Popcash.net "dialing Out," And Something Disabling Ad Blocker...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by principessa, May 31, 2018.

  1. principessa

    principessa Private E-2

    hi there :) ...and thanks so much to the experts here for the help you provide! :)


    ...a few months ago, i had a premium trial of malware bytes which started alerting me that something called "popcash.net" was trying to dial out from my computer -

    (to check if this is still going on, i might need to purchase a premium subscription - unless someone knows of a way i can get another trial?)

    then, something started disabling my ad blocker, adblock plus, (no matter how many times i re-enabled, or re-installed), and,

    i've gotten adblock plus to stay on, BUT, the ad counts it is showing on its little icon are going CRAZY - used to be "3-4 ads blocked" on a page, now...

    i left my email open overnight and the number kept going up and up, over ***9,000 OVERNIGHT***!!!

    (i DO now have "additional tracking/social media" items blocked by adblock plus, but ...would that make ***9,000*** ads attempt to break through, overnight in my email which wasn't even being used /by me/?)

    i've tried to provide what information i can think of, off the top of my head, and also i'll provide the logs from - i think i've run all the scans, and i've tried to do them the right way, as best as i could remember (even with the great instructions, it's a lot to remember)

    ...i tried to make sure user account control and antivirus were off, and to run all as administrator ...i hope i did right - if i did anything wrong that you notice, please let me know and i will try again, with my apologies!

    ...thanks so much for taking the time to review my issue! :)

    ~principessa
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall iSkysoft Helper Compact 2.5.2

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Reboot now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7,or Win8 or Win10 don't double click, use right click and select Run As Administrator).

    Attach the new MGLogs.zip
     
  3. principessa

    principessa Private E-2

    hi :) ........thank you so much for the FASTEST RESPONSE I'VE EVER HAD, FROM A TECH!!! :) ...you are AWESOME!!!

    adding the special code to the registry, was a success(!),

    and here's the latest mgtools log ...hope i did everything okay, and that everything worked as hoped...
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, that should have done it. That program is a nasty. How are things running?
     
  5. principessa

    principessa Private E-2

    WOW! that could possibly be ittttt??

    ...can i tell you, i had to go back and forth with another tech for over a month, and,

    what's worse, in the end he told me that my computer (windows vista) was basically too old for him to invest his time to help me?

    ...what is a person who is stuck with an old computer, to do? i felt so left to fend for myself -

    and then YOU helped me ...and FAST!

    THANK YOU SO MUCH!

    (would it be okay if i / should i wait cautiously a few days before i say that i think it's okay?

    so far, i've tried using adblock withOUT the "additional tracking," which - without it on, it was getting disabled repeatedly, and ...SO FAR, it is staying on,

    but i don't know about the "popcash.net" alerts - do you know of any way i could get a malware bytes free premium trial -

    maybe if i uninstall, then reinstall, or ...that would probably be too easy lol :))
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The program that you uninstalled was probably responsible for the pop-ups among other things. You can certainly wait for a few days to make sure nothing resurfaces. We don't close threads. So if an issue returns, feel free to come back to this thread and let us know about it. :)

    In the meantime:
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  7. principessa

    principessa Private E-2

    hi...


    i don't know if it's anything, but, after having left this tab and returned to it ...all the writing in our exchange was ...blanked out -

    maybe it is just a fluke thing, but it felt like there's still malware and, it's trying to stop us from getting it?! :)

    have you seen this happen before, and do you have any idea if it's just a fluke thing?


    ...i don't think i disabled any disk emulation software(?),

    i don't see "hijackthis" in my installed programs list,

    and i had manually turned back on user account control - do i still need to employ the "enableUAC.reg" file,

    and - i had wanted to ask you if it's safe to manually delete "fixME.reg,"

    and also there are two icon images (like, hidden files being shown?) on my desktop that say "desktop.ini" -

    are these safe to delete, or NO, and they are hidden files that i should try to make hidden again, through "folder options"?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds like you had a little glitch in your browser.

    Yes, you can delete the fixme.reg.

    When you run the MGClean.bat. your hidden files will go back to being hidden.
     
  9. principessa

    principessa Private E-2

    okay GREAT! .....................THANK YOU SO SO MUCH, AND WISHING YOU THE BEST!!! :)
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing.
     
  11. principessa

    principessa Private E-2

    ( hi... i'm sorry to bother you again... it may be because of the malware, OR it may be because - a previous tech had me "reset" opera browser, and he said it had not gone correctly, but then quit helping me...

    i am now unable to access my bank acct in OPERA - only - in firefox, it still works -

    and also - from the same "overview" page for both banking AND credit cards ...i'm able to click through to the credit card details, but not the bank details ...it shows a spinning circle, that never lets me through...

    do you have any opinion on this, and might you know any steps that might be able to help it work again?

    thank you again...... )
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing I can suggest is to uninstall Opera, run CCLeaner, reboot and reinstall Opera. If that doesn't work, you will need to post in the software forum.
     
  13. principessa

    principessa Private E-2

    ( okay cool, will do :) and thanks again! :) )
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem.
     
  15. principessa

    principessa Private E-2

    (...*sad sigh* so sorry to bother you again - nearly the only sites i have used since you kindly helped me to clear out my computer, have been ebay, my banking site, some information sites like wiki ...nothing that seemed like a risk -

    tonight, as i was attempting to go to ebay - and DID go through, and log in - i heard " *dingdingding* threat has been detected," and i noticed a little green dot on avast antivirus, went to the avast dashboard > notifications, and it says:

    " we've safely aborted connection to www.ebay.com _because IT was infected_ with JS:Redirector-BKG [TrJ] " -

    does this mean that ebay itself had a virus, and/or that a hacker intercepted the connection - and because i went through and entered my password, is it likely that i have now got a virus? [and/or a hacker has likely stolen my password?],

    OR is it likely that my computer has the virus? ...i thought i was in the clear, and i'm so sorry for bothering you again...)
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you type in the address in your browser or a saved link?
     
  17. principessa

    principessa Private E-2

    hi thanks for getting back! ...i typed in www.ebay.com manually, no link... really appreciate your replying!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I had no problem with the link. You said that you were successful at loging in to ebay. Did Avast abort the connection? And which browser? I am thinking it was a false positive.
     
  19. principessa

    principessa Private E-2

    hi, i was using opera, and i was able to log in and view pages as normally... i hope it was a false positive, and that i don't have to keep bothering you, i'm really sorry...
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's no problem. That's what we are here for. Avast hasn't been what it use to be since acquiring AVG.
     
  21. principessa

    principessa Private E-2

    okay then, with any luck, i won't be back here again in just a few days! :) ...thank you aaaaagain :), and best wishes :)
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We never sleep! :)
     
  23. principessa

    principessa Private E-2

    ( awwww :) ...well one would never know it from 'your picture' [avatar :)] - looking good :) ...okay okay i'm going away ...for now :) )
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see all, even without eyes!! :)
     
  25. principessa

    principessa Private E-2


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds