Need help getting rid of HelpAssistant virus.

Discussion in 'Malware Help (A Specialist Will Reply)' started by WoeIsMe, Mar 11, 2010.

  1. WoeIsMe

    WoeIsMe Private E-2

    I have done everything in the READ AND RUN ME FIRST thread. I was able to do everything successfully except for the MGtools. I had some issues with that.

    It seems I still have the helpassistant active and it is still copying files, but no where near the fast pace it was before. Whenever I try to log into banking websites, it'll direct me to enter sensitive personal info that I know is not right.

    Please help, here are my logs:
     

    Attached Files:

  2. WoeIsMe

    WoeIsMe Private E-2

    After reading other posts, I found my MGtools logs zip file. Hope this helps also.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please download HelpAsst_mebroot_fix.exe by noahdfear and save it to your Desktop.

    • Double click HelpAsst_mebroot_fix.exe to run the tool.
    • When the tool completes it will inform you HelpAssistant was successfully removed, or it may require a reboot. DO NOT reboot at this point if it tells you this. Do the below first.
    • With Windows Explorer, navigate to the C:\MGtools folder and double click on mbrfix.bat ( If not sure how to use Windows Explorer, you can optionally click Start > Run and enter C:\MGtools\mbrfix.bat into the run box and click OK. ) This will run quickly flashing a black screen in front of you too fast to read.
    • NOW REBOOT!
    • Run avenger.exe by double-clicking on it.
      * -Do not change any check box options!!
      * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

      * Now click the Execute button.
      * Click Yes to the prompt to confirm you want to execute.
      * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
      * Your PC should reboot, if not, reboot it yourself.
      * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    • After reboot run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file and the Avenger log. ( C:\Avenger.txt).

    Make sure you tell me how things are working now!
     
  4. WoeIsMe

    WoeIsMe Private E-2

    Here's what you requested. Thank you for responding. My last hope was reformatting the computer. :cry

    From the short time I've been using the comp since I followed your instructions, everything seems more responsive. Prior to this, everything was becoming slow and multiple tabs on IE would freeze. I haven't tried to surf the net yet because I want to surf on a restrictive profile, not the admin one. However, when I go to My Computer and click on 'manage', I still see the HelpAssistant user profile but it is disabled. I don't know if it has ALWAYS been there and just never caused me any problems or if I still have the virus.

    I want to ask you. When I was having trouble with this virus, I downloaded Microsoft Security Essentials. I had Norton but I uninstalled it and was using Microsoft Security Essentials instead. I also ordered Webroot AntiVirus with Spysweeper 2010 but have yet to install it. My question is: shall I remain with Microsoft Security Essentials or shall I install and use Webroot and uninstall Microsoft Security Essentials?
     

    Attached Files:

  5. WoeIsMe

    WoeIsMe Private E-2

    I'm sorry for posting agian, I tried to edit my prior post but it didn't let me.

    I forgot to tell you, when I was running the C:\MGtools\GetLogs.bat file, towards the end of it, I encountered two errors. Both times I hit cancel. If I recall correctly, I believe it said something about it couldn't handle the process and there was an error. If I wanted to run a debugger it told me to click OK. I hit cancel both times and it finished running.

    Also, when I ran the HelpAsst fix, at first it said that HelpAsst didn't exist. So I clicked on manage and saw that it was disabled when I know for a fact seconds earlier it was enabled. So I enabled it and ran HelpAsst and then I got the message that it was deleted successfully.
     
    Last edited: Mar 13, 2010
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. However, you still have Norton installed on your system. Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    I don't know what this is, and if you also do not know, delete it:
    C:\Documents and Settings\Daniel\Local Settings\Application Data\5B4t56F8r4rw

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. WoeIsMe

    WoeIsMe Private E-2

    Thank you for your time Tim.

    I ran the Norton tool twice but I still see Norton AntiVirus in my Add/Remove program list. :confused

    I have no clue what that file is so I deleted it.

    I also did everything you recommended. Thanks so much for your time. I appreciate it.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What happens when you try to uninstall Norton AntiVirus Corporate Edition?
     
  9. WoeIsMe

    WoeIsMe Private E-2

    When I try to uninstall it from the add/remove list, it will lauch an uninstall wizard and the progress bar zips along quickly and it'll say "7 seconds remaining" and it will just freeze at that spot.

    Then I have to use task manager to close it.

    And while I still have your help, I was wondering if you could look at this thread I made:http://forums.majorgeeks.com/showthread.php?t=212299

    I'm having some side effects from the virus removal.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Last edited: Mar 15, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds