Whenever I open an Internet Explorer Window another one pops open as well. I have TrendMicro anti-virus and it foun 25 Trojan, 22 of them are TROJ_VUNDO, but could not clean any of them. How can I clean them? Here is the Hijack This log, thanks:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:27:33 AM, on 12/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\Program Files\lotus\notes\nslsvice
.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Intel\Wireless\Bin\E
vtEng.exe
C:\Program Files\Intel\Wireless\Bin\S
24EvMon.ex
e
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aol
tsmon.exe
C:\Program Files\TOSHIBA\ConfigFree\C
FSvcs.exe
C:\WINDOWS\system32\cisvc.
exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\DVDRAM
SV.exe
C:\WINDOWS\system32\inetsr
v\inetinfo
.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\WINDOWS\System32\svchos
t.exe
C:\PROGRA~1\POWERC~1\pcns.
exe
C:\Program Files\Intel\Wireless\Bin\R
egSrvc.exe
C:\Program Files\Java\jre1.5.0_04\bin
\java.exe
C:\WINDOWS\system32\svchos
t.exe
c:\TOSHIBA\IVP\swupdate\sw
updtmr.exe
C:\WINDOWS\system32\ThpSrv
.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs3
2.exe
C:\Program Files\TOSHIBA\TME3\Tmesrv3
1.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\iTivity\bin\rfbd.exe
C:\Program Files\Viewpoint\Common\Vie
wpointServ
ice.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll
32.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\WINDOWS\TEMP\SV429A.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\WINDOWS\system32\cidaem
on.exe
C:\WINDOWS\system32\cidaem
on.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccnt.exe
C:\WINDOWS\system32\rundll
32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
https://172.16.2.14:4343/officescan/console/clientinstall/officescannt.htmR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = medical.local:8080
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = 133.117.1.24:8001/pls/cms2
/WEB_CMSLO
GIN ; 133.117.1.197:7001/ematrix
/NiceLDAPL
ogin.jsp?j
s=yes&refr
esh=true ;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7} - C:\Program Files\Yahoo!\Common\yiesrv
c.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\System32\DLA\DL
ASHX_W.DLL
O2 - BHO: (no name) - {951e93a1-0b71-4130-93fc-3
613e2b5ce0
5} - C:\WINDOWS\system32\rurisu
go.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
E66B5AD205
D} - C:\Program Files\Google\GoogleToolbar
Notifier\3
.1.807.174
6\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
3.dll
O4 - HKLM\..\Run: [NVRotateSysTray] rundll32.exe C:\WINDOWS\system32\nvsysr
ot.dll,Ena
ble
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [yogehevuda] Rundll32.exe "C:\WINDOWS\system32\duvap
ame.dll",s
O4 - HKLM\..\Run: [004d0017] rundll32.exe "C:\WINDOWS\system32\tehom
ake.dll",b
O4 - HKLM\..\Run: [CPM037e338b] Rundll32.exe "c:\windows\system32\gidah
umu.dll",a
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKUS\S-1-5-19\..\Run: [yogehevuda] Rundll32.exe "C:\WINDOWS\system32\duvap
ame.dll",s
(User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [yogehevuda] Rundll32.exe "C:\WINDOWS\system32\duvap
ame.dll",s
(User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON
.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSC
lientMsiTr
ans\tscuin
st.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON
.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSC
lientMsiTr
ans\tscuin
st.vbs" (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.
htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.
htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_04\bin
\npjpi150_
04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_04\bin
\npjpi150_
04.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7} - C:\Program Files\Yahoo!\Common\yiesrv
c.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\system32\Shdocv
w.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0
050045C3C9
6} - C:\Program Files\Yahoo!\Messenger\Yah
ooMessenge
r.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0
050045C3C9
6} - C:\Program Files\Yahoo!\Messenger\Yah
ooMessenge
r.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: pl15w2sp.dll
O10 - Unknown file in Winsock LSP: pl15w2sp.dll
O10 - Unknown file in Winsock LSP: pl15w2sp.dll
O10 - Unknown file in Winsock LSP: pl15w2sp.dll
O10 - Unknown file in Winsock LSP: pl15w2sp.dll
O10 - Unknown file in Winsock LSP: pl15w2sp.dll
O16 - DPF: {00134F72-5284-44F7-95A8-5
2A619F7075
1} (ObjWinNTCheck Class) -
https://172.16.2.14:4343/officescan/console/ClientInstall/WinNTChk.cabO16 - DPF: {08D75BB0-D2B5-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) -
https://172.16.2.14:4343/officescan/console/ClientInstall/setupini.cabO16 - DPF: {08D75BC1-D2B5-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) -
https://172.16.2.14:4343/officescan/console/ClientInstall/setup.cabO16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-f
a1d4f56a2a
b} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsth
elper.dll
O16 - DPF: {35C3D91E-401A-4E45-88A5-F
3B32CD72DF
4} (Encrypt Class) -
https://172.16.2.14:4343/officescan/console/html/AtxEnc.cabO16 - DPF: {5EFE8CB1-D095-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) -
https://172.16.2.14:4343/officescan/console/ClientInstall/RemoveCtrl.cabO16 - DPF: {8990AFAD-D352-42AC-A72F-A
660BBF6E20
9} (OfficeScan Management Console) -
https://172.16.2.14:4343/officescan/console/html/AtxConsole.cabO16 - DPF: {9059F30F-4EB1-4BD2-9FDC-3
6F43A218F4
A} (Microsoft Terminal Services Client Control (redist)) -
https://172.16.1.5:8098/admin/tsweb/msrdp.cabO16 - DPF: {B996510E-30C9-4083-ADB9-9
FD3760D689
D} (APC InfraStruXure Manager Client Control) -
http://172.16.2.201/ApcIsxInstaller.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
060082AA75
C} (GpcContainer Class) -
https://attwm.webex.com/client/T25L10NSP41EP15-attwm/webex/ieatgpc.cabO16 - DPF: {FD0B6769-6490-4A91-AA0A-B
5AE0DC75AC
9} (Performance Viewer Activex Control) -
https://secure.logmein.com/activex/ractrl.cab?lmi=100O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-D
FE1E2340CB
1} (DownloadManager Control) -
http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.2.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = TMRIUSA.COM
O17 - HKLM\Software\..\Telephony
: DomainName = TMRIUSA.COM
O17 - HKLM\System\CCS\Services\T
cpip\..\{7
B789461-1A
32-43AE-8F
E6-DFFF68B
88DE5}: NameServer = 172.16.2.15,172.16.2.16
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = TMRIUSA.COM
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
830C7DD7F5
D} - C:\PROGRA~1\COMMON~1\Skype
\SKYPE4~1.
DLL
O18 - Protocol: x-cnote - {8D32BA61-D15B-11D4-894B-0
0000000000
0} - C:\WINDOWS\system32\hsppp.
dll
O20 - AppInit_DLLs: c:\windows\system32\jomote
wa.dll c:\windows\system32\habupa
we.dll c:\windows\system32\ketedo
ti.dll c:\windows\system32\lupayu
sa.dll c:\windows\system32\fogigu
zu.dll c:\windows\system32\lojonu
da.dll c:\windows\system32\kosuya
pu.dll c:\windows\system32\tusihe
ku.dll c:\windows\system32\yimazi
tu.dll c:\windows\system32\fuzewu
pu.dll c:\windows\system32\muguvo
ra.dll c:\windows\system32\tedako
be.dll c:\windows\system32\wehoke
pu.dll c:\windows\system32\dumeze
vi.dll c:\windows\system32\kulufe
gi.dll c:\windows\system32\yejana
ra.dll c:\windows\system32\jahamu
re.dll c:\windows\system32\telele
pu.dll C:\WINDOWS\system32\seyile
hu.dll c:\windows\system32\gidahu
mu.dll
O20 - Winlogon Notify: TosBtNP - C:\WINDOWS\SYSTEM32\TosBtN
P.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E
0B85DBDD6C
4} - c:\windows\system32\gidahu
mu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E
0B85DBDD6C
4} - c:\windows\system32\gidahu
mu.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aol
tsmon.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\C
FSvcs.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAM
SV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\E
vtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1050\Inte
l 32\IDriverT.exe
O23 - Service: iTivity Live Support Connector Direct (iTivityODConnector) - Tridia Corporation - C:\Program Files\iTivity\bin\connecto
r_od.exe
O23 - Service: iTivity Live Support Connector To IAS (iTivityODConnectToIASConn
ector) - Tridia Corporation - C:\Program Files\iTivity\bin\connecto
r_od.exe
O23 - Service: iTivity Live Support Controller (iTivityODController) - Tridia Corporation - C:\Program Files\iTivity\bin\processo
r_od.exe
O23 - Service: Lotus Notes Single Logon - IBM Corp - C:\Program Files\lotus\notes\nslsvice
.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: PowerChute Network Shutdown (PowerChuteNetShut) - APC - C:\PROGRA~1\POWERC~1\pcns.
exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\R
egSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S
24EvMon.ex
e
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\sw
updtmr.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv
.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs3
2.exe
O23 - Service: Tmesrv3 (Tmesrv) - TOSHIBA - C:\Program Files\TOSHIBA\TME3\Tmesrv3
1.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: TridiaFTP Server (TridiaFTPServer) - Tridia Corporation - C:\Program Files\iTivity\bin\ftpd.exe
O23 - Service: Tridia Screen Server (tridiavnc) - Tridia Corporation - C:\Program Files\iTivity\bin\rfbd.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\Vie
wpointServ
ice.exe
--
End of file - 13794 bytes