Helponline.exe????

Discussion in 'Malware Help (A Specialist Will Reply)' started by MommyFish, Dec 27, 2005.

  1. MommyFish

    MommyFish Private E-2

    OK - we replaced a fan in my bf's system yesterday - now all of a sudden he is running at 100%CPU usage constantly - I finally got into Task manager (Win XP Pro) and there are 251 processes running (he usually has about 35) - seems to be almost all "iexplore.exe" and "helponline.exe"

    I'm going to try to stop them running from task manager, but has anyone heard of this "helponline" file? Google produced no results.... My guess is he got some type of malware or virus that is telling the program to open ie and run helponline over and over again - thoughts?

    Thanks bunches, as always.

    Kristina
     
  2. MommyFish

    MommyFish Private E-2

    Oh crap - processes have gone from 251 to 281 - now Task Mgr shows a program running called "BEND COAL BAIT.exe" Another new one on me...
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's sounds like a LOP infection. You did not install Messenger Plus....did you?

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  4. MommyFish

    MommyFish Private E-2

    I don't think he has that on there, he's not a big IM fan - I'll try the steps and get back to you, thanks bunches.

    --OMG - this will take forever - I can barely get into any of the Start Programs or Ctrl Panel because the sys is running at a constant 100% - this is like running a 286, lol. Is there any way to stop programs from running so i can access Ctrl panel etc? (302 processes and counting)
     
  5. MommyFish

    MommyFish Private E-2

    OK - impossible to get to control panel - should I start with step 5 and reboot in safe mode to get to add/remove programs?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Skip the uninstall part related to Add/Remove programs and go to step 2. Let me know if you can work from there down.
     
  7. MommyFish

    MommyFish Private E-2

    No can do - can't get to Start - every few seconds the program reloads and the button executions are not recognized...or recognized too slowly. Task manager is the only thing up on my screen and I can barely maneurver in that (processes are at 341 now). However, if my memory serves, he already has his "show hidden/system files" checked.

    (I am accessing this via my separate computer 2 feet away, btw)
     
  8. MommyFish

    MommyFish Private E-2

    LOL - looks like Ctrl panel may be coming up in a sec...it only took 10 minutes or so...If I can I'll check that hidden/sys is checked and try to get to add/remove progs. :eek:

    Oh, and he normally has current NAV and Personal Firewall running, regularly scans with Adaware, etc etc. His NAV caught a "Download.trojan" several days ago, and it seemed to have deleted it as appropriate.
     
  9. MommyFish

    MommyFish Private E-2

    No go on Ctrl Panel - it just won't give it to me. Got a Plan B?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you download and install programs?
     
  11. MommyFish

    MommyFish Private E-2

    Not a hope in hell on that - I can't get to anything in Windows it seems, as soon as I try to click on anywhere, that damn program re-executes and I lose mouse etc etc - think of a really really really slow computer trying to execute my commands in order. All I have up is Task Manager. I am able to "end process" one at a time, but by the time it accepts the command and ends it, another has taken it's place.

    Time for Safe Mode?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to see if you can either get HijackThis on there to get me a log or you will have to write down all the process names (not to usefull from Task Manager since it does not show full paths and does not show ALL processes either). Try safe mode and also make sure you are physically disconnected from the internet by unplugging cables.

    Sounds like you may have some services running that may need to be shut down. If msconfig works, you could try a selective boot with startups and non-MS services shutdown.
     
    Last edited: Dec 27, 2005
  13. MommyFish

    MommyFish Private E-2

    Safe mode it is - back in a few... =)
     
  14. MommyFish

    MommyFish Private E-2

    OK - in safe mode it is still slower than molasses, but manageable - the only processes running now are the predictable ones, down to 14 of them - I am going to check add/remove and then....

    get Hijack this on the system, run it and get you a log.

    Correct?

    This is the list of running processes in safe mode, just for giggles:

    taskmgr.exe
    rundll32.exe
    ctfmon.exe
    explorer.exe
    svchost.exe
    svchost.exe
    svchost.exe
    lsass.exe
    services.exe
    winlogon.exe
    csrss.exe
    smss.exe
    system
    system idle process
     
  15. MommyFish

    MommyFish Private E-2

    OK, I can't access the internet on that system, so I can't d/l hijackthis, but I can run Adaware and a few others that I had already installed on his system - any other suggestions?

    Thanks bunches...
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Get HijackThis by downloading elsewhere and unzipping. Then use a floppy, a flash drive, a CD or another method to get it to the infected drive. I would prefer a HijackThis log from normal boot mode, but to get things started, any log you can get will do. The task list from Safe mode shows nothing unusual.

    You can also run Ad-Aware in normal boot mode too (hopefully it is a current version with an updated reference file) and save a log and post it here as an attachment.
     
  17. MommyFish

    MommyFish Private E-2

    Will do - have to shut down for the night and will send tomorrow morning - thanks so much Chas - I really appreciate it!

    Kristina (a fellow Folder)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Alrighty! Anyway you can get this started would be good. I'm not sure if all the problems are malware or if maybe some are related to Windows software issues. Have to see more info to know.
     
  19. MommyFish

    MommyFish Private E-2

    Hi,

    If you are still there I have managed to speed-up my performance a quite a bit by pulling out the little battery on the mother board for about 30 seconds. After reinstalling that little ditty. I had a slow start-up with Norton SystemWorks not running; claiming some sort of issue. Of course my system clock reset which I suspect helped in some way to increase my performance. However, the system is still running rather oddly.

    Evidentally , I still have background programs/processes running. Norton is asking me to uninstall and then reinstall my Norton products, and I keep getting the "Error Report" splash box that appears about every 30-40 seconds stating that there has been an error with "BLAHCOOL.EXE" which I have NEVER heard of before - the same program everytime "BLAHCOOL.EXE" in all caps. I don't know how ot got on my system or why it is on my system. While writing this it has appeared about 10 times - litterally. I keep clicking on the "Send Error Report" button - the other options being "Debug" and "Don't Send". Every so often the when I hit the "Send Error Report" button in the splash box I suddenly have multiple instances of the splash box appearing. Hitting "Debug" works to close the box's in this instance - if this matters - I dunno??? I am at a loss for what is happening. Other than I suspect Malware/Spyware. I am praying for the $$$ for a Mac at this point.

    I was able to download Hijack this and have attached the log for your review (as an attachment, of course).

    Thank you for your help... awaiting your reply - eagerly and with baited breath....
    signed

    confused:
     

    Attached Files:

  20. MommyFish

    MommyFish Private E-2

    Did a file search - system found this file BLAHCOOL.EXE-2CF812AB.PF in the directory c:\windows\prefetch - the plot thickens...lol

    Also - I have turned Off my system restore.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Add/Remove programs and uninstall Daily Weather Forecast.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\Documents and Settings\All Users\Application Data\that close proxy browse\BLAHCOOL.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: (no name) - {924DFDBF-28DC-9EC5-3E57-55C97F982687} - C:\DOCUME~1\JOHNNY~1\APPLIC~1\SCRBALL\softwarebeep.exe
    O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
    O4 - HKLM\..\Run: [proxy browse extra four] C:\Documents and Settings\All Users\Application Data\that close proxy browse\BLAHCOOL.exe
    O4 - HKCU\..\Run: [Extra view] C:\DOCUME~1\JOHNNY~1\APPLIC~1\README~1\ante free link.exe
    Do you recognize these next 3 items? If not, fix them too.
    O16 - DPF: {0AA2D4B3-27C3-42CB-B671-8B6CF97AE4FE} (TSAEButton Class) - https://www.cwinsider.com/cwi/frntd/advantedge/TSAEButn.cab
    O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://inotes.cwinsider.com/mailsv05/iNotes6W.cab
    O16 - DPF: {AA5EB1A7-E492-4F88-9989-0AB26B52F4A6} (RZHelper Class) - http://portal.relizon.com/wlcs/controls/RZOFFICE.CAB

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Daily Weather Forecast <--- the whole folder
    C:\Documents and Settings\All Users\Application Data\that close proxy browse <--- delete the whole that close proxy browse folder
    C:\Documents and Settings\JOHNNY~1\Application Data\SCRBALL <--- delete the whole SCRBALL folder
    C:\Documents and Settings\\JOHNNY~1\Application Data\README~1 <--- delete the whole README~1 folder (README~1 is a shortened form of the full folder name)

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  22. MommyFish

    MommyFish Private E-2

    Hello,

    First off let me thank you for your time and efforts with my dilema.

    Step One: Deleting "Daily Weather Forcast" from Add/Remove programs did not work. Only because it was truly nowhere to be found in the programs list. However it was found in a later step (as a folder) which, of course I deleted.

    Step Two: Deleting "C:\Documents and Settings\All Users\Application Data\that close proxy browse\BLAHCOOL.exe" - also could not be found.

    I proceeded with the next steps that went precisely as described in your instructions.

    I did, in fact, recognize some of the entries; I work for Countrywide Home Loans and a couple of the entries referring to CW Insider is the Countrywide home page for employees. Ths allows employees to do work via terminal services client or AKA "Remote Desktop" - I think it is now called. Hopefully we are upgrading our version of Windows soon at Countrywide. Anyhoo - all else seemed to go well.... I think.

    I could not reboot in regular mode at first. However, when rebooted again (into Safe Mode) I reset my system date/time settings to reflect the current date. Norton liked me for doing this (aparently) becuase then I rebooted one more time (in Regular Mode) and the pc did infact seem to boot properly.

    Finally, I ran the second scan of "HijackThis" and am attachng it to this posting awaiting your reply.

    Thanks
     

    Attached Files:

  23. MommyFish

    MommyFish Private E-2

    Oh one more thing? If - all is okay at this point according the Hijack this. May I turn my System Restore back on? I won't do this until I get the okay from you specifically.

    Thank again
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you should really complete the rest of the READ & RUN ME since you were not able to run things before. HJT logs do not show everything. That is why the procedures use it last. Post the logs from BitDefender and Panda.

    How are things working right now.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  26. MommyFish

    MommyFish Private E-2

    I am running it as I type... hope that is not a no-no.

    I'll be back with the log. It has already found 13 infected items at the 50% complete point.
     
  27. MommyFish

    MommyFish Private E-2

    Okay,

    It took almost 2 hours but the scan from Ewido seems to be well worth it. It found 18 infect files. I have attached a copy of the scan as per your instructions.

    Let me know if I am on my way to normal... well - at least as my PC is concerned. LOL!
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be a good idea to point out these infections from trying to use illegal software cracks and key generators to whoever owns and uses the PC. As you can see, it was not a good idea.
    C:\Documents and Settings\Johnny V\My Documents\Tech Stuff\Key Generators cRaCkS and pATCHES\microsoft.product.activation.crack.all.products.office.wind.zip/microsoft.product.activation
    .crack.all.products.office.windows.xp.2003.pro.professional.home.server.enterprise.exe/instw32.exe -> Dropper.DNet.b : Cleaned with backup
    C:\Documents and Settings\Johnny V\My Documents\Tech Stuff\Key Generators cRaCkS and pATCHES\Office 2003 KeyGen.exe -> Worm.Mapson : Cleaned with backup

    You should delete the files in SpywareNuker's backup folder. It probably has an option to delete them.
    C:\Program Files\Spyware Nuker 2004\backup\200512211958.zip/newdotnet6_98.dll.000 -> Spyware.NewDotNet : Error during cleaning
    C:\Program Files\Spyware Nuker 2004\backup\200512211958.zip/uninstall6_98.exe.000 -> Adware.NewDotNet : Error during cleaning

    How is everything working now?
     
    Last edited: Dec 30, 2005
  29. MommyFish

    MommyFish Private E-2

    Hello,

    The speed of my pc is actually a bit better than, even before the problems were noticable. I will make certain the crack stuff is not an issue in the future.

    Everything appears to be good. I will keep using: Ewido, CCleaner, Microsofts Antispyware program, Spybot, Adaware, Spyware Nuker, and Spyware Blaster in addition to Norton SystemWorks. Geeeeeze!! Could they not just combined all this into one big office suite that automatically ran once a week (say Monday Morning at 2:00 am?)

    ... sorry - just dreaming.

    In your experience may I ask your opinion of Apple PC's. Do you think they are worth it?

    Oh - and may I turn on System Restore ?

    Thank you again for all your time and consideration regarding this issue - you guys Rock!!! :)
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having anymore malware problems, enable System Restore now. And then start working thru the below:

    How to Protect yourself from malware!

    However I would not keep all three of the below running full time. Only keep one:
    Ewido
    Microsofts Antispyware
    Spyware Nuker

    My first choice to remove as it is the least useful (even less useful than Spybot which is free) is Spyware Nuker. If you are not going to buy Ewido, uninstall it an keep MS Antispyware which is free.

    Combining into one application is what Symantec and McAfee and some others have already done. They call them names like Internet Security Suites. They are huge resource hogs and not worth the money.

    Apple PCs are nice. Some people really love them. I don't use them anymore and have not for along time. Not enough freeware/shareware software is available for them. At least not like in the PC world. If Apple PC's were as dominant in the world as PC's, you would more than likely see similar malware issues on them. It is not worth the malware creators time to attack them since there are not too many people (relatively speaking) using them. And also more people hate Microsoft.
     
  31. MommyFish

    MommyFish Private E-2

    You Guys are the best help I've found anywhere!... I mean On the Internet or in person!!!

    Thank you so0000 - very much!!

    Signed,

    Indebted for years to come
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. And thanks! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds