| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 48727 | 2004-08-30 23:41:00 | www.errorplace.com on browser - spyware? | nomad (3693) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 267203 | 2004-08-30 23:41:00 | Hiya Sometimes when I bumped onto a wrong url or a lost link the error page of IE appears and sometimes this www.errorplace.com appears. I have done a spyware check on it and then a few days later I see it again. Does anyone know how to get rid of this thing? |
nomad (3693) | ||
| 267204 | 2004-08-30 23:42:00 | i think when a pop up box appears too saying you must click ok or something like that. | nomad (3693) | ||
| 267205 | 2004-08-30 23:44:00 | There is a uninstaller here (http://www.errorplace.com/) hth |
johnboy (217) | ||
| 267206 | 2004-08-31 00:01:00 | If the uninstaller from johnboy does not work run Ad-Aware and Spybot Failing that use Hijackthis and post your log for experts to check the entries. For those using Hijackthis or having spyware or hijack problems there is some good information at this link. hometown.aol.co.uk |
Jim B (153) | ||
| 267207 | 2004-08-31 11:41:00 | Logfile of HijackThis v1.98.0 Scan saved at 10:50:03 p.m., on 31/08/2004 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\ibmpmsvc.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\Ati2evxx.exe C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe C:\WINNT\System32\svchost.exe C:\WINNT\System32\QCONSVC.EXE C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\stisvc.exe C:\WINNT\system32\ZoneLabs\vsmon.exe C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe C:\WINNT\Explorer.EXE C:\WINNT\system32\tp4serv.exe C:\Program Files\Thinkpad\ConnectUtilities\QCWLICON.EXE C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe C:\WINNT\system32\RunDll32.exe C:\WINNT\system32\PRPCUI.exe C:\PROGRA~1\Thinkpad\UTILIT~1\tphkmgr.exe C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe C:\PROGRA~1\Adaptec\DirectCD\directcd.exe C:\WINNT\system32\ltcm000c.exe C:\WINNT\system32\wuauclt.exe C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe C:\CFGSAFE\AUTOCHK.EXE C:\Program Files\Nikon\NkView6\NkvMon.exe C:\Program Files\Thinkpad\Utilities\tponscr.exe C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE C:\Program Files\ICQ\Icq.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Ray\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = lookfor.cc R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = lookfor.cc R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clear.net.nz/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lookfor.cc?pin=29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = lookfor.cc R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = lookfor.cc R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = lookfor.cc R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lookfor.cc?pin=29126 O2 - BHO: DAPBHO Class - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\Program Files\DAP\DAPIEBar.dll O2 - BHO: jimmyhelp.CBrowserHelper - {9C9327A0-8B21-473C-B851-45B70B36E1FF} - C:\WINNT\hhsfqcg.dll O2 - BHO: Adobe Acrobat Control for ActiveX - {CA8A9780-280D-11CF-A24D-444553540000} - C:\PROGRA~1\Adobe\ACROBA~1.0\Acrobat\ActiveX\pdf.o cx O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [FastCache] C:\Program Files\AnalogX\FastCache\fc.exe O4 - HKLM\..\Run: [BCONSET] regedit /s "C:\Program Files\ThinkPad\ConnectUtilities\bconprof.reg" O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\Thinkpad\ConnectUtilities\QCWLICON.EXE O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPw rMonitor O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\Thinkpad\UTILIT~1\tphkmgr.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe O4 - HKLM\..\Run: [XircWinModem4] ltcm000c.exe 9 O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINNT\system32\iexplorer.exe O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SpywareGuard] C:\WINNT\system32\winprc64.exe O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: AUTOCHK.LNK = C:\CFGSAFE\AUTOCHK.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\syihidco.exe O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - software-dl.real.com O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - us.dl1.yimg.com O17 - HKLM\System\CCS\Services\Tcpip\..\{E153CCE8-7C3B-4FE7-9B29-93478277FBC7}: NameServer = 203.97.33.14 203.97.37.14 |
nomad (3693) | ||
| 267208 | 2004-09-01 07:19:00 | does anyone know how to fix this? that stupid uninstaler does not work .. as others have had this too with my google search. now i updated lavasoft i get like 30 found and i just did a scan yesterday. when i open my homepage www.clear.net.nz 3 or 4 popups come up, something got copied onto my desktop without my attention. this errorplace.com page does not close, I need to press ALT CRTL DEL. I am gonna update McAfee now. |
nomad (3693) | ||
| 267209 | 2004-09-01 08:30:00 | my computer has been hijacked!! my favourites menu of IE now list only the folder "media" everything else is gone. but if I go to the start menu fav's is still all there... i have got mcafee update, lavasoft with update, spybot with update and a couple of websties. hope this fix it, does anyone have exp with this. what i think wbout this thing is it reinstalls itself when u are logged on or when it simply detects a active internet line. i had www.clear.net.nz and i saw 4 pop and zonealarm was requesting me to give authority for it to pass ....... so i did a lavasoft immediately after restarting it found another 12 bugs. |
nomad (3693) | ||
| 267210 | 2004-09-01 09:06:00 | You have the DAP disease. First try the method described here (www.spyany.com) then run Adaware (www.majorgeeks.com) | Pheonix (280) | ||
| 267211 | 2004-09-01 09:09:00 | Also pay, before restarting PC to run Ccleaner (http://www.ccleaner.com/) which will clean out your Internet cache, where it has been known for trojans to hide. The only thing to change from standard install is tick the "delete index.dat file" | Pheonix (280) | ||
| 267212 | 2004-09-01 09:12:00 | sounds like it missed a bit and the installer is still on your pc. clean out ALL temp files. make sure you do a full system scan with adaware and spybot in SAFE MODE, you might also want to try running CWshredder. then check with hijackthis for anythind werid. |
tweak'e (174) | ||
| 1 2 3 | |||||