Chinese Popup??

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by usum07, Mar 21, 2012.

  1. usum07

    usum07 Private E-2

    I can't seem to figure out why this popup continues to appear. It will randomly open while I'm using Adobe programs (Ps, illustrator, indesign). It's only popped up once with another design program (Rhino). It appears when I use the keyboard for shortcut commands and in order to use the keyboard again, I have to close the program and reopen it, but it always comes back.

    Has anyone seen this before? Suggestions for removal?? Thanks.



    http://i284.photobucket.com/albums/ll5/JPiazza7/chinesepopup.jpg
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Hmm, can you interact with the pop up at all? Right click or left click?
    • Are you able to bring up the task manager whilst the pop up is on screen and see if anything is running which could relate to it?

    It may be that you are better off posting about this first in the software forum. Choice is yours, but for me to rule out malware you will need to therefore follow these procedures:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. usum07

    usum07 Private E-2

    I CAN interact with it. I can move it around, click the left and right arrows on the right side of the popup, and click the symbols and it will add content to the upper left popup box.
    I CANNOT right click and get any information about it though. I when I switch programs, say to task manager, then back to the program it's popping up in, the popup disappears until I strike the keyboard again, so I don't know how I could identify it "processes". I do not see anything foreign under "programs" within task manager.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So do you wish to follow my instructions or would you rather ask first about it in the software forum? :)
     
  5. usum07

    usum07 Private E-2

    Okay, I'm going to give your instructions a shot.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's good. At least we can see if any malware is showing.
     
  7. usum07

    usum07 Private E-2

    Well, I gave the Adobe programs that the problem (popup) typically occurs in a quick run, and so far the popup has been removed. Hopefully it stays that way. Thanks for the help!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you did not deliberately set this proxy yourself then please include it in our list of HJT fixables below:



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local>
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    After clicking Fix exit HJT.

    Things still ok?
     
  9. usum07

    usum07 Private E-2

    Well, I spoke too soon. Last night after saying the problem was fixed, it showed back up again.

    I just ran the MGtools analyse.exe and fixed the two lines you addressed, then did a restart, but the problem still exists while using the keyboard in the Adobe programs.

    On the plus side, I swear my computer is running faster!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you will have to post about the issue in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. usum07

    usum07 Private E-2

    I appreciate all your help!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds