Logfile of HijackThis v1.99.1
Scan saved at 18:40:13, on 01.09.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
N:\WINDOWS\System32\smss.exe
N:\WINDOWS\system32\csrss.exe
N:\WINDOWS\system32\winlogon.exe
N:\WINDOWS\system32\services.exe
N:\WINDOWS\system32\lsass.exe
N:\WINDOWS\system32\svchost.exe
N:\WINDOWS\system32\svchost.exe
N:\WINDOWS\system32\svchost.exe
N:\Programme\AntiVir PersonalEdition Classic\avguard.exe
N:\WINDOWS\system32\netdde.exe
N:\Programme\AntiVir PersonalEdition Classic\sched.exe
N:\WINDOWS\system32\dllhost.exe
N:\WINDOWS\system32\nvsvc32.exe
N:\Programme\Belkin\F5D7051\WLService.exe
N:\Programme\Belkin\F5D7051\WLanCfgG.exe
N:\Programme\Stardock\Object Desktop\ThemeManager\wbload.exe
N:\WINDOWS\Explorer.EXE
N:\Programme\Java\jre1.5.0_01\bin\jusched.exe
N:\WINDOWS\system32\regsvr32.exe
N:\Programme\Java\jre1.5.0_01\bin\jucheck.exe
N:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
N:\Programme\SecCenter\scprot4.exe
N:\WINDOWS\system32\ctfmon.exe
N:\Programme\ICQ6\ICQ.exe
N:\PROGRA~1\MOZILL~1\FIREFOX.EXE
N:\Programme\Spybot - Search & Destroy\TeaTimer.exe
N:\Programme\Windows Media Player\wmplayer.exe
N:\Programme\Spybot - Search & Destroy\SpybotSD.exe
N:\Programme\WinRAR\WinRAR.exe
N:\DOKUME~1\Gamer\LOKALE~1\Temp\Rar$EX00.469\Hijac kThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - N:\PROGRA~1\ICQTOO~1\toolbaru.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE N:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE N:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] N:\Programme\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [runner1] N:\WINDOWS\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661 AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [avp] N:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe N:\WINDOWS\system32\drvgum.dll,startup
O4 - HKLM\..\Run: [itqrejgl] rundll32.exe "N:\Programme\itqrejgl\mjmtabwp.dll",Init
O4 - HKLM\..\Run: [wnuzkfot] regsvr32 /u "N:\Dokumente und Einstellungen\All Users\Anwendungsdaten\wnuzkfot.dll"
O4 - HKLM\..\Run: [avgnt] "N:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SC2] N:\Programme\SecCenter\scprot4.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\RunOnce: [SpybotDeletingA9158] command /c del "N:\Programme\Ultimate Cleaner\com\ucsecuredelete.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7921] cmd /c del "N:\Programme\Ultimate Cleaner\com\ucsecuredelete.dll_tobedeleted_old"
O4 - HKCU\..\Run: [CTFMON.EXE] N:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "N:\Programme\ICQ6\ICQ.exe" silent
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Oubp] "N:\WINDOWS\WNSXS~1\ati2evxx.exe" -vt yazb
O4 - HKCU\..\Run: [SpybotSD TeaTimer] N:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB5943] command /c del "N:\Programme\Ultimate Cleaner\com\ucsecuredelete.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6715] cmd /c del "N:\Programme\Ultimate Cleaner\com\ucsecuredelete.dll_tobedeleted_old"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - N:\Programme\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - N:\Programme\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - N:\Programme\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - N:\Programme\ICQ6\ICQ.exe
O11 - Options group: [INTERNATIONAL] International*
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - N:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - N:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Belkin High-Speed Mode Wireless G USB Driver (Belkin High-Speed Mode Wireless G USB Network Adapter Service) - Unknown owner - N:\Programme\Belkin\F5D7051\WLService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - N:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - N:\Programme\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - N:\Programme\Spyware Doctor\swdsvc.exe