Logfile of HijackThis v1.99.1
Scan saved at 14:55:54, on 20.10.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C

rogrammeVideoCompressionCodecisamonitor.exe
C

rogrammeVideoCompressionCodecpmsngr.exe
C

ROGRA~1mcafee.comagentmcagent.exe
C

rogrammeVideoCompressionCodecisamini.exe
C

rogrammeVideoCompressionCodecpmmon.exe
C

rogrammeMcAfee.comVSOmcvsshld.exe
C

rogrammeMcAfee.comVSOoasclnt.exe
C

ROGRA~1McAfeeSPAMKI~1MskAgent.exe
c:progra~1mcafee.comvsomcvsescn.exe
C

ROGRA~1McAfee.comPERSON~1MpfTray.exe
C

rogrammeJavajre1.5.0binjusched.exe
C:WINDOWSSOUNDMAN.EXE
C

rogrammeCreativeSBAudigy2ZSSurround MixerCTSysVol.exe
C:WINDOWSsystem32CTHELPER.EXE
C

rogrammeCreativeSBAudigy2ZSDVDAudioCTDVDDet.EXE
C

ROGRA~1McAfee.comPERSON~1MpfAgent.exe
C

rogrammeCreativeMediaSourceGOCTCMSGo.exe
C

ROGRA~1WALLPA~1WALLPA~1.EXE
C

rogrammeCreativeMediaSourceRemoteControlRCMan.EXE
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32CTSvcCDA.EXE
c:programmemcafee.comagentmcdetect.exe
c

ROGRA~1mcafee.comvsomcshield.exe
c

ROGRA~1mcafee.comagentmctskshd.exe
C

ROGRA~1McAfee.comPERSON~1MPFSERVICE.exe
C

ROGRA~1McAfeeSPAMKI~1MSKSrvr.exe
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSsystem32MsPMSPSv.exe
C

rogrammeT-OnlineT-Online_Software_5Basis-SoftwareBasis2kernel.exe
C

rogrammeT-OnlineT-Online_Software_5Basis-SoftwareBasis2sc_watch.exe
C

ROGRA~1T-OnlineT-ONLI~1BASIS-~1Basis2PROFIL~1.EXE
C:WINDOWSsystem32wuauclt.exe
C

rogrammeXfirexfire.exe
C

rogrammeOperaOpera.exe
C

rogrammeSkypePhoneSkype.exe
C

rogrammeWinRARWinRAR.exe
C

OKUME~1BesitzerLOKALE~1TempRar$EX00.094HijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://google.icq.com/search/search_frame.php
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
ICQ.com Search Results
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C

rogrammeICQToolbartoolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C

rogrammeAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:programmemcafeespamkillermcapfbho.dll
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d9b138c6a53b} - C

rogrammeVideoCompressionCodecisaddon.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C

rogrammeGemeinsame DateienMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O3 - Toolbar: (no name) - {8aed5df3-6e0b-4930-b1a5-f8aa8d757497} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:progra~1mcafee.comvsomcvsshl.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C

rogrammeICQToolbartoolbaru.dll
O4 - HKLM..Run: [MCAgentExe] c

ROGRA~1mcafee.comagentmcagent.exe
O4 - HKLM..Run: [MCUpdateExe] c

ROGRA~1mcafee.comagentmcupdate.exe
O4 - HKLM..Run: [VSOCheckTask] "C

ROGRA~1McAfee.comVSOmcmnhdlr.exe" /checktask
O4 - HKLM..Run: [VirusScan Online] C

rogrammeMcAfee.comVSOmcvsshld.exe
O4 - HKLM..Run: [OASClnt] C

rogrammeMcAfee.comVSOoasclnt.exe
O4 - HKLM..Run: [MSKAGENTEXE] C

ROGRA~1McAfeeSPAMKI~1MskAgent.exe
O4 - HKLM..Run: [MSKDetectorExe] C

ROGRA~1McAfeeSPAMKI~1MSKDetct.exe /startup
O4 - HKLM..Run: [MPFExe] C

ROGRA~1McAfee.comPERSON~1MpfTray.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 - HKLM..Run: [SunJavaUpdateSched] C

rogrammeJavajre1.5.0binjusched.exe
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [SBDrvDet] C

rogrammeCreativeSB Drive DetSBDrvDet.exe /r
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 - HKLM..Run: [CTSysVol] C

rogrammeCreativeSBAudigy2ZSSurround MixerCTSysVol.exe /r
O4 - HKLM..Run: [CTRegRun] C:WINDOWSCTRegRun.EXE
O4 - HKLM..Run: [CTHelper] CTHELPER.EXE
O4 - HKLM..Run: [CTDVDDET] C

rogrammeCreativeSBAudigy2ZSDVDAudioCTDVDDet.EXE
O4 - HKLM..Run: [CleanUp] C

ROGRA~1McAfee.comSharedmcappins.exe /v=3 /cleanup
O4 - HKLM..RunOnce: [vsoupd.dll] rundll32.exe advpack.dll,RegisterOCX c

ROGRA~1mcafee.comvsovsoupd.dll
O4 - HKCU..Run: [Creative MediaSource Go] C

rogrammeCreativeMediaSourceGOCTCMSGo.exe /SCB
O4 - HKCU..Run: [Wallpaper4U] C

ROGRA~1WALLPA~1WALLPA~1.EXE -w
O4 - HKCU..Run: [SB Audigy 2 Startup Menu] C

rogrammeCreativeSBAudigy2ZSProgramStartup MenuChkColor.EXE
O4 - HKCU..Run: [RemoteCenter] C

rogrammeCreativeMediaSourceRemoteControlRCMan.EXE
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C

rogrammeICQToolbartoolbaru.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C

rogrammeJavajre1.5.0binnpjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C

rogrammeJavajre1.5.0binnpjpi150.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:programmemcafeespamkillermcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:programmemcafeespamkillermcapfbho.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C

rogrammeICQLiteICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C

rogrammeICQLiteICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C

rogrammeMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C

rogrammeMessengermsmsgs.exe
O17 - HKLMSystemCCSServicesTcpip..{7C2D8939-769D-49DE-AC49-425A8B415A88}: NameServer = 217.237.150.115 217.237.148.49
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C

ROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C

ROGRA~1MSNMES~1MSGRAP~1.DLL
O21 - SSODL: contrabandists - {dfa61db1-388e-4c87-8d56-540fa229bcb4} - C:WINDOWSsystem32dpfwu.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32CTSvcCDA.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:programmemcafee.comagentmcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c

ROGRA~1mcafee.comvsomcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c

ROGRA~1mcafee.comagentmctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C

ROGRA~1McAfee.comAgentmcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C

ROGRA~1McAfee.comPERSON~1MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C

ROGRA~1McAfeeSPAMKI~1MSKSrvr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C

rogrammeTuneUp Utilities 2006WinStylerThemeSvc.exe