Infamous helper.dll issue..

Discussion in 'Malware Help (A Specialist Will Reply)' started by tard288, Dec 12, 2008.

  1. tard288

    tard288 Private E-2

    Hello all,

    I am one of the many that have encountered the infamous helper.dll malware problem. I have followed the advice on many of the existing threads and installed all of the various programs which were suggested in the READ & RUN ME FIRST. Malware Removal Guide. Everything seemed to go fine and the problem looks like it has gone away. No more 'Common' folder popping up at startup. The problem is that when I re-ran SUPERAntiSpyware and it once again found the same 'Trojan.Unclassified/Helper-DD' present in the registry.

    I have attached my last run of the various malware removal tools. Thank you very much for any help you guys can provide me...
     

    Attached Files:

  2. tard288

    tard288 Private E-2

    Here is the SAS log that I ran after I have finished everything in the READ & RUN ME FIRST. Malware Removal Guide. The strange thing is that the C:\Program Files\Common directory does not even exist anymore. When I open up Windows Explorer and have it show me all hidden files and directories, that folder is not present and yet SuperAntiSpyware says that the helper.dll is still there. I also went into the registry with regedit and tried to delete the registry keys manually and it would not let me. If you look at the MalwareBytes Anti-Malware log it shows that the same registry keys are suppose to be deleted when the computer re-boots but it did not happen for some reason. I am not sure why... Thanks once again for help you can provide me..

    Sam

    P.S> I have also included the CFScript I used with combofix.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the Malwarebytes log. You attached a HijackThis log which we did not ask for instead of the Malwarebytes log.

    Your logs look pretty clean. Please uninstall SUPERAntiSpyware and then download and install the current version from the below link. Be sure to update again during the installation. It may ask you to reboot. If it does, then reboot immediately. Then run a new scan and attach the new log.

    Also uninstall Viewpoint Media Player as requested in step 1.

    Now just in case the problem folder is still present, do the below.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 15, 2008
  4. tard288

    tard288 Private E-2

    Thank you very much for the response and sorry about including the wrong file. Here are the logs that you requested. SuperAntiSpyWare and MalwareBytes still found those infected locations in the registry. Is it ok for them to be there?? Thanks again for the help...

    Sam
     

    Attached Files:

  5. tard288

    tard288 Private E-2

    Here is the MalwareBytes log that I ran today.

    Sam
     

    Attached Files:

  6. tard288

    tard288 Private E-2

    Forgot to mention how things are working. Things seem to be working fine. No pop up window but SuperAntiSpyware still finds those two infected registry entries that nothing seems to be able to delete. When I go to look at them via regedit, they are empty but I can't delete them. MalwareByes and SuperAntiSpyware both could not delete them but both saw them. Thanks for any help you can provide me...

    p.S. Running Windows XP professional Service pack 3...
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this procedure: Resetting Registry and File Permissions Make sure you reboot as instructed.

    Afer reboot, run SUPERAntiSpyware and first check for updates. Then run a new scan and attach the new log. Do the exact same with Malwarebytes.

    Then reboot and run another scan with SUPERAniSpyware and Malwarebytes to see if they come back clean or still has detections. Let me know.
     
  8. tard288

    tard288 Private E-2

    Hi,

    I followed your steps with the subinacl utility and SuperAntiSpyWare and MalwareBytes still says that the registry is infected. I have included the two log files that you requested. Something strange that I saw was when I was running the reset.cmd, it stated that 3 registry locations could NOT be modified. I don't know what could be wrong. I can manually delete other registry locations but I can't delete this one. It is almost like it is being used.

    On the MalByte log, it states that the registry location will be deleted on reboot but I don't see that happening. Is MalwareByte suppose launch on windows start-up?? I have always manually start it unlike SuperAntiSpyware which places itself system tray on windows start-up.

    Please advise..

    Sam:cry
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run it again and tell me which registry locations it says this about.

    Are you logged with an account that has adminstrator priviledges. After getting the info to tell me which locations could not be modified, please reboot your PC into Safe Mode and logon to the real user account that is named Administrator. The run the same procedure to reset permissions again and see if you still get error messages. If not, then run SUPERAntiSpyware and Malwarebytes in safe boot mode while logged in as Adminstrator.

    Then reboot and log into your regular user account and see if a new scan is clean or finds the problems again.
     
  10. tard288

    tard288 Private E-2

    Hi again,

    Here is a log file that was generated by subinacl. I used the /errorlog to generate it since the failure message flashes by so quickly on the DOS box. There are 4 locations that it had problems with:

    HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SAC : 2 The system cannot find the file specified.

    HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SAI : 2 The system cannot find the file specified.

    HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SCM:{6c736d4F-CBD1-11D0-B3A2-00A0C91E29FE}: 6 : Unable to enumerate subkeys

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009 - RegSetKeySecurity Error : 6 The handle is invalid.

    The same failures happen in safe mode logged in as administrator. SuperAntiSpyware and MalwareBytes both still detected the infected registry locations. Thanks for any help you can provide me...

    Sam
    :confused
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A new version of SUPERAntiSpyware is out. Let's see if this helps. Make sure you follow the below instructions exactly.

    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too.
     
  12. tard288

    tard288 Private E-2

    Thank you very much for all of your help!!!! I installed the latest version of SuperAntiSpyware and followed your steps and the infection is finally all GONE!!!!! The new version of SuperAntiSpyware was able to finally delete the infected registry locations. MalWareBytes also states that everything is clear and malware free. Thanks once again for all your help!!!!

    Sam
    :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds