run from Outlook Express. I can send the file as an attachment, and double clicking the attachment will run the program. Quote Link to comment Share on other sites More sharing options...
lorna Posted June 10, 2005 Author Report Share Posted June 10, 2005 Thanks but I cannot see how this will work? I cannot run any program now apart from internet explorer. everything I try to run comes up with the message I mentioned above. I understand hijack this looks at the registory but I cannot get into the registory. If I could run regedit then I would be able to change the line with parite on it but I cant. Damm this virus.......Maybe there are other things going on here?I have been able to download and run antivirus programs but they, after a while, stop running.I managed to intall another copy of windows proffessional over the top of windows prof tablet edition by using a CD rom on another PC over the network, this was risky because I had to turn Zonelabs off to access the drive which left my other pC's exposed. However, this seems to have made things worse?Thanks for trying...I fear its may be the skip for this lovely tablet.Lorna Quote Link to comment Share on other sites More sharing options...
andsome Posted June 10, 2005 Report Share Posted June 10, 2005 It's surely worth a try. Hijack this does not as far as I know run like most programs. It is not installed, it just does a scan. I will stand correcting if I am wrong on this. Quote Link to comment Share on other sites More sharing options...
scuzzman Posted June 10, 2005 Report Share Posted June 10, 2005 It is not installed, it just does a scan. I will stand correcting if I am wrong on this.This is correctCan you access Safe Mode on the tablet? Quote Link to comment Share on other sites More sharing options...
lorna Posted June 10, 2005 Author Report Share Posted June 10, 2005 Yeah!Everything works in safe mode so I can run hijack thishere is my log I have not a clue what to do with it?Logfile of HijackThis v1.99.1Scan saved at 12:11:26, on 10/06/2005Platform: Windows XP (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\SYSTEM32\WISPTIS.EXEC:\WINDOWS\Explorer.EXEC:\PROGRA~1\WinZip\winzip32.exeC:\unzipped\spykiller\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworldF2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exeO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [TabletTip] "C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resumeO4 - HKLM\..\Run: [TosHKCW.exe] TosHKCW.exeO4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exeO4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUPO4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exeO4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logonO4 - HKLM\..\Run: [Trirot] Trirot.exeO4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /asyncO4 - HKLM\..\RunServices: [Microsoft Update Machine] wuawx.exeO4 - HKLM\..\RunServices: [Microsoft Update] navmgrd.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [Zinio DLM] C:\Program Files\Zinio\ZDLM.exe /hide O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.htmlO8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.htmlO8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.htmlO8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.htmlO8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.htmlO9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htmO9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htmO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1118226257946O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cabO20 - Winlogon Notify: loginkey - C:\WINDOWS\SYSTEM32\LoginKey.dllO20 - Winlogon Notify: TabBtnWL - C:\WINDOWS\SYSTEM32\TabBtnWL.dllO20 - Winlogon Notify: tpgwlnotify - C:\WINDOWS\SYSTEM32\tpgwlnot.dllO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeO23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted June 10, 2005 Report Share Posted June 10, 2005 The offer that I made in a PM still stands. If Hijack this cannot be downloaded, I have run a little experiment, and it can be run from Outlook Express. I can send the file as an attachment, and double clicking the attachment will run the program.Good idea, but HijackThis should not be run from a temporary folder. This would nullify any backups it makes, potentially causing more problems than it would solve. Quote Link to comment Share on other sites More sharing options...
andsome Posted June 10, 2005 Report Share Posted June 10, 2005 I created a file on drive C and called it Hijack this. I ran the program from the attachment, ignoring the first message about creating a folder. I then chose to save the scan into the new permanent folder. This worked OK. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted June 10, 2005 Report Share Posted June 10, 2005 I created a file on drive C and called it Hijack this. I ran the program from the attachment, ignoring the first message about creating a folder. I then chose to save the scan into the new permanent folder. This worked OK.HijackThis will place the backups in a folder named "Backup" where the HijackThis.exe is run from. If you run it from location (instead of save) it runs in a temporary folder. The backups will be placed in this temporary folder even though the log is saved elsewhere. Quote Link to comment Share on other sites More sharing options...
andsome Posted June 10, 2005 Report Share Posted June 10, 2005 I created a file on drive C and called it Hijack this. I ran the program from the attachment, ignoring the first message about creating a folder. I then chose to save the scan into the new permanent folder. This worked OK.HijackThis will place the backups in a folder named "Backup" where the HijackThis.exe is run from. If you run it from location (instead of save) it runs in a temporary folder. The backups will be placed in this temporary folder even though the log is saved elsewhere.OH! that has shut me up then. Quote Link to comment Share on other sites More sharing options...
lorna Posted June 10, 2005 Author Report Share Posted June 10, 2005 Meanwhile......back at the ranch :D Quote Link to comment Share on other sites More sharing options...
nellie2 Posted June 11, 2005 Report Share Posted June 11, 2005 I see Mark2 is helping you with your hijack log, so I will leave him to it if that's ok! Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.