main.txt
Deckard's System Scanner v20071014.68
Run by pauld99 on 2008-06-21 11:54:39
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 4 Restore Point(s) --
4: 2008-06-21 16:55:20 UTC - RP760 - Deckard's System Scanner Restore Point
3: 2008-06-21 12:47:55 UTC - RP759 - System Checkpoint
2: 2008-06-20 12:39:44 UTC - RP758 - Software Distribution Service 3.0
1: 2008-06-20 01:17:57 UTC - RP757 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 79% (more than 75%).
Total Physical Memory: 256 MiB (512 MiB recommended).
-- HijackThis (run as pauld99.exe) ---------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:57:00 AM, on 6/21/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\logonui.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\spoolsv.exe
C:\Windows\system32\cisvc.exe
C:\Windows\system32\inetsrv\inetinfo.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Windows\system32\mqsvc.exe
C:\Windows\system32\mqtgsvc.exe
C:\Windows\system32\cidaemon.exe
C:\Windows\system32\cidaemon.exe
C:\Windows\system32\winlogon.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\logon.scr
C:\Windows\system32\winlogon.exe
C:\Windows\system32\rdpclip.exe
C:\Windows\system32\wscntfy.exe
C:\Windows\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe
C:\Windows\system32\PDesk\PDesk.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\taskmgr.exe
C:\security\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\pauld99.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O1 - Hosts: 63.166.72.72 watchguard watchguard.performark.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: (no name) - {0E1230F8-EA50-42A9-983C-E22ABC2EED3F} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [bgsmsnd.exe] C:\Windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [HPID Scheduler] C:\Program Files\Hewlett-Packard\HP Instant Delivery\hpidschd.exe
O4 - HKLM\..\Run: [hpfsched] C:\Windows\hpfsched.exe
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\Windows\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-3649289120-1043784389-1942350698-1005\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'aaerison')
O4 - HKUS\S-1-5-21-3649289120-1043784389-1942350698-1005\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'aaerison')
O4 - HKUS\S-1-5-21-3649289120-1043784389-1942350698-1005\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe (User 'aaerison')
O4 - HKUS\S-1-5-21-3649289120-1043784389-1942350698-1005\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe (User 'aaerison')
O4 - HKUS\S-1-5-21-3649289120-1043784389-1942350698-1005\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'aaerison')
O4 - HKUS\S-1-5-21-3649289120-1043784389-1942350698-1005\..\Run: [WatchGuard Mobile VPN with SSL] "C:\Program Files\WatchGuard\WatchGuard Mobile VPN with SSL\wgsslvpnc.exe" /noconnect (User 'aaerison')
O4 - S-1-5-21-3649289120-1043784389-1942350698-1005 Startup: Windows Task Manager.lnk = C:\WINDOWS\system32\taskmgr.exe (User 'aaerison')
O4 - S-1-5-21-3649289120-1043784389-1942350698-1005 User Startup: Windows Task Manager.lnk = C:\WINDOWS\system32\taskmgr.exe (User 'aaerison')
O4 - Global Startup: Hyperion VPN Version 4.03d Rel (k9).lnk = C:\Program Files\Hyperion VPN Client\Hyperion VPN 4.03d\vpngui.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://download.windowsupdate.com
O16 - DPF: {00B28243-126B-4FFF-B346-6C3176E8296B} (Siebel Calendar) -
http://siebel-empweb.hyperion.com/callcenter/19221/applets/SiebelAx_Calendar.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1157924271515
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1157924944109
O16 - DPF: {CFAE61D0-7684-4ADE-81DA-8FB5EA342A77} (Siebel iHelp) -
http://siebel-empweb.hyperion.com/callcenter/19221/applets/SiebelAx_iHelp.cab
O16 - DPF: {DE2C7216-C882-400E-BB47-EBB90237CAD1} (Siebel High Interactivity Framework) -
http://siebel-empweb.hyperion.com/callcenter/19221/applets/SiebelAx_HI_Client.cab
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\Windows\system32\mgabg.exe
--
End of file - 8324 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 NaiAvTdi1 - c:\windows\system32\drivers\mvstdi5x.sys <Not Verified; Network Associates, Inc.; VirusScan (Enterprise, ASaP & Retail.)>
R2 cpqdfw (Diagnostics Driver) - c:\windows\system32\drivers\cpqdfw.sys
R2 cq_mem (Diagnostics Memory Driver) - c:\windows\system32\drivers\cq_mem.sys <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(TM) Operating System>
R2 cqcpu (Diagnostics CPU Driver) - c:\windows\system32\drivers\cqcpu.sys <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(TM) Operating System>
R3 tap0901 (TAP-Win32 Adapter V9) - c:\windows\system32\drivers\tap0901.sys <Not Verified; The OpenVPN Project; TAP-Win32 Virtual Network Driver>
S3 CpqDtct - c:\windows\system32\drivers\cpqdtct.sys <Not Verified; Compaq Computer Corp; Compaq Client Management Driver>
S3 iAimTV2 - c:\windows\system32\drivers\watv03nt.sys (file missing)
S3 NaiAvFilter1 - c:\windows\system32\drivers\naiavf5x.sys <Not Verified; Network Associates, Inc.; VirusScan (Enterprise, ASaP & Retail.)>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 McAfeeFramework (McAfee Framework Service) - c:\program files\network associates\common framework\frameworkservice.exe /servicestart <Not Verified; Network Associates, Inc.; McAfee Common Framework>
R2 McTaskManager (Network Associates Task Manager) - "c:\program files\network associates\virusscan\vstskmgr.exe" <Not Verified; Network Associates, Inc.; VirusScan Enterprise>
S4 hpzstatn (Printer Status Server) - c:\windows\system32\spool\drivers\w32x86\hpzstatn.exe <Not Verified; Hewlett-Packard Company; DJStatusServer Module>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&268D196D&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&268D196D&0
Service: i8042prt
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
-- Files created between 2008-05-21 and 2008-06-21 -----------------------------
2008-06-21 11:41:58 0 d------c- C:\Program Files\Trend Micro
2008-06-21 11:38:56 0 d------c- C:\security
2008-06-19 19:47:39 0 d------c- C:\Windows\Prefetch
2008-06-16 09:02:54 0 d------c- C:\Windows\ServicePackFiles
2008-06-14 10:44:06 0 d------c- C:\Program Files\WinDirStat
2008-06-13 15:17:58 0 d------c- C:\Windows\system32\scripting
2008-06-13 15:17:42 0 d------c- C:\Windows\l2schemas
2008-06-13 15:17:38 0 d------c- C:\Windows\system32\en
2008-06-13 14:53:15 0 d------c- C:\Windows\network diagnostic
2008-06-12 21:32:54 0 d--h---c- C:\Windows\$hf_mig$
2008-06-12 21:31:41 0 d------c- C:\Program Files\Microsoft Silverlight
2008-06-12 20:03:56 0 d---s--c- C:\Documents and Settings\pauld99\UserData
2008-06-11 19:30:09 664 --a----c- C:\Windows\system32\d3d9caps.dat
2008-06-11 19:25:26 0 d------c- C:\Temp
2008-05-30 07:54:43 691545 --a----c- C:\Windows\unins000.exe
2008-05-30 07:54:43 4644 --a----c- C:\Windows\unins000.dat
2008-05-26 10:14:07 0 d------c- C:\Documents and Settings\aaerison\Application Data\WatchGuard
2008-05-26 10:12:58 25344 --a----c- C:\Windows\system32\drivers\tap0901.sys <Not Verified; The OpenVPN Project; TAP-Win32 Virtual Network Driver>
2008-05-26 09:39:20 48 --a----c- C:\Documents and Settings\aaerison\hosts.cmd
-- Find3M Report ---------------------------------------------------------------
2008-06-19 10:46:51 0 d------c- C:\Program Files\Messenger
2008-06-19 10:43:16 0 d------c- C:\Program Files\Movie Maker
2008-06-19 10:40:38 0 d------c- C:\Program Files\Windows NT
2008-06-18 21:41:56 0 d--h---c- C:\Program Files\WindowsUpdate
2008-06-12 13:14:55 3260 --a----c- C:\Windows\system32\d3d8caps.dat
2008-06-11 15:50:14 0 d------c- C:\Program Files\Sony
2008-06-11 15:50:01 0 d--h---c- C:\Program Files\InstallShield Installation Information
2008-05-27 07:24:15 0 d------c- C:\Documents and Settings\pauld99\Application Data\Adobe
2008-05-26 10:12:51 0 d------c- C:\Program Files\WatchGuard
2008-05-13 15:25:03 0 d------c- C:\Documents and Settings\pauld99\Application Data\pdfMachine
2008-04-23 10:03:54 0 d------c- C:\Program Files\Common Files\InstallShield
2008-04-23 07:54:44 77696 --a----c- C:\Windows\system32\NCPLENTP.SYS
2008-04-23 07:28:41 8437035 --a----c- C:\Program Files\WatchGuard.zip
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [08/18/2004 08:00 AM]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [08/06/2004 03:50 AM]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" [10/07/2003 09:48 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"bgsmsnd.exe"="C:\Windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [07/06/2004 03:02 PM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [06/21/2006 12:14 PM]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"HPID Scheduler"="C:\Program Files\Hewlett-Packard\HP Instant Delivery\hpidschd.exe" [10/13/1999 04:51 PM]
"hpfsched"="C:\Windows\hpfsched.exe" [12/17/1999 02:22 PM]
"Matrox Powerdesk"="C:\Windows\system32\PDesk\PDesk.exe" [09/14/2004 12:13 PM]
"MyWebSearch Email Plugin"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/14/2008 05:42 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/28/2007 09:12 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Hyperion VPN Version 4.03d Rel (k9).lnk - C:\Program Files\Hyperion VPN Client\Hyperion VPN 4.03d\vpngui.exe [9/10/2006 7:34:55 PM]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [10/29/2004 9:35:34 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\Windows\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli scecli scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
-- Hosts -----------------------------------------------------------------------
63.166.72.72 watchguard watchguard.performark.com
192.168.1.25 adpdc adpdc.performark.com
192.168.1.42 adbdc adbdc.performark.com
192.168.1.10 fletch fletch.performark.com
192.168.1.62 skynet skynet.performark.com
192.168.1.14 interscan interscan.performark.com
192.168.1.50 entsqla entsqla.performark.com
192.168.1.51 entsqlb entsqlb.performark.com
192.168.1.48 entsqlc entsqlc.performark.com
192.168.1.60 entapp01 entapp01.performark.com
5 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-06-21 12:06:56 ------------