![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Security and Firewalls Protecting you against unwanted people and programs |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Aug 2009
Posts: 1
OS: XP SP3
|
Hello all,
I have a problem, just noticed today, not sure how long it's been there. My machine is an XP SP3 (tablet edition if that matters), on a home network with 2 computers with cable internet. I'm running Avast 4.8. This morning, Avast alerted me to a virus in the HelpAssistant account folder for temporary internet files (C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5). I had never heard of this account, but I've learned it's the RDP account. Anyway, I noticed that the TemporaryInternetFiles folder was growing at an alarming rate, about 3MB per minute. Looking in there were the standard files, some html, .js, etc, nothing unusual...but rapidly growing. Alarmed, I went to disable the account, and turned up the logging in event viewer. Someone with NTAUTHORITY/SYSTEM keeps re-enabling the account. I tried changing password, same thing, NTAUTHORITY/SYSTEM changes the password again, and then I start getting thousands of internet files. Is this normal? I tried deleting old accounts, changing the Administrator logon, but nothing helps...is a trojan doing this? What steps can I do to identify and remove it? Or is it sombody logging in from the outside? thanks in advance, any thoughts would be appreciated. -Jim |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#3 (permalink) |
|
Registered User
Join Date: Oct 2009
Location: Dutch, but living in Spain
Posts: 3
OS: WinXP SP3
|
Re: HelpAssistant Account hacked?
Hi, I'm having the same problem. Don't know how to disable the HelpAssistant, so I deleted it using "net user HelpAssistant /Delete". That works but after rebooting the directory C:\Documents and Settings\HelpAssistant is back and growing ...
Anyone? Thanks! |
|
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 2
OS: XP SP3
|
Re: HelpAssistant Account hacked?
Hello,
the problem it's a trojan (win32.mebroot.bz) that install itself in the mbr. Just start XP recovery console from XP CD and run fixmbr. After a reboot, disable HelpAssistant account and remove it from Administrators group. |
|
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Oct 2009
Location: Dutch, but living in Spain
Posts: 3
OS: WinXP SP3
|
Re: HelpAssistant Account hacked?
Thanks Pitta322,
But running fixmbr reports: " *** Caution *** This computer appears to have a non-standard or invalid master boot reord. FIXMBR may damage your partition tables if you proceed. This could cause all the partitions on the current hard disk to become inaccessible. If you're not having problems accessing your drive do not continue. " Chicken? Me? Might be, but what if indeed all the partitions on my hard disk become inaccessible?
|
|
|
|
|
|
#8 (permalink) |
|
Manager, Networking Forums
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 41,580
OS: Windows 7, XP-Pro, Vista, Linux
Blog Entries: 1
|
Re: HelpAssistant Account hacked?
If you have used a 3rd partitioning program to format the disk, the FIXMBR command will nuke the partition! That warning is correct!
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up! Microsoft MVP - Windows Desktop Experience |
|
|
|
|
|
#9 (permalink) |
|
Registered User
Join Date: Oct 2009
Location: Dutch, but living in Spain
Posts: 3
OS: WinXP SP3
|
If I am a chicken, I'm a brave one!
![]() The FIXMBR did work ok, the HelpAssistant user did not appear again and my disc seems pretty ok. Thank you all!
|
|
|
|
![]() |
| Thread Tools | |
|
|