Computing.Net > Forums > Security and Virus > errorplace.com, how to get rid of

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

errorplace.com, how to get rid of

Reply to Message Icon

Name: Rudderman
Date: May 18, 2004 at 05:44:49 Pacific
OS: XP Pro SP1
CPU/Ram: P4 3Ghz/512RAM
Comment:

I have a problem with IE being redirected to errorplace.com. Here is what I have tried to fix it:
- Downloaded and ran the uninstall utility from errorplace.com
- Ran adaware
- Ran bazooka
- Ran spybot and clicked fix all items
I have downloaded Hijackthis, but haven't used it yet. Please help

Thanks
David



Sponsored Link
Ads by Google

Response Number 1
Name: clover
Date: May 18, 2004 at 16:29:31 Pacific
Reply:

Not sure how advanced it has got but I had it a while ago.

I downloaded CWshredder from http://www.spywareinfo.com/~merijn/files/cwshredder.zip

started up in safe mode by tapping f8 on bootup.
Deleted C:\WINDOWS\vopqihwud.dll
ran CWshredder, clicked fix to all it found.


ran HijackThis and deleted

O2 - BHO: (no name) - {A7EEFDFC-2CB6-4196-A3D8-0D3C54B064B2} - C:\WINDOWS\vopqihwud.dll

As I said not sure if they have added something else so see if any more entries match the .dll above in HijackThis log.

Hope it helps



0

Response Number 2
Name: Rudderman
Date: May 19, 2004 at 15:38:54 Pacific
Reply:

Thanks for the reply,
I deleted the following using hijackthis and it seems to have worked:

O2 - BHO: (no name) - {4CCAA865-39FA-4A1A-A6C9-B78CD4F5EA00} - C:\WINDOWS\xbsgio.dll


0

Response Number 3
Name: aslantifosi
Date: June 20, 2004 at 23:44:29 Pacific
Reply:

i have same problem. and it is my hj list:

Logfile of HijackThis v1.97.7
Scan saved at 09:41:18, on 21.06.2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\antivirus\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\ANTIVI~1\NORTON~1\navapw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Babylon\Babylon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\Microsoft Visual Studio .NET 2003\Common7\IDE\devenv.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Documents and Settings\alirizat\Desktop\HijackThis.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {21B71D82-A96B-4C5D-97DC-CC6F0D198D53} - C:\WINDOWS\rrhpf.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\antivirus\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\antivirus\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\WINDOWS\Downloaded Program Files\googlenav.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\ANTIVI~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - HKCU\..\Run: [Babylon Translator] C:\Program Files\Babylon\Babylon.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at0_x.cab
O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} (AXWebMon Control) - http://www.smilecam.com/home/ezwebcam/eng5/common/AXWebMonProj1.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {3AE9ED90-4B59-47A0-873B-7B71554B3C3E} (JoystickCtl Class) - http://www.bigredswitch.co.uk/toolbox/joystick/examples/joystick.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) - http://toolbar.google.com/data/tr/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F2A84794-EE6D-447B-8C21-3BA1DC77C5B4} (SDKInstall Class) - file://D:\ENGLISH\PLATSDK\controls\sdkinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = invenoa.com
O17 - HKLM\Software\..\Telephony: DomainName = invenoa.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{A001A3AD-F066-44FA-B4AC-A9A380B13A9D}: NameServer = 10.0.0.5
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = invenoa.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{A001A3AD-F066-44FA-B4AC-A9A380B13A9D}: NameServer = 10.0.0.5
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = invenoa.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{A001A3AD-F066-44FA-B4AC-A9A380B13A9D}: NameServer = 10.0.0.5


please help me!!!


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: errorplace.com, how to get rid of

How to get rid of SeekSeek? www.computing.net/answers/security/how-to-get-rid-of-seekseek/10728.html

How to get rid of system32.html www.computing.net/answers/security/how-to-get-rid-of-system32html/20194.html

How to get rid of Wbock32.DLL www.computing.net/answers/security/how-to-get-rid-of-wbock32dll/13887.html