hello i'm having an issue with my homepage this morning when i logged on to my computer my homepage had changed to res://sjxdf.dll/index.html
#96676. i used hijack this to identify the problem files and even deleated them through hijackthis and through the registry but they keep comming back. can any one tell me how to rid my self of this trojan/
Logfile of HijackThis v1.97.7
Scan saved at 2:30:13 PM, on 6/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\System32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\TGTSoft\StyleXP\Styl
eXPService
.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\COMMON~1\AOL\A
CS\AOLacsd
.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTEC
T.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\ieqr32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SYSTEM32\3cmlin
k.exe
C:\PROGRA~1\ZONELA~1\ZONEA
L~1\zlclie
nt.exe
C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
C:\WINDOWS\SYSTEM32\3cshtd
wn.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\WINDOWS\SYSTEM32\3cmlin
k.exe
C:\WINDOWS\System32\rundll
32.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\A
OLSPY~1\AO
LSP Scheduler.exe
C:\WINDOWS\system32\sdkkg3
2.exe
C:\Program Files\TGTSoft\StyleXP\Styl
eXP.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.e
xe
C:\WINDOWS\System32\rundll
32.exe
C:\PROGRA~1\INCRED~1\bin\I
MApp.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\jsean\Desktop\Hij
ackThis.ex
e
C:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\sjxdf.dll
/sp.html#9
6676
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://sjxdf.dll/index.html
#96676
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page = res://sjxdf.dll/index.html
#96676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\sjxdf.dll
/sp.html#9
6676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = res://sjxdf.dll/index.html
#96676
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = res://C:\WINDOWS\sjxdf.dll
/sp.html#9
6676
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {1960401C-1EDC-C453-499B-B
9D8506F210
E} - C:\WINDOWS\system32\iecc.d
ll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Progr
Start Free Trial