Helper.dll & sig help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by smallpc, May 2, 2009.

  1. smallpc

    smallpc Private E-2

    Ran the SAS scanner, see following log, I will be moving on to the next step, the helper.dll file is gone in the common folder, all that is left is the helper.sig file.
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 05/02/2009 at 00:48 AM

    Application Version : 4.26.1002

    Core Rules Database Version : 3875
    Trace Rules Database Version: 1823

    Scan type : Complete Scan
    Total Scan Time : 02:26:59

    Memory items scanned : 610
    Memory threats detected : 1
    Registry items scanned : 4857
    Registry threats detected : 1
    File items scanned : 38693
    File threats detected : 3

    Trojan.Dropper/Sys-NV
    C:\WINDOWS\SYSTEM32\DSOUND3DD.DLL
    C:\WINDOWS\SYSTEM32\DSOUND3DD.DLL

    Trojan.Unclassified/Helper-DD
    HKU\S-1-5-21-861567501-1177238915-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}

    Adware.Vundo/Variant-Helper
    C:\PROGRAM FILES\COMMON\HELPER.DLL

    Trace.Known Threat Sources
    E:\Documents and Settings\Aaron and Jessica\Local Settings\Temporary Internet Files\Content.IE5\MH5HKLSE\g_default[1].gif
     
  2. smallpc

    smallpc Private E-2

    Sorry, forgot to add the other 3 logs, please review and let me know. So far so good on the pc. Still get the common folder showing up upon start-up, but no files in them. Any help is appreciated.
    Thanks
    smallpc
     

    Attached Files:

    Last edited: May 2, 2009
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. We are currently reviewing your logs and will get back to you with a set of instructions as soon as we possibly can. Thanks for your patience during this time.

    Kestrel13!
     
  4. smallpc

    smallpc Private E-2

    Thanks for the response, hopefully everything is gone except for the commom folder appearing at start-up, I will await your response.
    Thanks
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    more than likely yes :) It's late here in the UK so I shall get to checking your logs first thing in the morning.
     
  6. smallpc

    smallpc Private E-2

    Any Luck with the logs?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have to be patient ... I am working under supervision... and have to have my fixes approved at the moment. There isn't much to do though by the looks.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I see you are using AVG8 but that you also have Symantec installed. What exactly from Symantec are you using there? Is it anti-virus or something else? Did you have Norton installed at some point and have just not uninstalled the LiveUpdates?

    Let's restore a file:

    Navigate to the following bold file:

    C:\Qoobox\Quarantine\C\WINDOWS\Temp\logishrd\LVPrcInj02.dll.vir

    Copy it and place it back into it's original directory and remove the .vir (rename it):

    C:\WINDOWS\Temp\logishrd\

    Let me know about Symantec

    Now tell me exactly what is popping up.

    You may need to start using a startup manager:
    Startup Manager

    Startup_CPL
     
    Last edited by a moderator: May 8, 2009
  9. smallpc

    smallpc Private E-2

    Basically I just copy what you have in bold, and put right back in the same spot removing what you have directed?
    Also, regarding Norton, I had it at one time, but removed it, I would say that it is just the live update info.
    Let me knwo if I need to do anything else.
    Thanks
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, but ensure that you take off the .vir extension when you rename!

    Navigate to the below bold folder and delete it:

    C:\Program Files\Common

    OK then let's run the Norton Removal Tool:

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    and finally...

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds