Need help removing paypopup popups. They just won't leave.

Discussion in 'Malware Help (A Specialist Will Reply)' started by portsport, Nov 17, 2006.

  1. portsport

    portsport Private E-2

    Hi,
    I am have a bit of trouble getting rid of paypopup.com popups. Is there any help for me? I went through the read this first steps and still have an issue. Any help would great.
    Thanks
    Mike
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. portsport

    portsport Private E-2

    Here are the scans you asked for. Hope you can make something of them.
    Thanks again
    Mike
     

    Attached Files:

  4. portsport

    portsport Private E-2

    Seems I am unable to attach any others than the one above.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run GetRunKey again and attach a new log! You had some malware that stopped it from running the first time and ShowNew fixed some of the problems.

    You should be able to attach the other logs. Just remember that only three logs can be attach in a single message. If you have problems again, just click refresh. Sometimes dumping your cache will help too.


    What is the below folder on your Desktop? Names like this are always suspect!!!
    C:\Documents and Settings\Owner\Desktop\scans)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    Java 2 Runtime Environment, SE v1.4.2

    Delete the below files too!
    C:\WINDOWS\SYSC00.EXE
    C:\WINDOWS\gcewo.dll

    Now also attach a new log from ShowNew.
     
  7. portsport

    portsport Private E-2

    OK,
    deleted the two files, redid all scans and will try again. Scans) folder is where i have the reports so I can find em again. (I'm not real smart)
    Thanks
    Mike
     

    Attached Files:

  8. portsport

    portsport Private E-2

    Here are the other two reports.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
    O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\Owner\LOCALS~1\Temp\20061118111227_mcappins.exe /v=3 /cleanup
    O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Owner\LOCALS~1\Temp\20061118111224_mcinfo.exe /insfin
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\winupdates <--- the whole folder:
    C:\WINDOWS\keyboard1.dat

    Now run Ccleaner.

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. portsport

    portsport Private E-2

    Seems like things are working much better now. I have attached the reports you asked for. You guys are the best ever. Thanks a bunch.
    Mike
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You missed one item that is not necessary and is a frequent cause of popups:

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    You should fix this!

    Other than that, your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  12. portsport

    portsport Private E-2

    Seems I can not remove this item. it keeps showing up in my hjt log. Is there an alt way to remove it?
    Mike
     
  13. portsport

    portsport Private E-2

    NM tried a couple more times and it is now gone. toggled the restor pint and all is good now. You are awsome. Hope you have a great thanksgiving!
    Mike
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hope you enjoy a malware free ThanksGiving too!

    If you run into anymore problems with Windows Messenger, use the below to remove it.

    Disable/Remove Windows Messenger
     
  15. portsport

    portsport Private E-2

    Well as far as popups go I am good. But seems now I am unable to purchase anything online. Goes to a page that states "IE cannot display the webpage". Did we turn something on or off that might have caused this or is this something new? Sorry to bother you again.
    Thanks
    Mike
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No this is not from anything we did. Perhaps you are having new problems! Did you try another browser like FireFox. Does that message only occur on certain websites?

    Attach new logs from HJT and ShowNew.
     
  17. portsport

    portsport Private E-2

    Here are the new HJT log and shownew log
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer my two questions!

    You should uninstall the below rogue tool which I did not notice last time.
    NetSpy Protector (remove only)

    I see no other problems in your logs!
     
  19. portsport

    portsport Private E-2

    Ok,
    Sorry it took so long to get back to you (seems life always gets in the way of the thing you need to do). I have never used any browser other than IE. I downloaded Firefox, installed it and tried to run it but it will not let me connect. When I am in IE I can go to most all websites main page but cannot get much further. Such as Ebay I can look at items but I cannot save them in myebay. I can,t even get to my ebay. Also when I go to look at banking info it will not let me even have the oppertunity to try and log on. Happily I have a laptop I can do everything with. But it would be nice to have this one working the way it should again. I do appriciate all the help I have received so far.
    Thanks again!
    Mike

    PS
    Still no popups 8)~
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why you are having a problem with this unless you are not configuring something required for you system to connect. How do you connect to the internet (dial-up, cable, DSL)?

    This does not sound like malware. When you use this problem PC to connect here at Majorgeeks, does it work OK.
     
  21. portsport

    portsport Private E-2

    Seems I have so problems with your website so far. i did forget to tell you we connect via cable. I made all the security settings the same as on my laptop and still no change.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware problem! You have a configuration issue someplace that is not correct or you have a software problem. You may need to check to make sure you are not blocking cookies or anything else related to the websites you are trying to access. Shutdown security software, firewalls etc and see what happens. Also reset your Hosts file using the below:

    download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    If necessary, try adding the problem sites to your Trusted Zone just to see if that helps. You may have something improperly in your Security Zones or with ActiveX.

    I recommend that you post a message in the Software Forum and provide specific details or your problems since this is not an issue for this forum. You can access Majorgeeks and probably many other sites without a problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds