Hi!
Some INFO:
I dont know what kinda Virus this is, but I hope that you can help me.
Some day ago i had CWS Trojan, but got reed of it when I manuel took care of it. So thats gone, atleast that is what adaware says. I still go my IE Hijacked by this res: Homepage. and its kinda enoying. AVG dont get read of it. It only says - Virus Detected. and it always the same map but with changed name. like C:\WINDOWS\syssv.exe or C:\WINDOWS\dj3d.dll. I tryed to take care of it with Hijackerthis. But it just dissipare temporary. I wait 1 min and its back!. I tryed CWR Shredder - nothing found. Spybot find a DSO Exploit that I can´t get reed of. It just disipare temporary, or the programm says that it finishied but it´s still there. I also tryed spy sweeper and couldn´t find anything.
My Hijackerthis LOG:
Logfile of HijackThis v1.97.7
Scan saved at 14:33:46, on 2004-07-05
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Grisoft\AVG7\avgamsvr.exe
C:\Program\Grisoft\AVG7\avgupsvc.exe
C:\Program\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\NORTON~1\navapw32.exe
C:\WINDOWS\winqa32.exe
C:\Program\Grisoft\AVG7\avgcc.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\Valve\Steam\Steam.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program\Internet Explorer\iexplore.exe
W:\Anti-virus\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\saqnm.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://saqnm.dll/index.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://saqnm.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\saqnm.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://saqnm.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\saqnm.dll/sp.html#96676
O2 - BHO: (no name) - {F69AA0DB-F421-F1A5-FE7E-80CCFBC0B008} - C:\WINDOWS\crqg32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Jet Detection] C:\Program\Creative\SBLive\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [NAV Agent] C:\Program\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [winqa32.exe] C:\WINDOWS\winqa32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\Program\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\Program\Symantec\LIVEUP~1\SNDMon.EXE
O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
_________________________________________________________________
I have cleared the homepages serveral times, but they just always come back. i hate this shit and begg u to help me! thx.
Yours Nemii