This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need Help Removing Hijacker, Please

94 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Deny the changes to the registry but make a note of what the program or file is that is trying.

Then go to add/remove programs and remove anyhting you did not install.

Then scan with hijackthis and put a check beside these lines and choose FIX.

O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe

Then delete this folder

C:\PROGRA~1\Toolbar<<
Then post a new log as well as the names of the files/programs trying to alter your registry.

I will flag an expert to take a look. Hang in there.
As I was about to start the process of cleaning, I notivced that I have a WinTools directory in my c:\programs\common files directory. Even a "I" know this is not a good thing B)

I'll reboot again and make notes of what is attempting to take root.

Here is the HJT log in normal boot mode and after the denials:

Logfile of HijackThis v1.98.2
Scan saved at 2:26:42 PM, on 9/18/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\jetsuite\jsdaemon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINNT\Explorer.EXE
C:\Program Files\PopNot\PopNot.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\System32\wuauclt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\GetRight\getright.exe
C:\jetsuite\JETSTAT.EXE
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Webshots\WebshotsTray.exe
c:\jetsuite\JSFMAN.EXE
C:\Program Files\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {14B61A3A-3F46-9DCA-7FC9-CB56B4D6FA68} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [PopNot] C:\Program Files\PopNot\PopNot.exe auto
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [REGSHAVE] C:\Progra~1\REGSHAVE\REGSHAVE.EXE /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PNSetup] C:\Program Files\PopNot\PNSetup.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Lavasoft Adwatch] C:\Program Files\Lavasoft Ad-Aware\Ad-watch.exe /min
O4 - HKCU\..\Run: [Eaat] C:\Documents and Settings\Administrator.GATEWAY\Application Data\sust.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DllCmd32.lnk = C:\jetsuite\DLLCMD32.EXE
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: HP LaserJet 3100 Status.lnk = C:\jetsuite\JETSTAT.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: Allow Site's Pop-&ups - file://C:\Program Files\PopNot\trustsite.script
O8 - Extra context menu item: Always &Kill this Pop-up - file://C:\Program Files\PopNot\blocksite.script
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O12 - Plugin for .ply: C:\Program Files\Internet Explorer\PLUGINS\NPDRILL.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} -
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} -
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} -
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} (McAfee.com Download+Installer Class) -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…83/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} -
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} -
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{355655F2-DB0D-4570-A6DD-80C5FBDF25E5}: NameServer = 24.153.22.195
O17 - HKLM\System\CS1\Services\Tcpip\..\{355655F2-DB0D-4570-A6DD-80C5FBDF25E5}: NameServer = 24.153.22.195
O17 - HKLM\System\CS2\Services\Tcpip\..\{355655F2-DB0D-4570-A6DD-80C5FBDF25E5}: NameServer = 24.153.22.195
I attempted to follow your directions but neither of the entries was there. The only thing I managed to delete was the remnent directory of WinAd.

Also, none of my protection software indicated any problems on reboot.

I am VERY confused as things seem to be appearing and disappearing.

Here is my most current HJT log in normal mode:

Logfile of HijackThis v1.98.2
Scan saved at 2:50:10 PM, on 9/18/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\jetsuite\jsdaemon.exe
C:\WINNT\Explorer.EXE
C:\Program Files\PopNot\PopNot.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\GetRight\getright.exe
C:\jetsuite\JETSTAT.EXE
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Webshots\WebshotsTray.exe
c:\jetsuite\JSFMAN.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINNT\System32\msiexec.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\knlwrap.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe
C:\Program Files\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {14B61A3A-3F46-9DCA-7FC9-CB56B4D6FA68} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [PopNot] C:\Program Files\PopNot\PopNot.exe auto
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [REGSHAVE] C:\Progra~1\REGSHAVE\REGSHAVE.EXE /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PNSetup] C:\Program Files\PopNot\PNSetup.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Lavasoft Adwatch] C:\Program Files\Lavasoft Ad-Aware\Ad-watch.exe /min
O4 - HKCU\..\Run: [Eaat] C:\Documents and Settings\Administrator.GATEWAY\Application Data\sust.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DllCmd32.lnk = C:\jetsuite\DLLCMD32.EXE
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: HP LaserJet 3100 Status.lnk = C:\jetsuite\JETSTAT.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: Allow Site's Pop-&ups - file://C:\Program Files\PopNot\trustsite.script
O8 - Extra context menu item: Always &Kill this Pop-up - file://C:\Program Files\PopNot\blocksite.script
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O12 - Plugin for .ply: C:\Program Files\Internet Explorer\PLUGINS\NPDRILL.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} -
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} -
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} -
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} (McAfee.com Download+Installer Class) -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…83/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} -
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} -
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{355655F2-DB0D-4570-A6DD-80C5FBDF25E5}: NameServer = 24.153.22.195
O17 - HKLM\System\CS1\Services\Tcpip\..\{355655F2-DB0D-4570-A6DD-80C5FBDF25E5}: NameServer = 24.153.22.195
O17 - HKLM\System\CS2\Services\Tcpip\..\{355655F2-DB0D-4570-A6DD-80C5FBDF25E5}: NameServer = 24.153.22.195
Ok from what I am being told Spybot Teatimer is the issue.

Open SpyBot> on its tool-bar > Mode switch to advanced > tools >resident and uncheck tea timer. close SpyBot. in the windows tray (clock area) if tea timer is still visible right click it and chose exit.

Then scan with hijackthis and put a chek beside these lines and choose FIX.

O2 - BHO: (no name) - {14B61A3A-3F46-9DCA-7FC9-CB56B4D6FA68} - (no file)

O4 - HKCU\..\Run: [Eaat] C:\Documents and Settings\Administrator.GATEWAY\Application Data\sust.exe

O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} -
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} -
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} -
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} -

Then delete this file

C:\Documents and Settings\Administrator.GATEWAY\Application Data\sust.exe

Please empty all you temp folders. DO NOT DELETE THE FOLDERS ONLY THE CONTENTS.
C:\WINDOWS\Temp\ CONTENTS
C:\Temp\ CONTENTS
C:\Documents and Settings\username\Local Settings\Temp\ CONTENTS
Also delete your Temporary Internet Files Tools>InternetOptions delete all cookies, files as well as offline files. Also make sure that you clean out your recycle bin.

Then reboot and post a new log.
I followed your directions and it appeasr that TeaTimer was the programme with the rogue entries. However I cannot post my HJT log because now, I have no Internet connection. All the mechanics are there and working but I keep getting a DNSserver error message. Do you know of any connection (no pun inteneded) between the two? :wall:
Please disable all protection software except AV and Firewall as it often prevents any fixes from working. That includes SpybotSD, Tea Timer, WinPatrol, Spyware Guard, etc Then please post the log in normal mode SIggyx is now away and I will be taking over the thread. Good Luck!
It is my husband's computer which is having the problems. I am communicating to the board via my computer. After following Siggy's last instructions regarding Spybot TeaTimer, my husband's computer can no longer connect to the internet by any browser. I have checked the connections with my ISP tech and husband's computer is connected mechanically, just can't use the browser. It gives a 'cannot find server or DNS error' message. I have tried IE and Mozilla with same result. The ISP tech sugested that with all the tinkering in the registry, something fatal might have happened. He suggested reinstall IE and if that doesn't work - reinstall O/S :o My question to Siggy was: did he know of any connection between changes in SpyBot settings and loss of internet access. Obviously, without internet access, I can't post the HJT log. :wall:
Ok calicocat, I have reviewed the entire thread and know what has been done. From here I would like to take things slowly, step by step to get things back and the infection gone. The only possibility from Siggyx instructions regarding TeaTimer that could have killed the internet connection is the infection had bound itself into the Administrator account through that sust.exe file. I think what has happened is it has caused a problem in your LSP stack which is fixable fairly easily. The techsupport people at your ISP don't deal with this type of thing. Their recommendations are always to reinstall if the internet options are set properly and this rarely is necessary. Removing the O2 and the O16's would not have done anything to compromise the internet connection. What TeaTimer was showing was a list of items it had blocked. What you did had nothing to do with the function of the Registry or any other fatal actions. I believe this is one of the very newest of the infections we are seeing and they take a lot of work to get rid of, but are eventually gone with no trace. I suggest you avoid IE from here on out, and use Mozilla only on your husband's computer, because often opening IE reinstalls the entire infection. What you can do at this point is if you have a floppy disk or CD Rom that you can save to, you can download the tools you need like HJT on your computer, save it to CD or floppy, move to your husband's computer and run the tools. Save the Log files to the floppy or CD and take them to your computer to post back into this thread. More work for you but will get the information I need to give you instructions to finally get rid of the offending slimeware. If you can, copy an HJT log to floppy or CD and then post it here in this thread to find out what is going on now. Good Luck!
DUH! You can tell I am totally frazzled by this situation - I never even THOUGHT of a CD.

WAY too inside the box thinking :)



Here is the current HJT log from my husband's computer, booted in normal mode:

Logfile of HijackThis v1.98.2
Scan saved at 8:22:23 AM, on 9/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\jetsuite\jsdaemon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINNT\Explorer.EXE
C:\Program Files\PopNot\PopNot.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\GetRight\getright.exe
C:\jetsuite\JETSTAT.EXE
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Webshots\WebshotsTray.exe
C:\WINNT\System32\wuauclt.exe
c:\jetsuite\JSFMAN.EXE
C:\Program Files\HiJackThis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [PopNot] C:\Program Files\PopNot\PopNot.exe auto
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [REGSHAVE] C:\Progra~1\REGSHAVE\REGSHAVE.EXE /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PNSetup] C:\Program Files\PopNot\PNSetup.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\Run: [Lavasoft Adwatch] C:\Program Files\Lavasoft Ad-Aware\Ad-watch.exe /min
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DllCmd32.lnk = C:\jetsuite\DLLCMD32.EXE
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: HP LaserJet 3100 Status.lnk = C:\jetsuite\JETSTAT.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: Allow Site's Pop-&ups - file://C:\Program Files\PopNot\trustsite.script
O8 - Extra context menu item: Always &Kill this Pop-up - file://C:\Program Files\PopNot\blocksite.script
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} (McAfee.com Download+Installer Class) -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…83/mcinsctl.cab
Hi calicocat,

It is our job to do the thinking about how to get those log files when a person is having a terrible time with computer problems. I would like you to do a few things to get more information, for me. I have noticed a few entries which may be spyware as the spyware often takes the name of legitimate programs. One question did your husband upgrade from Windows 2000 to XP?

Step#1
Please tell me how long he has been running the following programs? I also would like you to check the properties of each please by right-click and choose properties. The information on the version tab is what to look for and then report back to me

C:\Program Files\PopNot\PopNot.exe
C:\Program Files\Webshots\WebshotsTray.exe
c:\jetsuite\JSFMAN.EXE


Step#2

I believe that the following entry is bad, It states that this file is from Symantec and yet is in an Office directory. Please check the properties of it as well and report back to me.
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE


Step#3

Please End Task using CTRL-ALT-DEL on the following processes:

C:\Program Files\PopNot\PopNot.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE


Step#4

Ad-Watch is another program like Spyware Guard etc that will prevent the fix from working, could you please disable it from starting and monitoring until we are finished.


Step#5

Now let's see if there is a hidden dll file that is reinstalling the spyware and malware

1. Please download DllCompare
( The Screenshot will show you how the program will look when it starts.)

2. Start the Program with its default settings and put a check mark in the include subdirectories. Click the Run Locate.com and wait until the scan says complete.

3. Click the Compare button to start the next process.

4. Files in the upper portion have been verified to "exist", Files in the bottom section were not able to be accessed. Very few files should be listed in the bottom section when the Compare scan is complete.

5. Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan screenshot.

6. This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files) screenshot

7. Click the Make a Log of what was found button, and post the log here in this thread using Add Reply to receive further instructions.


Step#6

I have noticed one thing that probably caused you to lose internet access. The O17's in the log file have disappeared and were registry entries for you ISP. We need to add the entries back for your DNS server. If you are using a router we may have to reset the router. First go to Start>All Programs> Accessories > Command Prompt. Click on Command Prompt and when the window opens, type ipconfig /all beside the entry likely: C:\Documents and Settings\UserName>
Please post what appears in the window following that command.

Open Network Connections and right click on your connection to the internet, copy what is in properties of the connection, and post so we can see what changes to make.


Please scan again with HJT and Post a new log here in this thread

Good Luck
Hi dgosling While completing Step 5 (Dllcompare) I received the following message: C:\docume~1\admini~1.gat\desktop\locate.com C:\winnt\system32\autoexec.nt The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose 'Close" to terminate the application. Should I 'close' or 'ignore' ?
hi calicocat can you tell me exactly which step you were at within 5 and what form did the error message take - a popup prompt? or a message within DllCompare? Please try to describe exactly what happened
OK… I completed part 2 of step 5. The programme window contains the note: 'Administrator Account Detected' Then a popup window came up entitled "16-bit MS-DOS subsystem". This window is overlaying the original programme window. The two messages which I posted are within the popup window. I am offered two choices: 'close' and 'ignore'. I have done neither and the programme is still open on my husband's computer.
Just click ignore and keep clicking ignore until something new happens. I have contacted the developer and hope to hear from him soon. Please continue with the steps if you can't run DllCompare
Here are the reults of your instructions: One question did your husband upgrade from Windows 2000 to XP? Yes. His computer was originally running Win2000. When we purchased mine, we installed XP Pro on mine and upgraded his to XP Pro as well. No specific reason, just thought is might make sense to have both computers running same O/S. I will admit that there has been some confusion when trying to do maintenance as there appears to be an amalgam of the 2 O/S’s on his computer. Step#1 Please tell me how long he has been running the following programs? I also would like you to check the properties of each please by right-click and choose properties. The information on the version tab is what to look for and then report back to me C:\Program Files\PopNot\PopNot.exe Running about 3 years Version: - 2.1 This programme is no longer supported or revised. I purchased it about 3 years ago and it has travelled through a couple of O/S reinstalls and upgrades. I think it still works very well in as much as it is an excellent popup blocker. C:\Program Files\Webshots\WebshotsTray.exe Running about 3 years Version: 1.3.0.3613 Build date: 11/18/2001 c:\jetsuite\JSFMAN.EXE Running over 4 years. This is software which came with our HP3100. It has been a pain from the beginning. When we upgraded to XP, there was a driver missing. HP wants to sell the CD with the driver on it and I am not paying for something I believe I should receive free, based on the warranty statement. It’s tedious and likely slows the computer down but we can’t print without it. Version: 2.0 Build 179.5 Step#2 I believe that the following entry is bad, It states that this file is from Symantec and yet is in an Office directory. Please check the properties of it as well and report back to me. C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE Type of file: application Description: Symantec Fax Starter Edition Port Launcher File Version: 9.0.98.0105 Internal name: OLFSNT40.DLL Step#3 Please End Task using CTRL-ALT-DEL on the following processes: C:\Program Files\PopNot\PopNot.exe C:\Program Files\Webshots\WebshotsTray.exe C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE Done Step#4 Ad-Watch is another program like Spyware Guard etc that will prevent the fix from working, could you please disable it from starting and monitoring until we are finished Done Step#5 Now let's see if there is a hidden dll file that is reinstalling the spyware and malware 1. Please download DllCompare ( The Screenshot will show you how the program will look when it starts.) … 7. Click the Make a Log of what was found button, and post the log here in this thread using Add Reply to receive further instructions. I clicked ‘ignore’ once and then was able to continue to Step 5- part 3 (compare). The programme indicated that the scan was completed and that I should click ‘compare’ to continue, which I did. Nothing happened, the message about completed scan did not change, so I closed the programme and continued as below. Step#6 I have noticed one thing that probably caused you to lose internet access. The O17's in the log file have disappeared and were registry entries for you ISP. Which explains why Mozilla is not working, either, I assume. We need to add the entries back for your DNS server. If you are using a router we may have to reset the router. First go to Start>All Programs> Accessories > Command Prompt. Click on Command Prompt and when the window opens, type ipconfig /all beside the entry likely: C:\Documents and Settings\UserName> We are using a router as we share an internet connection. Please post what appears in the window following that command. Windows IP configuration: Host name Derry Primary Dns suffix Node Type Unknown IP routing enabled no WINS Proxy enabled no Ethernet Adapter Local Area Connection: Connection-Specific DNS suffix Description Winbond W89C940-Based Ethernet adapter (generic) Physical Address 00-40-95-04-4F-85 Dhcp enabled no IP Address 192.168.1.12 Subnet mask 255.255.255.0 Default Gateway 192.168.1.1. NetBIOS over Tcpip Disabled Open Network Connections and right click on your connection to the internet, copy what is in properties of the connection, and post so we can see what changes to make. Internet Connection Properties Just the general message about what it is and allows you to do. Status is enabled Under “Settings”, all services are unchecked.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI