Some Help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by burnet01, Aug 18, 2008.

  1. burnet01

    burnet01 Private E-2

    I would appreciate if some one help me because I have follow READ & RUN ME FIRST. Malware Removal Guide but doesn’t work, I could not fix the problem myself.

    -About two weeks ago I started to get the UiPopupHidden error every time I shut down the PC and the PC run slower. On a web they advised to run the follows programs to get rid of the Uipopuphidden problem (MS Windows Defender, SpywareBlaster, Ad-Aware SE, Spybot-Search&Destroy and Ccleaner) I run all these programs one by one but things got worst.

    -The UiPopupHidden remain, plus now every so often a window appears for 2 seconds saying “Windows Installer. Preparing to Install” disappear and after awhile again.

    -Every time I start the PC the items in the desktop take ages to appear.

    -My untivirus PC guard (Virgin) doesn’t start automatically as usual, after a while I got an error and then PC guard antivirus starts. (I have uninstall and install PC guard few times but the problem remain).

    -Since I’ve run ComboFix.exe every time I turn on the computer for few seconds the screen appears on DOS and after disappears and the PC stars normally. It is not too annoy but this never happen before, it’s not the normal way of the PC to starts.

    -After I’ve installed and run all the programs advised in READ & RUN ME FIRST. Malware Removal Guide I got a strange file on the desktop Thumbs.db

    I’ve tried to get rid of the UipopupHidden and installed and run few programs (advised) but things are getting worst.

    Regards
     

    Attached Files:

    Last edited: Aug 18, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!



    You need to attacht the other log files that were requested in the READ & RUN ME. Attach the logs from the below:
    • SUPERAntiSpyware
    • Malwarebytes Anti-Malware
    • MGtools (this is the C:\MGlogs.zip file as stated in the instructions).
    Note that UiPopupHidden may not have anything to do with malware. It may be from some software you have installed. In fact it may be related to the security suite that you installed from your ISP.
     
  3. burnet01

    burnet01 Private E-2

    I've attached already the MGtools file. GetUnKey.txt was inside C:\MGlogs.zip.
    Here are the other two files. Please let me know what you think.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the C:\MGlogs.zip file which is supposed to contain 6 logs. If it does not contain 6 logs, you did not get it to run properly. Thus you will have to run it again and make sure you let it finish running.

    But note what I already stated, your popup message is most likely due to the software you install from your ISP.
     
  5. burnet01

    burnet01 Private E-2

    Thanks for your help.
    These must be the 6 files you said. Please have a look and tell me what you think.
     

    Attached Files:

  6. burnet01

    burnet01 Private E-2

    Here are the rest of the files.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it was just one file that you were supposed to attach. The C:\MGlogs.zip file as requested in the procedure. These 6 logs are already inside of the ZIP.

    At anyrate it does not matter. Your logs are clean. As I stated a couple times already. You are not having malware problems. The popup you are referring to is related to the software you got from your ISP.

    You do need to uninstall the below as requested in the READ & RUN ME in step 1:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    Viewpoint Media Player

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. burnet01

    burnet01 Private E-2

    Hi there,
    -I have followed all the steps. I saved as fixme.reg file and looks working. I got a warning saying if I want to add fixme.reg file to the registry, and then a second one saying that the fixme.reg file has been successfully entered into the registry. Beside UipopupHidden everything is fine.

    -The warning “windows installer. Preparing to install” is gone.

    -Removing HijackThis, I got an error saying that HijackThis may have already been uninstalled. I think HijackThis came inside ComboFix, because I don’t remember to have downloaded HijackThis, so uninstalling ComboFix, HijackThis should be gone as well.

    -I still have the UipopupHidden error. You said it may be related to my ISP, I am trying to get in touch with my ISP but so far they are ignoring me. I thought UipopupHidden was a “Blank hijacker”. Is it any harm to my PC or my security?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It was installed while using MGtools. It has nothing to do with ComboFix.

    Odds are they will not be able to help you anyway and will more than likely just tell you that you have malware because they will not really know what the problem is.

    It is not a hijacker and it is not a security problem. It is an issue with how the security software that you got from your ISP is being shutdown/terminated when Windows is shutdown.
     
  10. burnet01

    burnet01 Private E-2

    Firstly I would like to thank you for your help and time. The PC was very unstable, now everything seems fine (apart from the UipopupHidden)

    Finally, What do you advise me to do about UipopupHidden?

    Best regards,
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Either live with it or see if uninstalling all the software you installed from your ISP will fix it. It may or may not. I see all of the below which is from your ISP. I'm not sure it you have just one main program that will uninstall everything or not. I'm just listing what I see:

    Authentium AntiVirus SDK - 2
    RPS Ad Blocker
    RPS AntiFraud
    RPS AntiSpyware
    RPS AntiVirus
    RPS App Detector
    RPS AsRealtime
    RPS Backup
    RPS Burn
    RPS Diagnostic Utility
    RPS Firewall
    RPS ParentalControl
    RPS Performance Tool
    RPS PopupBlocker
    RPS Privacy Manager
    RPS RpsCore
    RPS Security Cleanup
    RPS Zip
    Virgin Broadband advisor 1.5.14
    Virgin Broadband PCguard

    This is not a malware problem so you will have to decide how you wish to address it.
     
  12. burnet01

    burnet01 Private E-2

    Hi,
    Today problems started again. At start windows, items on the desktop takes ages to appear. The whole pc got very slow, on and off line, and get freeze quite often. The antivirus fail to start automatically when starts the pc, and the “windows installer. Preparing to install” appears again.
    I just have one main program from my ISP, which contain all that.
    I’ve been asking for help to my ISP support but they just ignore me. This is depressing I don’t know what to do.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware problem and we really should not be working it in this forum; but here is what I suggest that you do.

    Uninstall ALL of their software!!!!! And then attach a new log from MGtools so I can verify that it all was removed. I will then give you some free tools to use to replace the antivirus, antispyware, and firewall.
     
  14. burnet01

    burnet01 Private E-2

    I’ve opened a new thread in: Help & Technical Forums>Software>PC troubles.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    WHY??? Everyone is going to tell you that those logs do not belong there. They are going to tell you to post in the Malware Forum. I already told you what I believe the problem is and what to do. You are supposed to be attaching the MGlogs.zip file and only this file here in this thread not in a new thread in the Software Forum. Please attach the correct log here now. I know I said it was not a malware problem, but I did give you something to try. Also note this problem is know to occur with certain ISP software. See another example here:http://www.castlecops.com/pstp372446-.html

    Are you still having that popup at shutdown after uninstalling all of that software?
     
    Last edited: Aug 26, 2008
  16. burnet01

    burnet01 Private E-2

    You said this, that’s why.

    The ISP finally replied, this is what they said:
    “Due to the many different configurations and setups that modern day PCs have it would be impossible to predict how a software program will react to each individual setup.
    This seems to be one of those times that something else on the PC is causing issues with PC Guard. Unfortunately being able to pinpoint the exact issue will be very difficult and all that I can suggest is to remove the PC Guard and retest to see if this is actually what is causing the issue.
    There are lots of free antivirus and spyware software available online and it may be beneficial to test to see if these other pieces of software cause similair issues.”

    Since I removed PC Guard, the pc works much faster. I haven’t had UipopupHidden (so far) neither “Windows installer. Preparing to install”

    Here are the Mgtools files.
     

    Attached Files:

  17. burnet01

    burnet01 Private E-2

    These are the rest of the files:
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but I also said
    And in addition why do you keep posting the individual files rather than the MGlogs.zip file that is requested. You don't need to look in the C:\MGtools folder unless we ask you to do so.


    So then as I stated, the problem was due to your ISPs software.

    You need to work thru the below now to get yourself properly protected:

    How to Protect yourself from malware!
     
  19. burnet01

    burnet01 Private E-2

    I didn’t look in the C:\MGtools folder. MGlogs.zip is in C:\MGlogs.zip. (outside MGtools folder) The files I posted are everything inside MGlogs.zip there are nothing more. Perhaps I should have posted MGlogs.zip here it is.
    You were right, the problems was the ISP software, but now i am without protection.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is what we asked for. ;)

    Yes and that is why I gave you the link in messages # 18 & 7.
     
    Last edited: Aug 28, 2008
  21. burnet01

    burnet01 Private E-2

    I’ve installed an antivirus and a firewall. The firewall (Online Armor personal) freezes the pc at start, also every time ,at start as well, I got error from windows (can not find a file) and online I got a blue screen error and the pc shut down itself. I uninstalled it and installed zonealarm, so far everything seem fine.

    If you don’t think I should do anything else, Can I uninstall Mgtools?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can just use the steps given for removing it in message # 7.
     
  23. burnet01

    burnet01 Private E-2

    Just to thank you for your help and time.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  25. burnet01

    burnet01 Private E-2

    Hi again,
    I deleted MGtoolsexe without problem but still remain lots of its files in C:\ and Thumbs.db all around the pc. I don’t recognise any of these files, so I don’t know which one I can delete and wihich one I shouldn’t.
    Would you mind tell me how get rid of these files.

    Regards
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't delete anything we did not ask you to delete. Thumbs.db is a Windows system file. You just did not see it in the past because you had files hidden. Now after running the READ & RUN ME, you don't have anything hidden which is better because you do not give malware an easy place to hide. If it bothers you that much, then undo those steps in the READ & RUN ME step 1 or just use the below registry patch to set things back to default.


    Copy the bold text below to notepad. Save it as hide.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  27. burnet01

    burnet01 Private E-2

    Thanks Chaslang, I’ll do that.
    Best regards
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds