Deal Helper and Time Sync

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hiptolick, Sep 29, 2004.

  1. hiptolick

    hiptolick Private E-2

    I've been fighting with this all day long. I've searched for solutions across the net with no luck and hope that someone here has some experience with a couple of nasty parasites that seem to be related. Specifically,
    Deal Helper and Timesync
    I first noticed these last night. I took my firewall down for 2 minutes to debug an issue with skype and before I knew it I was getting messages from all over the place with a new icon for "Time Sync" in the system tray.
    Immediately, I turned the firewall back on and ran Adaware. The result was the discovery of numerous malware items called Deal Helper and Time Sync. I went to google and found data on Time Sync which supposedly can be uninstalled via Add/Remove and I did this but it still pops up in the system tray. I ran adaware and removed the pesky little creatures and then ran hijack this. I noticed an executable running out of c:\programfiles\commonfiles\tsa called tsl.exe. Hence, I checked the little bugger and removed it. I then restarted the sytsem and found that deal helper and timesync were still being found by adaware. I went back to hjt and also found tsl.exe was back again. Hm? Must be something that reconnects to the internet after starting back up again and then reinstalls itself. Within a minute, or so an installation window pops up with a warning that "Windows cannot find tsl.exe". So, I got rid of the executable I didn't get rid of whatever it is that is trying to connect behind the scenes. I even spent another 29 bucks for "NoAdware". It seemed to find more crap, including Deal Helper but every time I remove it, it is back again in a matter of minutes. So, normally, I have been able to fix these things myself but I am rather stumped at this time. If anyone can help me identify what it is that is connecting and installing while I have my back turned, I'd appreciate it. I also emailed dealhelper.com and asked for removal instructions. I suspect I will have to go into the registry, but don't know where to look. If you can help, then I will put you on my permanent Christmas card list. Please advise.
    Dan
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get the correct version of HijackThis and post a log using that proper version. However first you need to follow ALL the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    NOTE: You should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Okay! Having said all that here is some stuff for you to work on:

    Definitely fix these next 4 lines with HJT but only after making sure no browsers are running.
    Always exit all browser applications before scanning or fixing lines with HJT.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O3 - Toolbar: (no name) - {D6223CBC-A263-4CB1-B35E-1AE40FEF3B3B} - (no file)
    O4 - HKLM\..\Run: [hpsysconf1] C:\WINNT\System32\kbnaauw.exe
    The O4 line with hpsysconf1 is Adware.ZioCom, an adware program that monitors Internet activity and displays customized advertisements.
    See this link: http://securityresponse.symantec.com/avcenter/venc/data/adware.ziocom.html


    Are these next 2 lines what you want for start page? If not, have HJT fix them.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://jazz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://jazz/

    Do you know what this URL for ventana-ranch is? Did you purposely put it in
    your trusted zone? If not, have HJT fix it.
    O15 - Trusted Zone: http://www.ventana-ranch.org

    Do you know anything about these two O16 lines below? If not, I would have HJT fix them.
    O16 - DPF: {2646205B-878C-11D1-B07C-0000C040BCDB} (NSIEMisc Class) - file://I:\autorun\x86\bin\nskey.dll
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-9.cab


    Did you order PC Doctor Online or did you just try their free examination?
    realtime.exe (that shows in your log) is the monitoring device for PC Doctor Online.
    It provides a "free" examination on system files (i.e. registry), reports the number
    of errors it finds, and invites you to "order" the fee-based fixes from its web site.
    Rip-off.
    You should uninstall PC Doctor Online and have HJT fix the below line if it still exists after the uninstall:
    O4 - HKLM\..\Run: [PCDRealtime] C:\WINNT\realtime.exe

    And one final note: NoAdware is on a list of rogue/fake spyware removal tools. We do not recommend using this tool. In addition the free tools work better. See the below link and look for NoAdware:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    After fixing all lines in HijackThis, reboot in safe mode and delete:
    C:\WINNT\System32\kbnaauw.exe

    No reboot normal mode and come back and tell us how things are working.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. hiptolick

    hiptolick Private E-2

    Well, after getting spanked for not following proper procedures (thank you sire may I have another) I followed all instructions to the letter and here are the results so far.
    1. On line virus scan using Trend Micro found no infections.
    2. Symantec Security Check found 2 trojans; 1)Trojan Dropper and 2) Download Trojan.
    3. Stinger did not recognize, or acknowledge Trojan removal.
    4. Ran all Adware removal tools.
    5. Ran HJT (latest version) and proceeded as directed with the following exceptions; 1) Nskey.dll-This seems to be a valid windows dll as reported by a number of website I visited, 2)http://www.Ventana-Ranch.Org is a SharePoint Web I manage and is valid, 3) http://jazz, is my own SharePoint site on my box I use to keep the family busines humming, 4) http://tools.ebaying.com is a valid Ebay resource. All other recommended HJT corrections were implemented.
    6. As far as Dealmaker is concerned, I went to Sysinternals.com and downloaded the Process Browser and proceeded to do the following;
    a. Reboot in safe mode.
    b. Find dealmaker.exe and delete it.
    c. Rebooted normally.
    d. Started process browser and waited for Dealmaker to start (which it did again in about 5 minutes).
    e. Started Process Browser and noted that one of the programs you recommended be deleted was the parent of the process. The parent was c:\WINNT\System32\kbnaauw.exe.
    f. Killed the dealmaker process.
    g. Deleted kbnaauw.exe and dealmaker has not reappeared.
    So, it appears as if everything is running ok and the only thing left to do is to go back to Symantec to see if those two trojans have persisted and if so deal with it some manner.
    I have McAfee Enterprise V7 and am surprised it didn't catch these two little critters.
    So, Chaslang, thanks for the help :)
    Oh, by the way, I never did get a message back from Dealmaker.com regarding removal instructions. Surprise, surprise!
    Oh and 1 last thing, I sent the NoAdware folks a request for a refund.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let us know if you still have any problems with those trojans.
     
  6. hiptolick

    hiptolick Private E-2

    About the Trojans.
    After doing a bit of research it seemed people were reporting good results with the AVG product, so I downloaded the free version, ran it and got rid of those pesky little bugs. The url for anyone elses reference is
    http://free.grisoft.com/freeweb.php/doc/2/.
    A couple of things stopped working after running through all the procedures.
    1. msconfig from "start/run" no longer works.
    2. The help center from strart/help no longer works. Is this common? Any ideas about how to get this back?

    Regards,

    Dan
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. hiptolick

    hiptolick Private E-2

    Chaslang, (or should it just be Chas)
    I'll check out your suggested references and hope I can repair msconfiga and help center. Regedit and task manager work without error. I had actually just updated to XP SP2 the day before, should that make any difference.
    I'll keep you posted.

    Dan
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just Chas is fine! Did you update to XP SP2 while you had this malware on your PC? That can cause problems in the upgrade. I'm not saying that it did in your case. I'm just saying that it could have.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds