Hi everyone ,i'm new to the site and not very good with computers ,
my avg had picked up alot of viruses which include trogan horse generic and dropper here is my hijack file if anyone could help me get rid of these little buggers for good id really aprichiatte it thanks xxx
ps i have no idea what im looking at when looking at hijack!
Logfile of HijackThis v1.99.1
Scan saved at 03:27:17, on 10/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec
Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec
Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-
LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common
Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch
Buttons\QlbCtrl.exe
C:\Program Files\WIDCOMM\Bluetooth
Software\bin\btwdins.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common
Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Symantec
Shared\ccApp.exe
C:\Program Files\Norton Save and
Restore\Agent\VProSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Common
Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Plate\X_Plate.exe
C:\Program Files\Common
Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Avant Browser\avant.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Metaboli Player\GPlayer.exe
C:\Documents and Settings\Bee\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection
Wizard,ShellNext = http://www.talktalk.co.uk/
O2 - BHO: superiorads browser optimizer - {09e81817
-1ec1-ccce-15aa-160e22167725} - C:\WINDOWS\system32
\gyxajbludscsoqa.dll
O2 - BHO: (no name) - {11A7A749-0381-4AE2-940B-
27EC006D6006} - C:\WINDOWS\system32\opnnonOG.dll
(file missing)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-
D42A53123C75} - C:\Program Files\Common
Files\Symantec Shared\coShared\Browser\1.0
\NppBho.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter -
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program
Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {514A5C49-0C7D-42c3-A71B-
38864A269B7A} - C:\WINDOWS\system32\stdhwpxp.dll
(file missing)
O2 - BHO: mysidesearch search enhancer - {74d92b5b-
fad2-d31b-22a7-04ee4200aec4} - C:\WINDOWS\system32
\cmmtufrnydtld.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-
B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: {13003dd9-ec29-88da-9844-7b60679b7cf7} -
{7fc7b976-06b7-4489-ad88-92ce9dd30031} -
C:\WINDOWS\system32\bnhcjg.dll
O2 - BHO: dcads - {9d8dfb91-4b37-56f9-c372-
e77d701ca906} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-
4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8
\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-
4d91-8333-CF10577473F7} - c:\program
files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-
7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\3.0.1225.9868
\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-
C946-4A17-ADC1-64B5B4FF55D0} - C:\Program
Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {D3C165B9-B1BB-4B38-A6C4-
359F747FFF82} - C:\WINDOWS\system32\adsmsex.dll
O2 - BHO: (no name) - {EDD08973-D6CC-4A9E-A0B2-
88CDF221B1C4} - C:\WINDOWS\system32\cbXrPIcd.dll
(file missing)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-
4738-B738-FBEE9C7B26DF} - C:\Program Files\Common
Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} - c:\program
files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946
-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows
Live Toolbar\msntb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC
-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8
\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ehTray]
C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32
\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32
\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32
\igfxpers.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property
Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program
Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program
Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program
Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-
Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett
-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard]
C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder]
C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton
Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1
\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program
Files\Common
Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common
Files\InstallShield\UpdateService\isuspm.exe" -
scheduler
O4 - HKLM\..\Run: [{e7280662-dc55-8b59-f76d-
2a3079e032d9}] C:\WINDOWS\System32\Rundll32.exe
"C:\WINDOWS\system32\gyxajbludscsoqa.dll" DllStart
O4 - HKLM\..\Run: [ExploreUpdSched]
C:\WINDOWS\system32\qcntttdm.exe DWrvgXX
O4 - HKLM\..\Run: [514b7fc2] rundll32.exe
"C:\WINDOWS\system32\vjqvwmxy.dll",b
O4 - HKLM\..\Run: [Symantec PIF AlertEng]
"C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}
\PIFSvc.exe" /a /m "C:\Program Files\Common
Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-
2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8
\avgtray.exe
O4 - HKLM\..\Run: [BM52784c5e] Rundll32.exe
"C:\WINDOWS\system32\cbxfieal.dll",s
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program
Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2
\RegistryBooster.exe /S
O4 - HKCU\..\RunOnce: [DependencyCheck] Performed
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32
\qcntttdm.exe
O4 - Startup: Plate - Auto Update.lnk = C:\Program
Files\Plate\Plate.exe
O8 - Extra context menu item: &Windows Live Search -
res://C:\Program Files\Windows Live
Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft
Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11
\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background
tab - res://C:\Program Files\Windows Live
Toolbar\Components\en-gb\msntabres.dll.mui/229?
a7d12cb83c144d22afec1f387012eaa7
O8 - Extra context menu item: Open in new foreground
tab - res://C:\Program Files\Windows Live
Toolbar\Components\en-gb\msntabres.dll.mui/230?
a7d12cb83c144d22afec1f387012eaa7
O8 - Extra context menu item: Send to &Bluetooth
Device... - C:\Program Files\WIDCOMM\Bluetooth
Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-
AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-
B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11
\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-
C863-46ef-9331-5C8D4460577F} - C:\Program
Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 -
{CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program
Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-
82b7-f2ba38496583} - %windir%\Network
Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%
\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-
BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF:
START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?
TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=presario&pf=la
ptop
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696}
(Bebo Uploader Control) -
http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC}
(Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUpl
oader.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}
(ExentInf Class) -
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0}
(VideoEgg ActiveX Loader) -
http://update.videoegg.com/Install/Windows/Initial/V
ideoEggPublisher.exe
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-
47BC-8C80-C34B9B80B32B} - C:\Program
Files\Logitech\Desktop Messenger\8876480
\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-
A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8
\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: geBqQGvW - geBqQGvW.dll (file
missing)
O20 - Winlogon Notify: igfxcui -
C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: opnnonOG - opnnonOG.dll (file
missing)
O20 - Winlogon Notify: WgaLogon -
C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-
95D7-94D524869DB5} - C:\WINDOWS\system32
\WPDShServiceObj.dll
O23 - Service: AddFiltr - Hewlett-Packard
Development Company, L.P. - C:\Program
Files\Hewlett-Packard\HP Quick Launch
Buttons\AddFiltr.exe
O23 - Service: Automatic LiveUpdate Scheduler -
Symantec Corporation - C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) -
AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8
\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG
Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8
\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) -
Broadcom Corporation. - C:\Program
Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) -
Unknown owner - C:\Program Files\Common
Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
(file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr)
- Unknown owner - C:\Program Files\Common
Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
(file missing)
O23 - Service: Symantec Lic NetConnect service
(CLTNetCnService) - Unknown owner - C:\Program
Files\Common Files\Symantec Shared\ccSvcHst.exe" /h
ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec
Corporation - C:\Program Files\Common Files\Symantec
Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) -
Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard
Development Company, L.P. - C:\Program
Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager
(IDriverT) - Macrovision Corporation - C:\Program
Files\Common Files\InstallShield\Driver\11\Intel 32
\IDriverT.exe
O23 - Service: Symantec IS Password Validation
(ISPwdSvc) - Symantec Corporation - C:\Program
Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc
Labeling Service (LightScribeService) - Hewlett-
Packard Company - C:\Program Files\Common
Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation -
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex
(LiveUpdate Notice Ex) - Unknown owner - C:\Program
Files\Common Files\Symantec Shared\ccSvcHst.exe" /h
ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown
owner - C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}
\PIFSvc.exe" /m "C:\Program Files\Common
Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-
2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program
Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech
Inc. - C:\Program Files\Common
Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. -
C:\Program Files\Common
Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Norton Save and Restore - Symantec
Corporation - C:\Program Files\Norton Save and
Restore\Agent\VProSvc.exe
O23 - Service: Pml Driver HPZ12 - HP -
C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner -
C:\Program Files\Common Files\Symantec Shared\CCPD-
LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore)
- Symantec Corporation - C:\Program Files\Common
Files\Symantec Shared\AppCore\AppSvc32.exe