Forum Home
Press F1
 
Thread ID: 48727 2004-08-30 23:41:00 www.errorplace.com on browser - spyware? nomad (3693) Press F1
Post ID Timestamp Content User
267203 2004-08-30 23:41:00 Hiya

Sometimes when I bumped onto a wrong url or a lost link the error page of IE appears and sometimes this www.errorplace.com appears. I have done a spyware check on it and then a few days later I see it again.

Does anyone know how to get rid of this thing?
nomad (3693)
267204 2004-08-30 23:42:00 i think when a pop up box appears too saying you must click ok or something like that. nomad (3693)
267205 2004-08-30 23:44:00 There is a uninstaller here (http://www.errorplace.com/)
hth
johnboy (217)
267206 2004-08-31 00:01:00 If the uninstaller from johnboy does not work run Ad-Aware and Spybot
Failing that use Hijackthis and post your log for experts to check the entries.

For those using Hijackthis or having spyware or hijack problems there is some good information at this link.
hometown.aol.co.uk
Jim B (153)
267207 2004-08-31 11:41:00 Logfile of HijackThis v1.98.0
Scan saved at 10:50:03 p.m., on 31/08/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\QCONSVC.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\tp4serv.exe
C:\Program Files\Thinkpad\ConnectUtilities\QCWLICON.EXE
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINNT\system32\RunDll32.exe
C:\WINNT\system32\PRPCUI.exe
C:\PROGRA~1\Thinkpad\UTILIT~1\tphkmgr.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\WINNT\system32\ltcm000c.exe
C:\WINNT\system32\wuauclt.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\CFGSAFE\AUTOCHK.EXE
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\Thinkpad\Utilities\tponscr.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\ICQ\Icq.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ray\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = lookfor.cc
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = lookfor.cc
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clear.net.nz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lookfor.cc?pin=29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = lookfor.cc
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = lookfor.cc
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = lookfor.cc
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lookfor.cc?pin=29126
O2 - BHO: DAPBHO Class - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\Program Files\DAP\DAPIEBar.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {9C9327A0-8B21-473C-B851-45B70B36E1FF} - C:\WINNT\hhsfqcg.dll
O2 - BHO: Adobe Acrobat Control for ActiveX - {CA8A9780-280D-11CF-A24D-444553540000} - C:\PROGRA~1\Adobe\ACROBA~1.0\Acrobat\ActiveX\pdf.o cx
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [FastCache] C:\Program Files\AnalogX\FastCache\fc.exe
O4 - HKLM\..\Run: [BCONSET] regedit /s "C:\Program Files\ThinkPad\ConnectUtilities\bconprof.reg"
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\Thinkpad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPw rMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\Thinkpad\UTILIT~1\tphkmgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [XircWinModem4] ltcm000c.exe 9
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINNT\system32\iexplorer.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpywareGuard] C:\WINNT\system32\winprc64.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AUTOCHK.LNK = C:\CFGSAFE\AUTOCHK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\syihidco.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - software-dl.real.com
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - us.dl1.yimg.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{E153CCE8-7C3B-4FE7-9B29-93478277FBC7}: NameServer = 203.97.33.14 203.97.37.14
nomad (3693)
267208 2004-09-01 07:19:00 does anyone know how to fix this?
that stupid uninstaler does not work .. as others have had this too with my google search.

now i updated lavasoft i get like 30 found and i just did a scan yesterday. when i open my homepage www.clear.net.nz 3 or 4 popups come up, something got copied onto my desktop without my attention. this errorplace.com page does not close, I need to press ALT CRTL DEL.

I am gonna update McAfee now.
nomad (3693)
267209 2004-09-01 08:30:00 my computer has been hijacked!!
my favourites menu of IE now list only the folder "media"
everything else is gone. but if I go to the start menu fav's is still all there...

i have got mcafee update, lavasoft with update, spybot with update and a couple of websties. hope this fix it, does anyone have exp with this.

what i think wbout this thing is it reinstalls itself when u are logged on or when it simply detects a active internet line. i had www.clear.net.nz and i saw 4 pop and zonealarm was requesting me to give authority for it to pass ....... so i did a lavasoft immediately after restarting it found another 12 bugs.
nomad (3693)
267210 2004-09-01 09:06:00 You have the DAP disease. First try the method described here (www.spyany.com) then run Adaware (www.majorgeeks.com) Pheonix (280)
267211 2004-09-01 09:09:00 Also pay, before restarting PC to run Ccleaner (http://www.ccleaner.com/) which will clean out your Internet cache, where it has been known for trojans to hide. The only thing to change from standard install is tick the "delete index.dat file" Pheonix (280)
267212 2004-09-01 09:12:00 sounds like it missed a bit and the installer is still on your pc. clean out ALL temp files.
make sure you do a full system scan with adaware and spybot in SAFE MODE, you might also want to try running CWshredder.

then check with hijackthis for anythind werid.
tweak'e (174)
1 2 3