Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi,
I would like to ask you, how can I remove this:
When I'm on Internet I get the paypopup Advertising_Loading_Window:
http://www.paypopup.com/loading.php?id=hostultra&pop=enter&t=0&subid=21826&tid=1092684783&ref=http://www.hostultra.com/paypop.php
...I have Ad-aware 6.0, Spybot, SpywareBlaster + CWShredder --> but they didn't find anything!
Please could you help me?
Thank you very much!
Shirley from Czech Republic
P.S.
Sorry for my English

I did some "Googling" for both "paypopup" and "Advertising_Loading_Window",under both the WEB tab and GROUPS tab.
I was going to suggest a HiJackThis log,but,apparently,that doesn't always pick it up.
It might take a lil' digging on Google,as I did see some positive results.But,I suggest you do the same,as you'll probably do better/learn more researching it yourself as opposed to me trying to relay any possible solutions...unless,of course,somebody knows alil' more about it.
*PestPatrol claims to detect and remove it,(via some Google search results",you can download a trial of it and see how it does.
Good Luck.

I tried the PestPatrol - and everything it's OK now!
Thank you very much for the info!
:0))Bye Shirley

:_0(
Hi Kid,
The paypopup window is back! PestPatrol didn't remove it! :_0((
Could you look on my Hijackthis log?
Thank you very much!
Logfile of HijackThis v1.97.7
Scan saved at 8:05:34, on 19.8.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\PROGRA~1\ALWILS~1\AVAST32\AvMaiSrv.exe
C:\Program Files\ConMet\ConMet.exe
C:\PROGRA~1\ALWILS~1\AVAST32\avupdsvc.exe
C:\PROGRA~1\ALWILS~1\AVAST32\avServer.exe
C:\WINDOWS\System32\WF2K.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\iexplore.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijack\HijackThis.exeO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\TRANSLAT\WEBIE.DLL
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [AvMaiSrv] C:\PROGRA~1\ALWILS~1\AVAST32\AvMaiSrv.exe
O4 - HKLM\..\Run: [Avast32] C:\PROGRA~1\ALWILS~1\AVAST32\ASTART32.exe /keepserver
O4 - HKLM\..\Run: [ConMet] C:\Program Files\ConMet\ConMet.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinFoxV2] C:\WINDOWS\System32\WF2K.exe Initial
O4 - HKLM\..\Run: [WinFast2KLoadDefault] rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\iexplore.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Get Flash by FlashKeeper - C:\Program Files\FlashKeeper\GetFlash.htm
O8 - Extra context menu item: Stáhnout pomocí Net Transportu - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Stáhnout vše pomocí &Net Transportu - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: FlashKeeper (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: WebTran (HKLM)
O9 - Extra 'Tools' menuitem: &Nastavit překladač (HKLM)
O9 - Extra 'Tools' menuitem: Přeložit &označený text (HKLM)
O9 - Extra 'Tools' menuitem: Přeložit &stránku (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: KB KTpro Pack - https://www.mojebanka.cz/jars/kt_pro_v1101.cab
O16 - DPF: KB SH Pack - https://www.mojebanka.cz/jars/sh_pack.cab
O16 - DPF: MIB Pack - https://www.mojebanka.cz/jars/mib_pack_v1400.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E24622B-FEDD-42EF-B089-62562C2E85B5}: NameServer = 195.146.100.5 195.146.100.100

I have the exact same problem and have tried numerous spware programs to remove it (ad-aware, spy bot gold, spybot S&D) and have had no luck. In spybot everytime I use it, it shows CleverIEHooker.Jeired and DSO exploit. I am getting the same paypop, yesadvertising pop ups and cant even stop them with pop up blockers. Some body PLEASE HELP ME!!!!!!!!!!!

I'm far from a "HijackThis" analyst,but this one raises an eyebrow;
O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
Google WEB search results for "NTIEHelper.dll"
as does this one;
Google WEB search results for "CleverIEHooker.Jeired"

Hi Shirley,
try this
Put a check next to this, click "fix checked" and reboot.O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\iexplore.exe
Go to safe mode
and delete iexplore.exe
located in windows
C:\WINDOWS\Go to start, search for files or folders,
right click and delete the file.You may need to show hidden files.
There may be something else, let us know
if it helped.
Good luck

Hi Abnormal and TheKid,
I removed the NTIEHelper.dll + iexplore.exe...
I think the Paypopup Advertising Window is away...I'll inform you! :0))
Thank you very very much for your help!
Bye Shirley

Hi. I'm also getting the paypopup ad window when visiting certain websites. How can I remove it ??
(I do not have the NTIEHelper.dll + iexplore.exe files on my computer, so is it coming from some other file ?)

![]() |
SpywareBlaster update ava...
|
Dialer hijack. 1 900 561...
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |