Spybot S&D found smitfraud and it keeps coming back. I had some vundo viruses so I ran vundofix.
Here's the log file for that:
VundoFix V6.4.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Scan started at 1:44:11 PM 5/23/2007
Listing files found while scanning....
C:\WINDOWS\system32\bxannril.ini
C:\WINDOWS\system32\csdsgkxx.dll
C:\WINDOWS\system32\lirnnaxb.dll
C:\WINDOWS\system32\mpqss.bak1
C:\WINDOWS\system32\mpqss.bak2
C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\nyrhoxbs.ini
C:\WINDOWS\system32\sbxohryn.dll
C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\uabvvxlm.dll
C:\WINDOWS\system32\vtusssq.dll
C:\WINDOWS\system32\xxkgsdsc.ini
C:\WINDOWS\system32\yltkxyhr.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\bxannril.ini
C:\WINDOWS\system32\bxannril.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\csdsgkxx.dll
C:\WINDOWS\system32\csdsgkxx.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\lirnnaxb.dll
C:\WINDOWS\system32\lirnnaxb.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\mpqss.bak1
C:\WINDOWS\system32\mpqss.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\mpqss.bak2
C:\WINDOWS\system32\mpqss.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\mpqss.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\nyrhoxbs.ini
C:\WINDOWS\system32\nyrhoxbs.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\sbxohryn.dll
C:\WINDOWS\system32\sbxohryn.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\ssqpm.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\vtusssq.dll
C:\WINDOWS\system32\vtusssq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\xxkgsdsc.ini
C:\WINDOWS\system32\xxkgsdsc.ini Has been deleted!
Performing Repairs to the registry.
Done!
I ran HiJackThis after to double check.
I got this:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:36:15 PM, on 5/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Ron\Desktop\HiJackThis_v2.exe
O2 - BHO: (no name) - {E5E4D79D-2E6F-4156-82AA-F9101C3B6760} - C:\WINDOWS\system32\ssqpm.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: NTRU Hybrid TSS v2.0.7 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.7\bin\tcsd_win32.exe
--
End of file - 1151 bytes
I still got a virus pop up last night but I closed down. I am not getting the virus pop up this morning (I use PC-cillin) but I ran virus scan this morning.
The log I got was this:
PC-cillin 2003 Log List
"Time","Event","Source Type","Virus Name","File Name","First Action","Second Action"
"00:48","Real-time Scan","File","TROJ_VUNDO.ACK","C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP174\A0039878.dll","Clean Fail","Quarantine Success"
"08:56","Manual Scan","File","TROJ_VUNDO.ACW","C:\VundoFix Backups\csdsgkxx.dll.bad","Clean Fail","Quarantine Success"
Doesn't seem to leave the system, any suggestions?
Here's the log file for that:
VundoFix V6.4.1
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Scan started at 1:44:11 PM 5/23/2007
Listing files found while scanning....
C:\WINDOWS\system32\bxannril.ini
C:\WINDOWS\system32\csdsgkxx.dll
C:\WINDOWS\system32\lirnnaxb.dll
C:\WINDOWS\system32\mpqss.bak1
C:\WINDOWS\system32\mpqss.bak2
C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\nyrhoxbs.ini
C:\WINDOWS\system32\sbxohryn.dll
C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\uabvvxlm.dll
C:\WINDOWS\system32\vtusssq.dll
C:\WINDOWS\system32\xxkgsdsc.ini
C:\WINDOWS\system32\yltkxyhr.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\bxannril.ini
C:\WINDOWS\system32\bxannril.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\csdsgkxx.dll
C:\WINDOWS\system32\csdsgkxx.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\lirnnaxb.dll
C:\WINDOWS\system32\lirnnaxb.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\mpqss.bak1
C:\WINDOWS\system32\mpqss.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\mpqss.bak2
C:\WINDOWS\system32\mpqss.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\mpqss.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\nyrhoxbs.ini
C:\WINDOWS\system32\nyrhoxbs.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\sbxohryn.dll
C:\WINDOWS\system32\sbxohryn.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\ssqpm.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\vtusssq.dll
C:\WINDOWS\system32\vtusssq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\xxkgsdsc.ini
C:\WINDOWS\system32\xxkgsdsc.ini Has been deleted!
Performing Repairs to the registry.
Done!
I ran HiJackThis after to double check.
I got this:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:36:15 PM, on 5/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Ron\Desktop\HiJackThis_v2.exe
O2 - BHO: (no name) - {E5E4D79D-2E6F-4156-82AA-F9101C3B6760} - C:\WINDOWS\system32\ssqpm.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: NTRU Hybrid TSS v2.0.7 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.7\bin\tcsd_win32.exe
--
End of file - 1151 bytes
I still got a virus pop up last night but I closed down. I am not getting the virus pop up this morning (I use PC-cillin) but I ran virus scan this morning.
The log I got was this:
PC-cillin 2003 Log List
"Time","Event","Source Type","Virus Name","File Name","First Action","Second Action"
"00:48","Real-time Scan","File","TROJ_VUNDO.ACK","C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP174\A0039878.dll","Clean Fail","Quarantine Success"
"08:56","Manual Scan","File","TROJ_VUNDO.ACW","C:\VundoFix Backups\csdsgkxx.dll.bad","Clean Fail","Quarantine Success"
Doesn't seem to leave the system, any suggestions?