HelpAssistant Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Petedz, Mar 7, 2010.

  1. Petedz

    Petedz Private E-2

    I seem to have acquired the HelpAssistant Virus as in some of the previous posts. I have gone through the Windows XP Cleaning procedures as outlined in those posts, however I was unable to get RootRepeal to work. I have attached the other logs as requested. I would like to know what the next step is.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please download HelpAsst_mebroot_fix.exe by noahdfear and save it to your Desktop.
    • Double click HelpAsst_mebroot_fix.exe to run the tool.
    • When the tool completes it will inform you HelpAssistant was successfully removed, or it may require a reboot. DO NOT reboot at this point if it tells you this. Do the below first.
    • With Windows Explorer, navigate to the C:\MGtools folder and double click on mbrfix.bat ( If not sure how to use Windows Explorer, you can optionally click Start > Run and enter C:\MGtools\mbrfix.bat into the run box and click OK. ) This will run quickly flashing a black screen in front of you too fast to read.
    • NOW REBOOT IMMEDIATELY!
    After reboot, delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\LES GRANT\Local Settings\TEMP
    • Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    Then attach the new C:\MGlogs.zip file

    Make sure you tell me how things are working now!
     
  3. Petedz

    Petedz Private E-2

    Everything appears to be back to normal. No more folder named HelpAssistant and much more free space on the hard drive. I have attached the MGlogs.zip. Thank you very much.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see a few files related to the infection. Let's make sure it is really fixed.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Petedz

    Petedz Private E-2

    Ran the Avenger as you suggested. This computer seems quite a bit faster now. Also, hard drive free space has increased. Attached are the files you requested.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and it will increase more when you uninstall all of the below old Sun Java versions as we requested in the READ & RUN ME:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2
    Java(TM) 6 Update 15
    Java(TM) 6 Update 2
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1

    We have a little more cleanup to do.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
    O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
    O24 - Desktop Component 0: Warning homepage - C:\WINDOWS\warnhp.htmlcontinue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Petedz

    Petedz Private E-2

    OK, uninstalled all of the old Java programs. Ran Analyse.exe and fixed the items you listed. Tried to run the fixme.reg script and received the following error message:

    Cannot import C:\Documents and Settings\LES GRANT\Favorites\Desktop\fixme.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor.

    I went ahead and rebooted, downloaded and installed the latest Java, and ran the getlogs.bat. Attached is the MGlogs.zip file.

    The computer is running much better now but I am not sure about the registry thing.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Chaslang is without power since Sat. and can not get on the web.

    Did you do this:
    ?
     
  9. Petedz

    Petedz Private E-2

    Yes, file type was set to all files. I got the error message as stated in my last post.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is not where it should be:
    C:\Documents and Settings\LES GRANT\Favorites\Desktop\fixme.reg:

    It should be saved directly to the desktop:
    C:\Documents and Settings\LES GRANT\Desktop\fixme.reg.
     
  11. Petedz

    Petedz Private E-2

    I recreated the fixme.reg file and saved it in the desktop folder as noted in your last post and got the following error message:

    Cannot import C:\Documents and Settings\LES GRANT\Desktop\fixme.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor.

    I have attached the fixme.reg file as a zip file.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not the same as what I asked you to create. See for yourself. Why do you have asteriks in four places. You need to use notepad and you need to copy and paste in exactly what was given.

    I will highlight in bold red what you added and what does not belong there:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds