Hi Experts
i can't get rid of the virus Trojan.12.BM, it gives my a runtime error each time i go on the Internet Explorer and AVG tells me i have this virus, i turned off system restore, scan with avg in safe mode, executed ad-aware to no avail. it's kind of urgent, here's my hijack log:
Logfile of HijackThis v1.99.0
Scan saved at 08:46:25 AM, on 01/17/05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgamsv
r.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgupsv
c.exe
C:\Program Files\RealVNC\WinVNC\WinVN
C.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtr
ay.exe
C:\WINDOWS\System32\hkcmd.
exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgemc.
exe
C:\PROGRA~1\AQUATI~1\AQ3HE
L~1.EXE
C:\WINDOWS\Xhrmy.exe
C:\PROGRA~1\ezula\mmod.exe
C:\PROGRA~1\Web Offer\wo.exe
C:\WINDOWS\system32\prutjc
t.exe
C:\Program Files\TSX\TSX-Net\netserve
.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\WINDOWS\system32\prutjc
t.exe
C:\Hijack\HijackThis.exe
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://GLOBAL.ACER.COM/ R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/ O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F
247DB0C6FD
6} - C:\Program Files\E2G\IeBHOs.dll
O2 - BHO: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-9
0E36537C25
2} - C:\Program Files\QuickSearch\QuickSea
rchBar3_28
.dll
O2 - BHO: (no name) - {CD9A8CFE-A579-9B45-A8EA-6
0F9FA9F4AA
4} - C:\WINDOWS\system32\iovigw
vu.dll
O3 - Toolbar: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-9
0E36537C25
2} - C:\Program Files\QuickSearch\QuickSea
rchBar3_28
.dll
O3 - Toolbar: TopText - {55910916-8B4E-4C1E-9253-C
CE296EA71E
B} - C:\PROGRA~1\eZula\eabh.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVN
C.exe" -servicehelper
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE
~1\avgemc.
exe
O4 - HKLM\..\Run: [AQ3HelperStartUp] C:\PROGRA~1\AQUATI~1\AQ3HE
L~1.EXE /partner AQ3
O4 - HKLM\..\Run: [xhrmy] C:\WINDOWS\Xhrmy.exe
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [prutjct] C:\WINDOWS\system32\prutjc
t.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: TSX Networking.lnk = C:\Program Files\TSX\TSX-Net\netserve
.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.d
ll
O14 - IERESET.INF: START_PAGE_URL=
http://GLOBAL.ACER.COM/ O16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094145396000 O16 - DPF: {A3009861-330C-4E10-822B-3
9D16EC8829
D} (CRAVOnline Object) -
http://www.ravantivirus.com/scan/ravonline.cab O17 - HKLM\System\CCS\Services\T
cpip\..\{5
45BAC12-F2
05-407B-AF
54-4D469B6
04DD2}: NameServer = 206.47.244.134,207.236.176
.27
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE
~1\avgamsv
r.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE
~1\avgupsv
c.exe
O23 - Service: Miscrosoft Updates Service 4 - Unknown - C:\WINDOWS\system32\msupd4
.exe
O23 - Service: VNC Server - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\WinVN
C.exe