Hi Polonus - here I am.
Here is the fix I propose with some questions at the end:
I see a couple different things going on in your log, Frankie. This may take more than one go but lets start here.
First, zip and passsword protect a copy of C:\Program Files\21cn\VGO\VGOIEBHO.dll and C:\WINDOWS\SYSTEM32\rdihost.dll and email them to virus@avast.com. Include the password in the body of the email with a link to this thread.
EDIT: DavidR suggested an easier method to upload C:\Program Files\21cn\VGO\VGOIEBHO.dll and C:\WINDOWS\SYSTEM32\rdihost.dll to avast!:
They can be added to the User Files (File, Add) section of the avast chest (before deletion of the original) where it can do no harm and send it from there (select the file, right click, email to Alwil Software).
Then open Folder Options in the Control Panel and click the View tab. Place a check mark next to
Show Hidden Files and Folders
And remove the check mark (if present) from
Hide extensions for known file types
Hide protected operating system files
Then click OK.
Next, open HijackThis again and click the button labled Do A System Scan Only. When it finishes place a check mark next to these lines and click the button labled Fix Checked
O2 - BHO: Trellian BHO Impl - {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: ToolbarBrowser - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O4 - HKLM..\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot
O4 - HKLM..\Run: [Windows System Configuration] C:\WINDOWS\SYSCFG16.EXE
O4 - HKLM..\Run: [Windows DLL Loader] C:\WINDOWS\SYSCFG16.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O21 - SSODL: rdihost - {DF756174-9280-4C6E-9BE2-74F3DDAEFFA9} - rdihost.dll (file missing)
Close HijackThis, boot into safe mode, and delete these files (if present)
C:\WINDOWS\SYSCFG16.EXE
C:\WINDOWS\SYSTEM32\rdihost.dll
Then post a fresh HijackThis log.
As Polonus said Sweet IM is very “iffy”. Have you installed it and do you wish to keep it?
Also, have you installed VGO?