Computing.Net > Forums > Security and Virus > Advertising Loading Window

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Click here to start participating now! Also, check out the New User Guide.

Advertising Loading Window

Reply to Message Icon

Name: Shirrlleeyy
Date: August 16, 2004 at 12:53:25 Pacific
OS: Win XP Home
CPU/Ram: Celeron/256 Ram
Comment:

Hi,

I would like to ask you, how can I remove this:

When I'm on Internet I get the paypopup Advertising_Loading_Window:

http://www.paypopup.com/loading.php?id=hostultra&pop=enter&t=0&subid=21826&tid=1092684783&ref=http://www.hostultra.com/paypop.php

...I have Ad-aware 6.0, Spybot, SpywareBlaster + CWShredder --> but they didn't find anything!

Please could you help me?

Thank you very much!

Shirley from Czech Republic

P.S.

Sorry for my English




Sponsored Link
Ads by Google

Response Number 1
Name: TheKid
Date: August 16, 2004 at 13:26:12 Pacific
Reply:

I did some "Googling" for both "paypopup" and "Advertising_Loading_Window",under both the WEB tab and GROUPS tab.

I was going to suggest a HiJackThis log,but,apparently,that doesn't always pick it up.

It might take a lil' digging on Google,as I did see some positive results.But,I suggest you do the same,as you'll probably do better/learn more researching it yourself as opposed to me trying to relay any possible solutions...unless,of course,somebody knows alil' more about it.

*PestPatrol claims to detect and remove it,(via some Google search results",you can download a trial of it and see how it does.

Good Luck.

• TheKid •


0

Response Number 2
Name: Shirrlleeyy
Date: August 17, 2004 at 09:06:50 Pacific
Reply:

I tried the PestPatrol - and everything it's OK now!

Thank you very much for the info!
:0))

Bye Shirley


0

Response Number 3
Name: TheKid
Date: August 17, 2004 at 12:26:06 Pacific
Reply:

Shirley,you're welcome...
or is it;
Surely,you're welcome...

;-)

• TheKid •


0

Response Number 4
Name: Shirrlleeyy
Date: August 18, 2004 at 23:23:55 Pacific
Reply:

:_0(

Hi Kid,

The paypopup window is back! PestPatrol didn't remove it! :_0((

Could you look on my Hijackthis log?

Thank you very much!

Logfile of HijackThis v1.97.7
Scan saved at 8:05:34, on 19.8.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\PROGRA~1\ALWILS~1\AVAST32\AvMaiSrv.exe
C:\Program Files\ConMet\ConMet.exe
C:\PROGRA~1\ALWILS~1\AVAST32\avupdsvc.exe
C:\PROGRA~1\ALWILS~1\AVAST32\avServer.exe
C:\WINDOWS\System32\WF2K.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\iexplore.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijack\HijackThis.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\TRANSLAT\WEBIE.DLL
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [AvMaiSrv] C:\PROGRA~1\ALWILS~1\AVAST32\AvMaiSrv.exe
O4 - HKLM\..\Run: [Avast32] C:\PROGRA~1\ALWILS~1\AVAST32\ASTART32.exe /keepserver
O4 - HKLM\..\Run: [ConMet] C:\Program Files\ConMet\ConMet.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinFoxV2] C:\WINDOWS\System32\WF2K.exe Initial
O4 - HKLM\..\Run: [WinFast2KLoadDefault] rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\iexplore.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Get Flash by FlashKeeper - C:\Program Files\FlashKeeper\GetFlash.htm
O8 - Extra context menu item: Stáhnout pomocí Net Transportu - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Stáhnout vše pomocí &Net Transportu - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: FlashKeeper (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: WebTran (HKLM)
O9 - Extra 'Tools' menuitem: &Nastavit překladač (HKLM)
O9 - Extra 'Tools' menuitem: Přeložit &označený text (HKLM)
O9 - Extra 'Tools' menuitem: Přeložit &stránku (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: KB KTpro Pack - https://www.mojebanka.cz/jars/kt_pro_v1101.cab
O16 - DPF: KB SH Pack - https://www.mojebanka.cz/jars/sh_pack.cab
O16 - DPF: MIB Pack - https://www.mojebanka.cz/jars/mib_pack_v1400.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E24622B-FEDD-42EF-B089-62562C2E85B5}: NameServer = 195.146.100.5 195.146.100.100



0

Response Number 5
Name: vinnybf
Date: August 19, 2004 at 12:08:46 Pacific
Reply:

I have the exact same problem and have tried numerous spware programs to remove it (ad-aware, spy bot gold, spybot S&D) and have had no luck. In spybot everytime I use it, it shows CleverIEHooker.Jeired and DSO exploit. I am getting the same paypop, yesadvertising pop ups and cant even stop them with pop up blockers. Some body PLEASE HELP ME!!!!!!!!!!!


0

Related Posts

See More



Response Number 6
Name: TheKid
Date: August 19, 2004 at 15:36:11 Pacific
Reply:

I'm far from a "HijackThis" analyst,but this one raises an eyebrow;

O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll

Google WEB search results for "NTIEHelper.dll"

HijackThis Tutorial

as does this one;

Google WEB search results for "CleverIEHooker.Jeired"

Google GROUPS search results for "CleverIEHooker.Jeired"

• TheKid •


0

Response Number 7
Name: Abnormal
Date: August 19, 2004 at 19:56:12 Pacific
Reply:

Hi Shirley,

try this
Put a check next to this, click "fix checked" and reboot.

O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\iexplore.exe

Go to safe mode
and delete iexplore.exe
located in windows
C:\WINDOWS\

Go to start, search for files or folders,
right click and delete the file.

You may need to show hidden files.

There may be something else, let us know
if it helped.


Good luck


0

Response Number 8
Name: Shirrlleeyy
Date: August 20, 2004 at 00:21:41 Pacific
Reply:

Hi Abnormal and TheKid,

I removed the NTIEHelper.dll + iexplore.exe...

I think the Paypopup Advertising Window is away...I'll inform you! :0))

Thank you very very much for your help!

Bye Shirley


0

Response Number 9
Name: Shirrlleeyy
Date: August 20, 2004 at 12:32:22 Pacific
Reply:

Everything is OK! It was the iexplore.exe file!

Thanx again!

Bye Shirley



0

Response Number 10
Name: Abnormal
Date: August 21, 2004 at 17:14:36 Pacific
Reply:

Glad it helped you, and letting us know it
worked.

Thanks for saying thanks.


0

Response Number 11
Name: Marc Segard
Date: September 8, 2004 at 11:51:12 Pacific
Reply:

Hi. I'm also getting the paypopup ad window when visiting certain websites. How can I remove it ??

(I do not have the NTIEHelper.dll + iexplore.exe files on my computer, so is it coming from some other file ?)


0

Sponsored Link
Ads by Google
Reply to Message Icon

SpywareBlaster update ava... Dialer hijack. 1 900 561...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Advertising Loading Window

Virus on Windows load www.computing.net/answers/security/virus-on-windows-load/14074.html

Cannot load windows! www.computing.net/answers/security/cannot-load-windows/20604.html

CleverIEHooker.Jeired - advertising www.computing.net/answers/security/cleveriehookerjeired-advertising/13370.html