error loading c:\progra~1\intern~2\inetkw.dll
Logfile of HijackThis v1.98.0
Scan saved at 2:58:53 PM, on 7/2/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
D:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\documents and settings\brian\local settings\temp\Jg.exe
C:\WINNT\System32\IEHost.exe
C:\Program Files\WhenUSearch\Search.exe
C:\Program Files\Common Files\Dpi\dpi.exe
C:\PROGRA~1\INTERN~2\inetmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\System32\ntmzuum.exe
C:\PROGRA~1\INTERN~2\inetsvc.exe
C:\WINNT\System32\ERFCTRSP.exe
C:\WINNT\System32\rundll32.exe
C:\WINNT\System32\jpeetlib.exe
D:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\WINNT\System32\Stv49R6.exe
C:\WINNT\System32\SunCI.exe
C:\Documents and Settings\brian\My Documents\HijackThis.exe
C:\WINNT\System32\rundll32.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
file://C:\WINNT\System32\SearchBar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.master-search.com/search.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.couldnotfind.com/search_page.html?&account_id=144440
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.master-search.com/search.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.master-search.com/search.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.master-search.com/search.php
R3 - Default URLSearchHook is missing
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,
O2 - BHO: TwaintecObj Class - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINNT\twaintec.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll
O2 - BHO: (no name) - {EE8EB588-0867-E940-55E6-D63514572A97} - C:\WINNT\system32\crbn32.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\ISTbar\istbar.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Jg] C:\documents and settings\brian\local settings\temp\Jg.exe
O4 - HKLM\..\Run: [Bakra] C:\WINNT\System32\IEHost.exe
O4 - HKLM\..\Run: [55MKLEH2SWZ#7K] C:\WINNT\System32\Cvx1j.exe
O4 - HKLM\..\Run: [WhenUSearch] C:\Program Files\WhenUSearch\Search.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe
O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe
O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\brian\LOCALS~1\Temp\app5.tmp
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [garjdggyj] C:\WINNT\System32\ntmzuum.exe
O4 - HKLM\..\Run: [ERFCTRSP] C:\WINNT\System32\ERFCTRSP.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.EXE 1
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - HKCU\..\Run: [LBopRVGFl] jpeetlib.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = D:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: Sidesearch - {000007C6-17DF-4438-92A4-DE5537471BA3} - C:\Program Files\Lycos\Sidesearch\sidesearch1400.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\ms.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\ms.exe
O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Microsoft® JavaScript® Console - {BC78E693-B74B-49A3-B8DF-F0CE14896FAF} - (no file)
O9 - Extra 'Tools' menuitem: JavaScript Console - {BC78E693-B74B-49A3-B8DF-F0CE14896FAF} - (no file)
O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - (no file) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)
O9 - Extra button: Microsoft® JavaScript® Console - {BC78E693-B74B-49A3-B8DF-F0CE14896FAF} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: JavaScript Console - {BC78E693-B74B-49A3-B8DF-F0CE14896FAF} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {62B53F93-2E32-11D4-B0A1-004095451A77} (EagleSTAR Download Manager) -
http://208.48.227.168/tpe/modules/dmgr/downloadmanager.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) -
http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
O21 - SSODL: System - {75F3D748-E0B7-42C4-8EDB-DF0FB30EB23A} - C:\WINNT\system32\system32.dll
About:Buster Version 1.23
Removed! : C:\WINNT\abujqnwr.exe
Removed! : C:\WINNT\alchem.exe
Removed! : C:\WINNT\huvmnkh.exe
Removed! : C:\WINNT\lohuv.dat
Removed! : C:\WINNT\piyhlq.dat
Removed! : C:\WINNT\rtjdy.dat
Removed! : C:\WINNT\rtjdyw.dat
Removed! : C:\WINNT\sdkzx32.exe
Removed! : C:\WINNT\sysdx.exe
Removed! : C:\WINNT\vyn.exe
Removed! : C:\WINNT\winol32.exe
Removed! : C:\WINNT\ybyz.exe
Error Removing! : C:\WINNT\System32\atlkb.dll
Removed! : C:\WINNT\System32\crbn32.dll
Removed! : C:\WINNT\System32\crbn32.exe
Removed! : C:\WINNT\System32\jlwxi.dll
Removed! : C:\WINNT\System32\msal.exe
Error Removing! : C:\WINNT\System32\ntmzuum.exe
Removed! : C:\WINNT\System32\ntqm32.exe
Removed! : C:\WINNT\System32\odkmc.dll
Attempted Clean Of Temp folder.
Removed LEGACY___NS_Service_3 Key
Removed __NS_Service_3 Key
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!