Over 1 million tech questions and answers.

Geocities web page building:Deleted index.html/index.htm

Q: Geocities web page building:Deleted index.html/index.htm

had a geocities web page for one year although i barely knew how to build,change and manage the site.

JUST NOW,on the file manager page, i deleted 2 files of 3 causing a mistake.

i now get a "warning you do not have an "html.index or"index.htm"file. when i type my page in a search site, i get a page saying index page.

how can i go back ?

RELEVANCY SCORE 200
Preferred Solution: Geocities web page building:Deleted index.html/index.htm

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

A: Geocities web page building:Deleted index.html/index.htm

by going to this site, i was able to solve muy this problem
http://help.yahoo.com/help/us/geo/gfiles/gfiles-22.html

thanks for the viewing.

Read other 1 answers
RELEVANCY SCORE 106.4

Logfile of HijackThis v1.97.7
Scan saved at 10:52:58 AM, on 10/20/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\ZIPCD\DIRECTCD.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
C:\WINDOWS\SYSTEM\MSWHEEL.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IOWATCH.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IMGICON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS10
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://msaps.dll/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://msaps.dll/index.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://msaps.dll/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://msaps.dll/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://msaps.dll/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://msaps.dll/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssista... Read more

A:res://msaps.dll/index.html--- as start up page

Welcome to TSG!!

Create a permanent folder on your hard drive for Hijackthis, like My Documents\HJT
Click on this link to download the new version of Hijackthis post a log using that version from your permanent folder.
 

Read other 3 answers
RELEVANCY SCORE 106.4

I have changed the description and meta tags in the html of my index webpage.

How long do I need to wait for the description to change on the various search engines results pages.

Thanks
 

Read other answers
RELEVANCY SCORE 105.2

I could really use some help... My 17yo son was surfing something ( porn im sure ) and now im getting pop ups and my home page on IE 6 keeps going back to his -

res://mshp.dll/index.html#10213

I also ran HijackThis,

Logfile of HijackThis v1.97.7
Scan saved at 8:52:07 PM, on 1/6/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = C:\WINNT\system32\searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://mshp.dll/index.html#10213
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINNT\system32\sea... Read more

A:IE home page keeps getting set to - res://mshp.dll/index.html#10213

Hi NorcalJim

Welcome to TSG!

Click on the link below to download CWShredder. Close all browser windows,UnZip the file, click on the cwshredder.exe then click "Fix" (Not "Scan only") and let it do it's thing.

http://www.merijn.org/files/cwshredder.zip

When it is finished restart your computer.

To help prevent this from happening again, I strongly recommend you install the folowing patches for the vulnerabilities that this hijacker exploits:

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-011.asp

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS00-075.asp

*Note: The simplest way to make sure you have all the security patches is to go to Windows update and install all "Critical Updates"

EDIT: I see now you said you have run Adaware and Spybot, but if you did not run them with these settings you should run them again accordingly.

Go here http://www.lavasoftusa.com/support/download/ and download
Adaware 6 Build 181

Install the program and launch it.

First in the main window look in the bottom right corner and click on "Check for updates now" and download the latest referencefiles.

Make sure the following settings are made and on -------"ON=GREEN"

From main window :Click "Start" then " Activate in-depth scan (recommended)"

Click "Use custom scanning options" then click "Customize" and have the... Read more

Read other 3 answers
RELEVANCY SCORE 105.2

Hello, tried everything I could to figure this out. My homepage keeps getting put on the URL above, entitled "Home Search". I've done scans with Norton (shows nothing), Spybot (shows a Data Source Object exploit), Adaware 6.0(said it was a CWS trojan), and tried the CWS shredder. Spybot referred me to http://security.greymagic.com/adv/gm001-ie/, and I tried that fix to no avail. I've ran "hijack this" and here's my log. Any help on this one would be deeply appreciated.Logfile of HijackThis v1.97.7Scan saved at 4:07:47 PM, on 6/16/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\Program Files\Norton AntiVirus\SAVScan.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeC:\WINDOWS\system32\addqc32.exeC:\WINDOWS\... Read more

A:Home page hijacking to:res://bxwdr.dll/index.html#

Firs tthing you need to do is create a directory on your c: drive called c:\hijackthis and move the download and run HijackThis from that location. This is one is a pain to clean so bear with me with the process.I want you to fix some of those entries. Please do the following:Please make sure that you can view all hidden files. Instructions on how to do this can be found here:How to see hidden files in WindowsPlease put a checkmark in the box for each of these entries, close all other windows, and click the fix button:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\bxwdr.dll/sp.html#96676R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://bxwdr.dll/index.html#96676R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://bxwdr.dll/index.html#96676R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\bxwdr.dll/sp.html#96676R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://bxwdr.dll/index.html#96676R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\bxwdr.dll/sp.html#96676O2 - BHO: (no name) - {602C3D03-C6C8-CE58-094E-67D08A6CADCB} - C:\WINDOWS\msbg.dllO4 - HKLM\..\Run: [addpy32.exe] C:\WINDOWS\... Read more

Read other 15 answers
RELEVANCY SCORE 105.2

I've had the pleasure last night of having to figure out how to clean this thing off over a remote connection--without the benefit of safe mode. It looks like I've successfully cleaned it--no signs of reinfection yet--so I thought I'd share what I've learned. I'm trying to write it as a high-level description so that non-pros might be able to understand it. I'm writing this information down now from memory, though, not from a good set of notes. I'm also not a tech support professional, and in particular I know very little about how BHOs work.

From what I can tell, this is a variation of the ZAFI worm, or else the ZAFI worm hasn't been described accurately on the anti-virus sites. I suspect it's the ZAFI worm slightly modified and cludged together with another worm (BHO based) so that they will reinfect each other as you're trying to clean it. I don't know what the payload or method of infection is. I've only been concerned with cleaning it off, and will leave the rest to the experts.

On my system, it will reinfect the machine from 3 different areas, so that if you clean one or two spots, the third can still reinfect you and you have to start over again. The system I was working on was running XP.

The three infected areas that I noticed:
- Executable in the windows folder
- Executable in the windows/system32 folder
- Browser helper object (DLL) associated with Internet Explorer

The files are randomly named and hav... Read more

A:Possible fix for home page set to res://random.dll/index.html#96676

There's also a good thread (though more technical) at this other forum: http://forums.spywareinfo.com/index.php?showtopic=7447&st=0

I wish I had seen it before I went through this hell.
 

Read other 1 answers
RELEVANCY SCORE 104

Have run current versions of Ad-aware (configured with recommended custom scanning options), Spybot-S&D and CWShredder all find offending files but on reboot it's deja-vu.
Hijack logs follows, (hijackthislog-1)is before any cleaning and (hijackthislog-2) is after Ad-a, SSD and CWS have done their magic. The reboot log is identical to HJt-1 log.

Any insight would be appreciated!

HJt-1 log:

Logfile of HijackThis v1.97.7
Scan saved at 8:34:13 PM, on 2/6/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP2 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\WINNT\System32\3Com_DMI\3CDMINIC.EXE
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\technesis\enterprise\service\tnSvcNT.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\program files\quicktime\qttas... Read more

A:Hijacked home page to res://mshp.dll/index.html#37049

Due to the incredible depth of resource available on this site and especially the CWS site I was able to cure myself.
To all with hijack problems the tutorial at http://www.spywareinfo.com/~merijn/htlogtutorial.html
is fantastic especially the referenced sites in the tutorial where you can search specific info from your scan log.

My fix was as follows:

From HJt log deleted the following:

O2 - BHO: ShowSearch module - {E2DDF680-9905-4dee-8C64-0A5DE7FE133C} - C:\Documents and Settings\MBarella\Application Data\syszd\mssearch.dll
O4 - HKLM\..\Run: [Image] rundll32 C:\WINNT\image.dll,Install
O4 - HKCU\..\Run: [explore] c:\winnt\explore.exe
O4 - HKCU\..\Run: [sysinfo] C:\WINNT\sysinfo.exe

Rebooted and was cured!!

Thank you to all who are dedicated to providing such a wealth of info on keeping ahead of the a-holes who spend time creating this sh*t.

Hope this is helpful for the next poor soul.
 

Read other 1 answers
RELEVANCY SCORE 104

uh yeah, after hours of work i finaly got rid of find4u, and now i have this res://mshp.dll/index.html#37049
ill post my hjt log so you guys can see if anything is wrong...this is frustrating
Logfile of HijackThis v1.97.7
Scan saved at 8:43:05 PM, on 1/18/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Trevor\Local Settings\Temp\Temporary Directory 5 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://mshp.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://mshp.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#37049
... Read more

A:Home page sets itself to res://mshp.dll/index.html#37049

Read other 9 answers
RELEVANCY SCORE 104

Hello, um I had this virus or something in my computer and after i removed it, there are still some of the features left. So, when I'm in firefox, I press "+" so I  could open a new tab, instead of seeing the normal firefox page I just see a blank white screen and it says ---- chrome://quick_start/content/index.html ---- for my location, how do I fix this?

Read other answers
RELEVANCY SCORE 104

Hello all. Looking for help. I have an annoying home page hijacker with pop ups problem for Windows XP. I have searched the forums and have not seen anything like it so it may be new. Please Help.

Have Run

Spybot
adaware
CWS shredder
Trojan remover.

All programs show no problems found.

HIJACKTHIS log is...

Logfile of HijackThis v1.97.7
Scan saved at 8:44:35 PM, on 6/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\addyy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Joe\Desktop\Joe's Folder\New Installs\Roxio Easy CD Creater 5 Platinum\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
C:\Program Files\ABBYY FineReader 5.0 Sprint\CAgent.exe
C:\Documents and Settings\Joe\Desktop\Joe's Folder\New Installs\Logitech Mouse and Keyboard\iTouch\iTouch.exe
C:\DOCUME~1\Joe\Desktop\JOE'SF~1\NEWINS~1\LOGITE~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\d3ql.exe
C:\Documents and Settings\Joe\Desktop\Joe's Folder\New Installs\AIM Instant Messenger\aim.exe
C:\Documents and Settings\Joe\Desktop\Joe's Folder\New Installs\Rainlender\Rainlendar\Rainlendar.exe
C:\WINDOWS... Read more

A:home page hijack/ pop ups res://lunkb.dll/index.html#96676

Read other 9 answers
RELEVANCY SCORE 102.8

Hi, I'm a newbie in this forum,
I justy realised that my computer is now reseting my
Home page sets itself to res://mshp.dll/index.html#37049 everytime I start
Internet Explorer.

here's my hjt log so you guys can see if anything is wrong...this is frustrating

thanks for your help!

Pierre
Logfile of HijackThis v1.97.7
Scan saved at 18:28:59, on 2004-04-09
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\r_server.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\System32\devldr32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C... Read more

A:[Solved] Home page sets itself to res://mshp.dll/index.html#37049

Read other 9 answers
RELEVANCY SCORE 102.8

Please help me to get rid of
res://mshp.dll/index.html#37049 which overrides my browser home page.
I am using Windows 2000.
 

A:Browser home page is replaced with res://mshp.dll/index.html#37049

Read other 11 answers
RELEVANCY SCORE 102

Redirects Mozilla FF 12.0 to weird webRedirects Mozilla FF 12 to weird web page, http://www.thenetbrains.com/7d6e0d/index.html page, http://www.thenetbrains.com/7d6e0d/index.html

Thank you for your help in advance!

------------------
DDS LOG:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by HP_Administrator at 17:32:03 on 2012-05-03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1214.462 [GMT -4:00]
.
AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\arservice.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS&... Read more

A:Redirects Mozilla FF 12 to weird web page, http://www.thenetbrains.com/7d6e0d/index.html

Hello and Welcome to Bleeping Computer!!My name is Gringo and I'll be glad to help you with your computer problems. I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of usPlease do not run any tools unless instructed to do so.
We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.Please do not attach logs or use code boxes, just copy and paste the text.
Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.Please read every post completely before doing anything.
Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.Please provide feedback about your experience as we go.
A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.NOTE:... Read more

Read other 12 answers
RELEVANCY SCORE 95.6

Im currently using Xtreme pagebuilder to build a webpage. I have uploaded all of the files needed & I have labeled the primary file as the index.html but the page still wont load. Can anyone help me or tell me what im doing wrong. I have even veiwed it in the publushing section of the pagebuilder & it worked, so I figued I could just copy & paste it in my geocities editor but still no haps.
 

A:Help With Html Codes On Geocities Website Im Building

http://help.yahoo.com/help/us/geo/editors/editors-23.html
 

Read other 1 answers
RELEVANCY SCORE 94.8

Hi,

my home page has been hijacked. It reads :
res://koxri.dll/index.html#96676

My operating system is XP and IE 6.

