also @ TechSpot: Weekend Open Forum: Google Chrome OS and the future of cloud computing
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Trojans/helper.dll/helper.sig

Closed Thread
Page 2 of 3 1 2 3
Bookmark Thread Tools
  #21  
Old 08-24-2008
TechSpot Member
 
Location: Ca
Member since: Jul 2008, 51 posts
System specs
nevermind, saw the answer to my question in one of the pictures.
  #22  
Old 08-24-2008
xxdanielxx's Avatar
TechSpot Addict
 
Location: Southern CA
Member since: Aug 2006, 1,212 posts
Make sure to disable any AV or Spyware protection before running this tool
To remove this ad, sign in. To register for a new account, click here.
  
  #23  
Old 08-24-2008
TechSpot Member
 
Location: Ca
Member since: Jul 2008, 51 posts
System specs
Ok, here are the combofix and HJT logs
Attached Files
File Type: txt combofix log.txt (21.6 KB, 1 views)
File Type: txt hijackthis log.txt (14.1 KB, 1 views)
  #24  
Old 08-24-2008
xxdanielxx's Avatar
TechSpot Addict
 
Location: Southern CA
Member since: Aug 2006, 1,212 posts
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version. Then reboot into safe mode by rebooting then start tapping the F8 key you will get the advance option select safe mode then load run the program
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
  #25  
Old 08-24-2008
Newcomer, in training
 
Member since: Aug 2008, 3 posts
Trojan/helper.dll/helper.sig

I have the same problem as Dave. Can you check to see if my HJT log is clean. The windows doesn't pop up anymore after I ran malwarebytes twice, and then deleted helper.sig and the folder. However, my computer restarts randomly.

Thanks.
Attached Files
File Type: log hijackthis.log (13.6 KB, 1 views)
File Type: txt mbam-log-08-23-2008 (13-09-53).txt (8.1 KB, 0 views)
File Type: txt mbam-log-08-23-2008 (15-03-52) v2.txt (2.6 KB, 0 views)

Last edited by sharkie21; 08-24-2008 at 11:57 AM.. Reason: Added logs
  #26  
Old 08-24-2008
TechSpot Member
 
Location: Ca
Member since: Jul 2008, 51 posts
System specs
Here is the MBAM log
Attached Files
File Type: txt mbam-log-08-24-2008 (09-16-12).txt (1.4 KB, 10 views)
  #27  
Old 08-24-2008
xxdanielxx's Avatar
TechSpot Addict
 
Location: Southern CA
Member since: Aug 2006, 1,212 posts
HKEY_CLASSES_ROOT\main.bho.1 (Trojan.BHO) -> No action taken.
  #28  
Old 08-24-2008
TechSpot Member
 
Location: Ca
Member since: Jul 2008, 51 posts
System specs
Ok, so what do I do with that and these?

Files Infected:
C:\Program Files\Common\helper.dll (Adware.BHO) -> No action taken.
C:\System Volume Information\_restore{E4FBD1B3-1970-40BB-936B-F702FFF64F9F}\RP1646\A0757445.vxd (Adware.Winad) -> No action taken.
C:\System Volume Information\_restore{E4FBD1B3-1970-40BB-936B-F702FFF64F9F}\RP1648\A0758353.dll (Adware.BHO) -> No action taken.
C:\System Volume Information\_restore{E4FBD1B3-1970-40BB-936B-F702FFF64F9F}\RP1648\A0759353.dll (Adware.BHO) -> No action taken.
C:\System Volume Information\_restore{E4FBD1B3-1970-40BB-936B-F702FFF64F9F}\RP1648\A0760353.dll (Adware.BHO) -> No action taken.
  #29  
Old 08-25-2008
TechSpot Member
 
Location: Ca
Member since: Jul 2008, 51 posts
System specs
I just rebooted and helper.dll is gone but helper.sig and _helper.sig still remain
To remove this ad, sign in. To register for a new account, click here.
  
