Yes Guard.tmp is in my systems folder
Logfile of HijackThis v1.98.2
Scan saved at 12:45:41 AM, on 12/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Nokturnal\Desktop\VX2Finder.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co…b?1097456561584
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
Warning! This utility will find legitimate files in addition to
malware.
Do not remove anything unless you are sure you know what you're
doing.
——- System Files in System32 Directory ——-
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
12/15/2004 12:33 AM 222,555 srftpub.dll
12/15/2004 12:32 AM 226,292 e2202cfmgf2a2.dll
12/13/2004 03:50 PM dllcache
12/13/2004 03:48 PM 226,292 Hgperman.dll
12/13/2004 03:48 PM 222,555 r4r60e9seh.dll
12/13/2004 01:18 PM 225,583 wgnsta.dll
12/12/2004 07:36 PM 225,583 j6j60g1se6.dll
12/12/2004 07:35 PM 223,039 o266lcjs1fo6.dll
12/12/2004 06:06 PM 225,046 o6nslg5716.dll
12/12/2004 05:57 AM 223,120 mmsign32.dll
12/12/2004 05:26 AM 223,078 sne.dll
12/12/2004 04:00 AM 223,834 o6ns0g57e6.dll
12/12/2004 03:19 AM 223,381 fp0o03d3e.dll
12/06/2004 11:06 PM 223,078 kddmac.dll
12/05/2004 08:06 AM 225,244 nzmsdba.dll
12/05/2004 01:18 AM 225,653 cmcdll.dll
12/05/2004 01:00 AM 225,244 kmdsl.dll
12/04/2004 06:47 PM 224,570 jBvart.dll
12/04/2004 06:24 PM 222,891 sarobj.dll
12/04/2004 06:21 PM 225,559 igetcplc.dll
12/04/2004 07:56 AM 224,976 fZultrep.dll
12/03/2004 10:50 PM 224,804 irr6l59s1.dll
12/03/2004 10:34 PM 223,825 slrrun.dll
12/03/2004 09:27 PM 225,842 mliavi32.dll
12/03/2004 08:29 PM 222,952 csusapi.dll
12/03/2004 12:35 AM 223,561 wgigest.dll
12/02/2004 10:24 PM 224,098 dawsock.dll
12/02/2004 08:33 PM 224,098 dgrgui.dll
12/02/2004 08:21 PM 223,232 kcdycc.dll
12/02/2004 08:20 PM 223,232 irrsl5971.dll
12/02/2004 05:35 PM 223,232 irl8l53u1.dll
12/02/2004 05:33 PM 224,354 f22mlcf11f2.dll
10/09/2004 09:53 PM Microsoft
31 File(s) 6,950,803 bytes
2 Dir(s) 32,851,308,544 bytes free
——- Hidden Files in System32 Directory ——-
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
12/13/2004 03:50 PM dllcache
10/09/2004 06:15 PM 488 logonui.exe.manifest
10/09/2004 06:15 PM 488 WindowsLogon.manifest
10/09/2004 06:14 PM 749 nwc.cpl.manifest
10/09/2004 06:14 PM 749 sapi.cpl.manifest
10/09/2004 06:14 PM 749 ncpa.cpl.manifest
10/09/2004 06:14 PM 749 cdplayer.exe.manifest
10/09/2004 06:14 PM 749 wuaucpl.cpl.manifest
11/29/2003 10:11 AM 2,045 whlpda32e.dll
8 File(s) 6,766 bytes
1 Dir(s) 32,851,304,448 bytes free
———- Files Named "Guard" ————-
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
12/15/2004 12:35 AM 222,555 guard.tmp
1 File(s) 222,555 bytes
0 Dir(s) 32,851,300,352 bytes free
——— Temp Files in System32 Directory ——–
Volume in drive C has no label.
Volume Serial Number is 1C8B-07BE
Directory of C:\WINDOWS\System32
12/15/2004 12:35 AM 222,555 guard.tmp
07/16/2003 03:25 PM 2,577 CONFIG.TMP
2 File(s) 225,132 bytes
0 Dir(s) 32,851,300,352 bytes free
—————- User Agent ————
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Interne
t Settings\User Agent\Post Platform]
"{712564B5-8817-46A3-9E29-BA19CD2A41CB}"=""
———— Keys Under Notify ————
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\Unimodem]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\r4r60e9seh.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
—————- Xfind Results —————–
————– Locate.com Results —————
Log for VX2.BetterInternet File Finder (ALL)
Files Found—
Additional Files—
Keys Under Notify—
crypt32chain
cryptnet
cscdll
ScCertProp
Schedule
sclgntfy
SensLogn
termsrv
Unimodem
wlballoon
Guardian Key— is called:
Guardian Key— :
User Agent String—
{712564B5-8817-46A3-9E29-BA19CD2A41CB}