Further more my notepad behaves strange. It closes wihout warning. When I looked for the file notepad.exe there was a notepad.exe.bak.

I downloaded hijackthis and here is the log.

Logfile of HijackThis v1.97.7
Scan saved at 20:24:33, on 2004-07-07
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\runservice.exe
C:\Program\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\sysby32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program\NORTON~1\navapw32.exe
C:\WINDOWS\syshv32.exe
C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program\Digital Line Detect\DLG.exe
C:\Program\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Bo Gerdin\Mina dokument\HiJackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\koxri.dll/sp.html#96676
R0 - HKCU\Software\Microso... Read more

Read other answers
RELEVANCY SCORE 90.4

i have a web page running for 2 months now on geocities.

i want to put an "add-on"(newsheadlines)on to the page.
On the geocities page"add-ons" which has 3 steps, Step 2 has me puzzled(because i'm still learning about computer files)
Step 1 says clip newsheadline code) which i have done

Step 2 says: "Step 2: Click Go To File Manager, select the file you would like to add your News Headlines to, and paste the code in. Click Save and make sure to return to this page and complete Step 3. "
I HAVE GONE TO FILE MANAGER PAGE,but am lost what file to select. i know how to paste,but again,do not know how/which file to select? (my web site is listed on the file manager page)
 

A:familar with geocities web page building ?

File manager lists all of the html pages, images, subdirectories, etc that make up your site/page.

Select the html file that represents the individual page that you want to cut/paste your add-on to. (I am sure that your site is composed of several pages, 'index.htm' is probably the default page with all/most other pages linked to it, just decide what page you want the add-on on). Have the page open in the advanced html editor. Cut and paste your add on where ever you want on your page, then save the file. Go back to file manager and click on preview icon of that particular page to see if presents as you expected, if not, open it again in html editor and work on it some more (you could also preview from html editor, I believe). Just be sure to save your work before you exit html editor.
 

Read other 1 answers
RELEVANCY SCORE 88.8
RELEVANCY SCORE 88.4

I ran a chkdsk on a vista machine and this came up, any ideas what they are or how to fix them ?

index entry iedvtool.dll in index $130 of file 453 is incorrect

index entry iexplorer.exe in index $130 of file 453 is incorrect

index entry wininetplugin.dll in index $130 of file 4103 is incorrect

There is 2 other errors now, the ordinal 459 could not be located in the dynamic link libary urlmon.dll & BHO.DLL but they werent in the chkdsk errors in the cmd
 

Read other answers
RELEVANCY SCORE 88

flrman1 and Crunchie, many thanks for assisting folks like me whose PC had the same problem(s) as did haste's. I Googled the offending URL, which was the same one that had hijacked haste's system, and discoverd Tech Support Guy and the helpful two of you.

I followed your advice, installing and running CWShredder, Ad-Aware and Spybot Search & Destroy and installing all Windows critical updates and service packs. A scan of my system's hard drive found and quarantined the Trojan Byte Verify virus. Thanks to you two, I believe my system is now trouble-free. Anything else I should do? Would running that Hijack thing be beneficial?

Trotter
 

A:res://mshp.dll/index.html

trotter, post a hijackthis log to check whether anything else is running please

please post it in a new thread as it gets confusing helping 2 people in one thread

go to http://www.thespykiller.co.uk/files/HijackThis.exe and download 'Hijack This!'.
make sure it is placed into it's own folder, not a temporary folder. Then doubleclick the Hijackthis.exe.
Click the "Scan" button, when the scan is finished the scan button will become "Save Log" click that and save the log.
Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.
It will possibly show issues deserving our attention, but most of what it lists will be harmless or even required,
so do NOT fix anything yet.
Someone here will be happy to help you analyze the results.
 

Read other 2 answers
RELEVANCY SCORE 88

ok ive read some threads about this and i did the hijack thingy

this is what i got

Logfile of HijackThis v1.97.7
Scan saved at 12:16:27 AM, on 3/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Software\Panda Antivirus Titanium\apvxdwin.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\AIM95\aim.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\program files\steam\steam.exe
C:\Program Files\Panda Sof... Read more

A:res://mshp.dll/index.html

Read other 8 answers
RELEVANCY SCORE 88

I've seen this posted before but now I have the same problem. Everytime I boot up my computer, IE pops up and trys to launch this " 63.246.131.130/index.html "....I've scanned my computer with Norton, S&D, adaware, and CWShredder.They come up with nothing?.....any help would be greatly appreciated!!!!!!

Here's my HJT log:

Logfile of HijackThis v1.97.7
Scan saved at 11:22:43 AM, on 11/23/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common ... Read more

A:Solved: 63.246.131.130/index.html help

Read other 8 answers
RELEVANCY SCORE 86.8

I am running WIN 2000 and I can't get rid of the above home page. Following is my file after I run HiJackThis. Any help would be appreicated. Thanks.

Logfile of HijackThis v1.97.7
Scan saved at 11:33:26 AM, on 4/7/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\DSentry.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\DvzCommon\DvzMsgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.enjoysearch.info/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Mai... Read more

A:res://mshp.dll/index.html#37049

Click on the link below to download CWshredder.
http://www.spywareinfo.com/~merijn/files/cwshredder.zip

Run the program and let it do it's thing. Make sure to click on "Fix" and not scan only.

Next:

Download Spybot http://www.sherrylynn.us/privacypolicy.htm

Make sure to follow the instructions for updates prior to running the scan.

Click on "Search For updates" After the search has completed, the available Updates will be listed. Choose which Updates you would like to Download. Click "Download updates." The Updates will self install. The screen will change and the program will come back and be ready to use.

Sometimes the default Download Location will produce an Error. If that happens, look in the right panel. There you will find a small arrow next to the name of the current Download site. Click on it for a list of alternate sites. One of those should be able to retrieve the files you have selected.

Scan, click on fix problems then reboot.

Post another HJT log.
 

Read other 2 answers
RELEVANCY SCORE 86.8

Can someone please help me get rid of this home search webpage, here is my HijackThis Log, Thank you

Logfile of HijackThis v1.97.7
Scan saved at 1:06:42 PM, on 6/19/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\appmg32.exe
C:\WINDOWS\iery32.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Temp\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mfsdq.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://mfsdq.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://mfsdq.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mfsdq.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mfsdq.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mfsdq.dll/sp... Read more

A:res://mfsdq.dll/index.html#96676 HELP!! here is the log

Please don't duplicate post, keep replying back to your same thread.

http://forums.techguy.org/showthread.php?t=240618
 

Read other 1 answers
RELEVANCY SCORE 86.8

I have the same problem as the previous user has hijacked my computer homepage and I am too much od a novice to follow what you told him. Please help get rid of the res://mshp.dll/index.html#37049 problem.

adam
 

A:res://mshp.dll/index.html#37049 PLEASE HELP!!

Read other 13 answers
RELEVANCY SCORE 86.8

I have been following your thread and have been trying to fix a similar problem dealing with "res://mshp.dll/url_error.html#yahoo.com/" and the pop-up "only the best" or.

Can you help me also?

Logfile of HijackThis v1.97.7
Scan saved at 9:29:44 AM, on 6/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
C:\WINDOWS\System32\LMSXXD.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 600\Bin\HPOstr05.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 600\bin\HPOVDX05.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\US\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: . - {D34F08C5-4F18-477c-86CB-1A9BEECFE37B} - C:\Documents and Settings\US\Ap... Read more

A:res://mshp.dll/index.html#37049 PLEASE HELP!!

Read other 12 answers
RELEVANCY SCORE 86.8

How do I get rid of this!
 

A:res://iafsz.dll/index.html#37049

Hi Verna,

Please do this. Click here to download Hijack This. Run Hijack this.
Click the "Scan" button when the scan is finished the scan button will become "Save Log" click that and save the log.

Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.

DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required. Someone here will be glad to advise you on what to fix.

*Note: When you download Hijack This Do Not download it to a temp folder or to the desktop. Create a permanent folder somewhere like in My Documents and name it Hijack This and put it in that folder.
 

Read other 1 answers
RELEVANCY SCORE 86.8

Hi, I'm having some problems with spyware. Whenever I open up my IE my homepage is set to "res://zqnfr.dll/index.html". Also, whenever I search for anything using google, other "searching" pages come up like "http://search-to-find.com/" and "lookingfor.cc". On top of this pop-up adds are occasionally popping up. I've used ad-aware and HiJackThis, but it hasn't worked. Also, I noticed some unusual running processes, closed them down and removed them from startup using msconfig. I've done what I can, but my IE is still messed up.
I'm posting my HiJackThis log. Thank you in advance for your help.

Logfile of HijackThis v1.97.7
Scan saved at 1:13:54 PM, on 6/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMg... Read more

A:ARGH! res://zqnfr.dll/index.html

Read other 6 answers
RELEVANCY SCORE 86.8

First off, I note that this problem is being discussed in another thread, but I didn't want to 'hijack' that person's thread, so I apologise in advance if I've committed a tech guy sin, and please merge if appropriate.

I have tried a million things to get rid of this crap: spybot, hijackthis, ad-aware, cwshredder, but to no avail. From everything I've read thus far, it looks like the only thing to do is post my hijackthis log and get some genius' help so PLEASE HELP!

I've also been getting this pop-up page when I do searches in google, as well as a left-hand side bar thingy (?).: http://search-777.com/sec.php?qq=fdfs
Not sure if this is related to the stupid coolwwwsearch crap or some other wonderful disaster all to itself.

Logfile of HijackThis v1.97.7
Scan saved at 12:39:40 PM, on 6/13/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM32\DRIVERS\DCFSSVC.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\MSOFFICE.EXE
C:\PROGRAM FILES... Read more

A:res://mshp.dll/index.html#37049

Hi chim, welcome to TSG.

You did the right thing starting your own thread. I know you're waiting for a genuis to help here, but you got me instead.
Okay, close your browser and check the following entry in HJT, click Fix and then REBOOT.

O4 - HKLM\..\RunServices: [SystemSAS] system32.exe
After rebooting, find and delete this file:

system32.exe
Now, I don't see any antivirus application running or firewall.

Good idea to go here for a free online AV scan:

http://housecall.trendmicro.com/housecall/start_corp.asp
 

Read other 3 answers
RELEVANCY SCORE 86.8

Been having problems with this "res://vukhf.dll/index.html#841298243" thing for a day or so and it has taken over my browser homepage. I've fixed with HJT and the problems come back. I've scanned with Spybot and CWShredder for what it's worth, and they each find no problems. At one time it changed from vukhf.dll to mshp.dll, but that doesn't happen anymore.
Here's the hijackthis log and whatnot
Logfile of HijackThis v1.97.7
Scan saved at 10:55:43 AM, on 6/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\netzu.exe
C:\WINDOWS\System32\wuamgrd32.exe
C:\WINDOWS\System32\SSTray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
C:\WINDOWS\system32\javaff32.exe
C:\Program Files\Winamp\winamp.exe
C:\Documents and Settings\ain soph aur\Desktop\HijackThis.exe
C:\P... Read more

A:res://vukhf.dll/index.html#841298243 help!

Read other 10 answers
RELEVANCY SCORE 86.8

Here is my hijackthis log.

Logfile of HijackThis v1.97.7
Scan saved at 12:39:57 AM, on 6/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\mfcby.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\apifj32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pqgad.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://pqgad.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://pqgad.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pqgad.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://pqgad.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pqgad.dll/sp.html#37049
O2 - BHO: (no name) - {EAF849B0-D48F-42B8-2286-38E91D0091E5} - C:\WINDOWS\apifj32.dll
O3 -... Read more

A:res://pqgad.dll/index.html#37049

Looks similar to the mshp.dll problems and my very own ortlx.dll problem which I just posted about an hour ago.... is there something new spreading around we don't know about?
 

Read other 2 answers
RELEVANCY SCORE 86.8

Help! I've been following threads on how to fix this problem. I get the "res://mshp.dll/index.html#37049" URL whenever I open the browser. I've been trying suggestions posted here to no avail. it keeps coming back. hijackthis.log is attached.

i tried everything,ad aware 6, Spybot - Search & Destroy, HijackThis, CWShredder.

how do i get rid of that

thanks
 

A:res://mshp.dll/index.html#37049

Welcome to TSG!!

Double click on Hijackthis.exe then click on the "Scan" button, then click on "Save Log".

Copy and paste it back here and someone will be happy to review it.

Don't make any changes until instructed to do so.
 

Read other 1 answers
RELEVANCY SCORE 86.8

This showed up on my INTERNET explorer home page and is affecting a web site i am about to post
how do i blow this away:
res://mshp.dll/index.html#37049
 

A:res://mshp.dll/index.html#37049

Download CWShredder from http://209.133.47.200/~merijn/files/CWShredder.exe & run it. Select the fix button & it will get rid of everything related to CoolWebSearch. Close ALL other programs including IE before running CWShredder.
 

Read other 1 answers
RELEVANCY SCORE 86.8

Hi Tech Support:

I noticed that people are encountering this problem now, I have just got it on my computer as well. I ran HiJackThis and here is what I got.

I will wait for your message before continuing with deleting.

Thank you for your support, you are doing a fantastic job!

Craig

Logfile of HijackThis v1.97.7
Scan saved at 6:31:05 PM, on 2/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\System32\dvdupgrd.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\CKM\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://mshp.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://mshp.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#37049
R1 - HKLM\Sof... Read more

A:HELP:::::: rev://mshp.dll/index.html#37049

Read other 11 answers
RELEVANCY SCORE 86.8

Hello everyone:

I did a search for "res://mshp.dll/index.html#10213" which is keep resetting my homepage to this URL. But I didn't find any info on it. I must have downloaded some other junk as well because I keep getting pop-ups too. Please let me know how I can remove this. Also I wanted to donate some money but when I clicked on the VISA donation banner, a message came up and didn't let me make a donation.

Thank you,

ARS01760
 

A:res://mshp.dll/index.html#10213

Read other 16 answers
RELEVANCY SCORE 86.8

Hi,

First of all, I'm new to this forum and I'm looking for some help please!

I need some help about this problem, I get the "res://mshp.dll/index.html#37049" as my homepage whenever I open the browser. Is there someone to guide me through, solving this problem?

And I have another problem and I don't know if it has to do with the above problem or not. Each time before turning off the PC or logging off, I'm receiving this popup menu error:

--------------------------------------------------------------------------------------------------

End Program - rundll32.exe

This Program is not responding.

Tho return to Windows and check the status of the program click cancel. If you choose to end the program immediately you will lose any unsaved data. To end the program now, click end now.

---------------------------------------------------------------------------------------------------

Thanks in advance!
 

A:need to get rid of:res://mshp.dll/index.html#37049

Read other 7 answers
RELEVANCY SCORE 86.8

I think my home computer has a bug. We use Yahoo as our home page. Recently whenever we do a search in Yahoo another search program pops up in front and then it changes our home page from www.yahoo.com to

res://mshp.dll/index.html#37049

This is getting to be a pain in the butt....how do I correct the problem.
Thanks
 

A:res://mshp.dll/index.html#37049

Read other 10 answers
RELEVANCY SCORE 86.8

When I type www.localhost, where is index.html

I have asked this question on other news groups even Microsoft. Why is this such a hard question to answere. I have installed Apachi web server on my PC but when I type www.localhost into a web browser, I find myself looking at a difrent file.

HELP

A:When I type www.localhost, where is index.html

Hi Otuatail,

Try typing just localhost and leave out the www. That may work. If not, you can try typing 127.0.0.1

Hope that helps!
Snarks

Read other 9 answers
RELEVANCY SCORE 86.8

"Home Search Assistent" strikes again! Here is my latest Hijackthis log:

Logfile of HijackThis v1.97.7
Scan saved at 11:37:11 PM, on 6/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wapisvsu.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\ntez.exe
C:\WINDOWS\system32\ipow32.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\unzipped\hijackthis\H... Read more

A:res://ccvbc.dll/index.html#96676

Read other 7 answers
RELEVANCY SCORE 86.8

Have a website barendh.com with a simple structure, starting with index.html.
Whenever I update some files this works fine, but when I try to replace index.html still the old version is shown, even when I just rename it to index.htmlBAK.
I suppose it's some sort of refreshing thing, but I can't seem to find an option in Firefox 11 nor in IE.

A:Website: index.html does not register

press F5 in internet explorer. fixed?

Read other 1 answers
RELEVANCY SCORE 86.8

Hello,
I found some information pertaining to my problem but it's not an exact match. There was a post from Tordis that was very similar. Anyway... The internet explorer on the problem machine will not take me to the internet. Everytime I start IE it comes up with the Microsoft Office window stating that it is installing components. It will supposedly finish installing components and then redirect to the location above and there will also be a small pop-up window open. I have uninstalled and reinstalled office and Internet Explorer. I'm fairly sure that there are no virus' on the PC. (symantec corporate edition) So I'm not sure where to go from here. I ran the CwShredder and it only found and fixed CWS.Winshow. Below is the Hack This log from the machine after Shredder was run. Would appreciate any help possible. Thanks.

Logfile of HijackThis v1.97.7
Scan saved at 7:12:33 AM, on 7/6/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Analog Dev... Read more

A:res://tcqwc.dll/index.html#37049

Found the answers I needed from flrman and dvk. Thanks for the help!!
 

Read other 2 answers
RELEVANCY SCORE 86.8

First off...I just want to thank everyone that contributes to this site, you all have help me sort out most of my problems. As indicated I was hijacked by CoolWebSearch. After checking this site at work, especially the thread from e-liam dated Feb 15, 2004, I forwarded the fixes, including CoolWebShredder, Highjack this, Spybot search and destroy, Windows updater and ad-aware. I was fortunate that my e-mail operated as I was unable to get my internet explorer operating as it was freezing upon opening on CoolWebsearch. Anyhow...thanks again.

I have attached a hijackthis.log, if anyone cares to take a look and possibly give me any further pointers.

Thanks in advance!

Logfile of HijackThis v1.97.7
Scan saved at 9:02:26 PM, on 17/05/04
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.... Read more

A:res://mshp.dll/index.html#37049 ....I have done what I can!!!!

Read other 6 answers
RELEVANCY SCORE 86.8

How do I fix this? I ran Hijack This and this is what it says...

Logfile of HijackThis v1.97.7
Scan saved at 10:42:14 PM, on 4/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\config\services.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\hijackthis1977[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://mshp.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsof... Read more

A:res://mshp.dll/index.html#37049

Read other 11 answers
RELEVANCY SCORE 86.8

res://mshp.dll/index.html#37049.............How do I get rid of this. I do not know how to get rid of this. I'm kinda new at computers.
 

A:res://mshp.dll/index.html#37049

Here's a how to article:

http://www.pchell.com/support/lookfor.shtml

Steve
 

Read other 1 answers
RELEVANCY SCORE 86.8

I have seen many people with the same situation, but I have yet to find a solution. My home page resets to res://dmkc.dll/index.html#96678, and my internet is running slow. I have scanned my computer with Norton Antivirus, Spybot, Ad-aware, and aboutbuster, but have had no luck. I have downloaded Hijackthis, but I have not run it yet. I am using windows XP, and have a 3.0 cable connection. If anyone can help I would greatly appreciate the time. Thanks!
 

A:Help???...res://dmekc.dll/index.html#96678

Read other 8 answers
RELEVANCY SCORE 86.8

Hi; I think our computer's been hijacked -- can't get rid of this annoying homepage -- res://mshp.dll/index.html#37049

I don't have any experience with all this (even having trouble figuring out the posting procedure here!).

I'm running XP, but beyond that, I don't know what info you'd need to help me. Can anybody help me clean this parasite out? Step by step, please! Thanks! David
 

A:can't get rid of res://mshp.dll/index.html#37049

Read other 13 answers
RELEVANCY SCORE 86.8

Every time I launch my web browser I am receiving this address(res://mshp.dll/index.html#37049) in my address bar and I cannot get ride of it. I have seen similair threads relating to this. How do I get rid of it?
 

A:res://mshp.dll/index.html#37049

Logfile of HijackThis v1.97.7
Scan saved at 1:47:40 PM, on 6/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\System32\ltmsg.exe
C:\WINDOWS\System32\tp4serv.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\System32\RunDll32.exe
C:\progra~1\c4ebreg\c4ebreg.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\atlxv32.exe
C:\Program Files\Zone Labs\Integrity Client\iclient.exe
C:\Program Files\Common Files\efax\Dllcmd32.exe
C:\WINDOWS\System32\drivers\trcboot.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE
c:\sdwork\issimsvc.exe
C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Dantz\Retrospect\Launcher.exe
C:\WINDOWS\System32\svchost.exe
C:\epricer\tomcat\bin\jk_nt_service.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\epricer\jdk\bin\java.exe
C:\WINDOWS\System32\drivers\ldlcserv.exe
C:\Program Files\c4ebreg\isamsmt.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\Program Files\AT&T Network Client\NetClient.exe
C:\PKWARE\PKZIPW\pkzipw.exe
C:\PKT... Read more

Read other 2 answers