  #30  
Old 08-25-2008
Newcomer, in training
 
Member since: Aug 2008, 3 posts
Do a Google search for {AFD4AD01-58C1-47DB-A404-FBE00A6C5486}
and follow the link to my blog (it should be one of the first links; probably the second one), where you will find a method to get rid of this pain.

I am not allowed to post links yet, so I have to apologize for the indirect approach.
  #31  
Old 08-26-2008
TechSpot Member
 
Location: Ca
Member since: Jul 2008, 51 posts
System specs
xxdanielxx, any word? Should I trust Metallica and go to his blog? I havent yet...just seems fishy to me
  #32  
Old 08-26-2008
Newcomer, in training
 
Member since: Aug 2008, 3 posts
Ask Daniel who is teacher is at GeekU.

I can't post any direct links because on this board you have to have 5 posts first.
But I have been fighting malware since 2002 and have been awarded by Microsoft with a MVP award.
  #33  
Old 08-26-2008
Newcomer, in training
 
Member since: Aug 2008, 3 posts
Quote:
Originally Posted by PsychoDave View Post
I just rebooted and helper.dll is gone but helper.sig and _helper.sig still remain
Dave, once helper.dll was gone. I just deleted helper.sig and the folder and it never came back. However, I'm not sure if the virus is gone still. I'm trying to get someone to verify my HJT log.
  #34  
Old 08-26-2008
xxdanielxx's Avatar
TechSpot Addict
 
Location: Southern CA
Member since: Aug 2006, 1,212 posts
Quote:
Originally Posted by PsychoDave View Post
xxdanielxx, any word? Should I trust Metallica and go to his blog? I havent yet...just seems fishy to me
Yes
  #35  
Old 08-27-2008
TechSpot Member
 
Location: Ca
Member since: Jul 2008, 51 posts
System specs
Cool, Ill head over there and check it out...


Ok, got the program and script and ran it...here is the log
Attached Files
File Type: txt BFUlogdeepdive.txt (1.5 KB, 2 views)

Last edited by PsychoDave; 08-27-2008 at 02:01 AM..
  #36  
Old 08-27-2008
TechSpot Member
 
Location: Ca
Member since: Jul 2008, 51 posts
System specs
Its gone!! Finally! Thank you xxdanielxx and Metallica! I really appreciate it! Sharkie, go to Metallicas blog to remove helper.dll and .sig. If you have any other bugs get the programs xxdanielxx told me to do and run them.

Again, thank you both!!!
  #37  
Old 08-27-2008
Newcomer, in training
 
Member since: Aug 2008, 3 posts
You're welcome.
  #38  
Old 08-28-2008
xxdanielxx's Avatar
TechSpot Addict
 
Location: Southern CA
Member since: Aug 2006, 1,212 posts
anytime I will be back after I am done with training.
  #39  
Old 12-12-2008
Kindwoman's Avatar
Newcomer, in training
 
Location: Gloucester, VA
Member since: Sep 2007, 25 posts
System specs
Me too

Hi, I have been struggling with the same problem! Is there someone who could give me some advice as what to do please? My computer's performance is getting worse and worse.


I just ran hijackthis and am attaching the log file. Please could someone take a look at it!
Attached Files
File Type: txt hijackthis 12-12-08.txt (9.0 KB, 1 views)

Last edited by Kindwoman; 12-12-2008 at 10:11 AM..
  #40  
Old 12-12-2008
TechSpot Booster
 
Location: Illinois, USA
Member since: Feb 2007, 908 posts
System specs
Please open a new thread for your computer problem. Be specific about the symptoms you're seeing
Quote:
Closed Thread
Page 2 of 3 1 2 3

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Please help me. I have 2 trojans :( Virus & Malware removal 6 05-15-2007 05:00 PM
Trojans! Virus & Malware removal 3 04-03-2007 03:22 PM
IM trojans on net ... Virus & Malware removal 8 02-13-2007 09:42 PM
Trojans R Us atm lol Virus & Malware removal 9 10-23-2006 06:32 PM
A BHO ( Browser helper object) Virus & Malware removal 2 10-23-2006 07:48 AM


All times are GMT -4. The time now is 07:31 PM.