1,661 Posted Topics

Member Avatar for Michelle1070

Hi Michelle, welcome to DaniWeb :D First, right-click in an open area of your desktop and select [B]New[/B], [B]Folder[/B]; give the new folder a name (something like HJT or HijackThis), and then drag the hijackthis.exe icon that is on your desktop into the new folder. I don't see the typical …

Member Avatar for DMR
0
627
Member Avatar for JessKenziesMom

Hi Jessica, welcome to DaniWeb :D You will need to disconnect from the internet so you may wish to print these instructions. Download [B]Ewido Security Suite[/B] from here: [url]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install it, and while installing, under [B]Additional Options[/B], [U]uncheck[/U] [B]Install background guard[/B] and [B]Install scan via context menu[/B]. From the main …

Member Avatar for dlh6213
0
267
Member Avatar for cjillson7030

Download, install, update, and run the PurityScan uninstaller -- [url]http://www.purityscan.com/uninstall.html[/url] Download [B]Ewido Security Suite[/B] from here: [url]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install it, and while installing, under [B]Additional Options[/B], [U]uncheck[/U] [B]Install background guard[/B] and [B]Install scan via context menu[/B]. From the main Ewido screen, click on [B]Update[/B] in the left menu, and then click …

Member Avatar for DMR
0
315
Member Avatar for dfederman

Most likely the teen is using the net for research (just researching some stuff he shouldn't be in the midst of what he should be). I think giving him his own computer, if connected to the net, will just encourage the behavior, though it would keep the offensive material away …

Member Avatar for ArtChess
0
1K
Member Avatar for SilentBob3208

SilentBob3208, For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire contents of your C:\Windows\Temp folder. Delete the entire contents of your C:\Temp folder (if you have one). Do a …

Member Avatar for jjmiami05
0
615
Member Avatar for aslee

Hi aslee, welcome to DaniWeb :D This first part if kind of a guess, so you may not find any of the files listed. Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). …

Member Avatar for dlh6213
0
302
Member Avatar for rahulgbe

Hi Rahul, welcome to DaniWeb :D First, you should go to Windows Update and get SP1a for both XP and IE. Then go here and follow the instructions: [url]http://securityresponse.symantec.com/avcenter/venc/data/hacktool.rootkit.html[/url] After you've done that, close any open browser windows, scan with hijackthis, and post a new log please.

Member Avatar for dlh6213
0
156
Member Avatar for soulkeeper90

Hi soulkeeper, welcome to DaniWeb :D Start with this -- For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire contents of your C:\Windows\Temp folder. Delete the entire contents of …

Member Avatar for dlh6213
0
400
Member Avatar for emilythestrange

Hi Emily, welcome to DaniWeb :D Be sure your system is set to "Show hidden files and folders" Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe Mode and do …

Member Avatar for dlh6213
0
276
Member Avatar for n00dlejester

Download CWShredder 2.14 from here: [url]http://www.intermute.com/products/cwshredder.html[/url] Run it, and press the [B]Fix[/B] button (not scan). Close all windows before hitting the Fix button. For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Cookies History Local Settings\Temp Local Settings\Temporary Internet Files\Content.IE5 …

Member Avatar for dlh6213
0
119
Member Avatar for Commodore_64

Please review this thread: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] Then, after your friend has moved HijackThis, post a new log.

Member Avatar for dlh6213
0
183
Member Avatar for wezzerjapan05

Try getting this self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it in this thread.

Member Avatar for dlh6213
0
124
Member Avatar for ljmora501

Did this problem start after you went online with the 'new' computer? If so, this may help explain what might have happened: [url]http://www.daniweb.com/techtalkforums/thread16365.html[/url] Try using System Restore to set your system back to a point before you started having trouble.

Member Avatar for Coconut Monkey
0
109
Member Avatar for Andrew Bentley

Hi Andrew, welcome to DaniWeb :D Sorry for the delay in responding to this :( Please review this thread to get the latest version of HijackThis, and put it into it's own permanent folder. Then, post a new log please.

Member Avatar for dlh6213
0
111
Member Avatar for stemp65

Hi stemp65, welcome to DaniWeb :D Please review the following thread, and then post a new HijackThis log: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] Thanks :)

Member Avatar for crunchie
0
194
Member Avatar for 1337cshacker

[B]Don't[/B] remove alg.exe! More info on it here: [url]http://www.liutilities.com/products/wintaskspro/processlibrary/alg/[/url] Read this thread, it may help: [url]http://www.daniweb.com/techtalkforums/thread16365.html[/url] Get HijackThis from here so we can help with whatever the real problem is: [url]http://www.spywareinfo.com/~merijn/[/url] Close all browser windows, 'Scan and Save Log' with hijackthis, copy and paste the entire log here in this …

Member Avatar for dlh6213
0
316
Member Avatar for Linchey050

Get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it in this thread.

Member Avatar for dlh6213
0
454
Member Avatar for allisonmaria

Hi allisonmaria, welcome to DaniWeb :D Please review this thread and then post a new HijackThis log: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] Thanks :)

Member Avatar for dlh6213
0
138
Member Avatar for navygin21

Hi Jennifer, welcome to DaniWeb :D To answer your question "[B]Does everything that show on the log indicate something "wrong"[/B]?" The answer is [B]NO![/B] Just about everything shown in an HijackThis log is important to proper operation of your computer. CCAPP.EXE is a part of Norton, and you can find …

Member Avatar for dlh6213
0
231
Member Avatar for cancer10

Nothing can catch everything, but SpywareGaurd is one recommended program; a link to it can be found in this thread (along with other helpful advice and tools): [url]http://www.daniweb.com/techtalkforums/thread5690.html[/url]

Member Avatar for dlh6213
0
57
Member Avatar for tharmet

Hi Tammy, welcome to DaniWeb :D Go to Add/Remove Programs in your Control Panel and remove (if present): [B]WeatherBug Ebates[/B] For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire …

Member Avatar for dlh6213
0
144
Member Avatar for SilentBob3208

According to Staples ([url]http://www3.staples.com/spotlights/000000/virus.htm)[/url], you must first remove all previously installed antivirus software, and any active firewall needs to be disarmed; have you done this? Personally I think the program is unnecessary because there are enough free programs available to do what this claims to do, but since you've already …

Member Avatar for dlh6213
0
128
Member Avatar for RaineX

Hi RaineX, welcome to DaniWeb :D Start with this -- For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire contents of your C:\Windows\Temp folder. Delete the entire contents of …

Member Avatar for dlh6213
0
460
Member Avatar for Pikachu

Hi Pikachu, What little I could find out about it doesn't really help much ([url]http://translate.google.com/translate?hl=en&sl=zh-CN&u=http://bbs.db.kingsoft.com/forumdisplay.php%3Ffid%3D110%26sid%3Dnbdq4L&prev=/search%3Fq%3DNPFMONTR.exe%26hl%3Den%26lr%3D%26sa%3DG)[/url]. Lack of information is usually a pretty good indiction of a bad file. Can you right-click on NPFMONTR.exe, go to Properties, and let us know whatever info you can (Manufacturer, version, etc.).

Member Avatar for buddylee614
0
206
Member Avatar for Benny591

Hi Benny591, welcome to DaniWeb :D Since you suspect a 'bug' I've move your thread to the Virus forum (for the time being anyway). In order for us to see what you have running on your system, I suggest you get the self-extracting version of HijackThis from here (in line …

Member Avatar for dlh6213
0
444
Member Avatar for MpG

[QUOTE=MpG]I recently started using Mozzila firefox but I dont know where the ''Temp'' folder of Mozilla is and whether is accesible just like IE or not.[/QUOTE] Go to Tools, Options, click on Privacy (padlock icon on the left), and there you have it -- and there's even a button to …

Member Avatar for dlh6213
0
106
Member Avatar for HurlaBurrito

Hi HurlaBurrito, welcome to DaniWeb :D Go to Windows Update and get SP1a for XP Scan with hijackthis and have it fix the following entries: O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file) O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\kodhu.dll O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - …

Member Avatar for dlh6213
0
204
Member Avatar for ggogeta

Hi gg, welcome to DaniWeb :D Go to Add/Remove Programs in your Control Panel and remove (if present): Viewpoint Manager (or Viewpoint) Right-click in an open area of your desktop and select [B]New[/B], and then [B]Folder[/B]; give the new folder a name (something like HJT or HijackThis), and then drag …

Member Avatar for dlh6213
0
223
Member Avatar for rkerner

Hi rkerner, welcome to DaniWeb :D Please review this thread, and the post a new log: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] Thanks.

Member Avatar for rkerner
0
242
Member Avatar for chuckles225

Hi chuckles225, welcome to DaniWeb :D Please review this thread and then post a new log: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] Thanks.

Member Avatar for chuckles225
0
197
Member Avatar for lazyfly21

Hi lazyfly21, welcome to DaniWeb :D Please get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, 'Scan and Save Log' with hijackthis, copy the log, and paste it in this thread.

Member Avatar for dlh6213
0
148
Member Avatar for psulions

Hi psulions, welcome to DaniWeb :D Boot into Safe Mode and do a search for that file; you'll probably find it in two locations -- the Prefetch folder and a Temp folder. Delete any instances found. If you would like us to help you clean up anything else that may …

Member Avatar for dlh6213
0
136
Member Avatar for lemurianprince

Hi lemurianprince, welcome to DaniWeb :D I've moved your thread to the Virus forum as that is the only place HijackThis log are allowed to be posted. For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History …

Member Avatar for DMR
0
498
Member Avatar for burketdsl

Hi Laura, I don't think it will help with your Shutdown problem, but there are some things in your log that should be fixed. Go to Add/Remove Programs in your Control Panel and remove (if found): [B]Media Access Internet Optimizer[/B] Scan with HJT and have it fix the following entries: …

Member Avatar for dlh6213
0
536
Member Avatar for rex12345

Hi rex, welcome to DaniWeb :D Please review this thread, and then post a new log please: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] Thanks.

Member Avatar for dlh6213
0
99
Member Avatar for Kiwi Chris

Hi Kiwi Chris, welcome to DaniWeb :D Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe Mode and do a search for these files and delete any instances found: [B]param32.dll …

Member Avatar for dlh6213
0
282
Member Avatar for whyme

You can remove Newdotnet either from Add/Remove Programs, or by going to [url]http://www.newdotnet.com/#remove[/url] and scrolling down to the Uninstall tool. Go to Windows Update and get SP2 for XP and IE ASAP. See this thread for more advice on keeping your computer clean: [url]http://www.daniweb.com/techtalkforums/thread16365.html[/url]

Member Avatar for dlh6213
0
92
Member Avatar for mldaniels

Hi Maurine, welcome to DaniWeb :D For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire contents of your C:\Windows\Temp folder. Delete the entire contents of your C:\Temp folder (if …

Member Avatar for mldaniels
0
308
Member Avatar for patrick_q

Get the Pocket Killbox from here: [url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url] Unzip the file to your desktop. Go offline until this is completed (you may wish to print these instructions). Boot into Safe Mode and do a search for these files and delete any instances found: [B]param32.dll guninst.exe popup_bl.dll systr.dll svrhost.exe[/B] If any could …

Member Avatar for dlh6213
0
164
Member Avatar for vash420xxx

Hi vash420xxx, I've split your post into it it's own thread (per forum rules -- [url]http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq#faq_rules)[/url]. Please see this thread, and then post a new hijackthis log: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url] Thanks for understanding :)

Member Avatar for dlh6213
0
114
Member Avatar for Quitahd

Hi Quitahd, welcome to DaniWeb :D Your English is pretty good :) First thing to do is right-click on your desktop, and select [B]New[/B], [B]Folder[/B]. Give the new folder a name (like HJT or HijackThis), and then drag the hijackthis.exe icon that is on your desktop into this new folder. …

Member Avatar for Quitahd
0
357
Member Avatar for munky79

Hi Munky79, welcome to DaniWeb :D I've split your post into it's own thread (per forum rules -- [url]http://www.daniweb.com/techtalkforums/faq.php?faq=daniweb_faq#faq_rules)[/url]. Please review this thread and then post a new HijackThis log: [url]http://www.daniweb.com/techtalkforums/thread24085.html[/url]

Member Avatar for dlh6213
0
185
Member Avatar for GypsyTeaRoom

If you haven't already, you should try System Restore; here are instructions for using it: [url]http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q306084[/url] Without being able to download anything, this could be difficult. Have you considered backing up what you can and reinstalling Windows? Do you have access to another computer where you can download, and then …

Member Avatar for dlh6213
0
150
Member Avatar for Shackbase

New link for the story: [url]http://www.totalillusions.net/forum/index.php?showtopic=328&st=0[/url] (The other one seems to have disintegrated... do you suppose bitchchecker had anything to do with that???)

Member Avatar for Real-tiner
1
248
Member Avatar for mabantot

What OS are you using? If you have System Restore available, try using that to return your system to a date before you started having problems. Try running HijackThis from Safe Mode; we won't get a complete picture that way, but at least a starting point.

Member Avatar for dlh6213
0
100
Member Avatar for irishbum04

Hi irishbum, welcome to DaniWeb :D Go to Add/Remove Programs in your Control Panel and remove [B]WareOut[/B]. For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves): Local Settings\Temp Cookies History Local Settings\Temporary Internet Files\Content.IE5 Delete the entire contents of your …

Member Avatar for dlh6213
0
143
Member Avatar for JediSange

Hi JediSange and Xyzyxx, welcome to DaniWeb :D Xyzyxx, you really should start your own thread, unless you just want to follow along with this one and see if you can clean up your system; but please, do not post any logs within this thread. Thanks :) Start with this: …

Member Avatar for dlh6213
0
220
Member Avatar for server_crash

As a precaution, I suggest you boot into Safe Mode and do a search for these files and delete any instances found: [B]param32.dll guninst.exe popup_bl.dll systr.dll svrhost.exe[/B] If any could not be deleted -- most likely param32.dll -- run Pocket Killbox ([url]http://bleepingcomputer.com/files/spyware/KillBox.zip[/url]) and paste the full file path of file …

Member Avatar for DMR
0
518
Member Avatar for AppleSam

Hi AppleSam, welcome to DaniWeb :D Glad you found the right place to post this :) Remove Newdotnet, either from Add/Remove Programs, or by going to [url]http://www.newdotnet.com/#remove[/url] and scrolling down to the Uninstall tool. Download [B]Ewido Security Suite[/B] from here: [url]http://fileforum.betanews.com/detail/ewido_security_suite/1098736486/1[/url] Install it, and while installing, under [B]Additional Options[/B], [U]uncheck[/U] …

Member Avatar for dlh6213
0
895
Member Avatar for Lachessis

Hi Lachessis, welcome to DaniWeb :D There are several things that can cause this, if you think this may be related to some type of malware on your system, I suggest you get the self-extracting version of HijackThis from here (in line 2): [url]http://www.malwareremoval.com/downloads.html[/url] Then close any open browser windows, …

Member Avatar for Lachessis
0
150

The End.