Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Security and Firewalls Protecting you against unwanted people and programs

Reply
 
LinkBack Thread Tools
Old 08-22-2009, 07:58 PM   #1 (permalink)
Registered User
 
Join Date: Aug 2009
Posts: 1
OS: XP SP3


EEK! HelpAssistant Account hacked?

Hello all,

I have a problem, just noticed today, not sure how long it's been there.

My machine is an XP SP3 (tablet edition if that matters), on a home network with 2 computers with cable internet.

I'm running Avast 4.8.

This morning, Avast alerted me to a virus in the HelpAssistant account folder for temporary internet files (C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5). I had never heard of this account, but I've learned it's the RDP account. Anyway, I noticed that the TemporaryInternetFiles folder was growing at an alarming rate, about 3MB per minute. Looking in there were the standard files, some html, .js, etc, nothing unusual...but rapidly growing.

Alarmed, I went to disable the account, and turned up the logging in event viewer. Someone with NTAUTHORITY/SYSTEM keeps re-enabling the account. I tried changing password, same thing, NTAUTHORITY/SYSTEM changes the password again, and then I start getting thousands of internet files.

Is this normal?

I tried deleting old accounts, changing the Administrator logon, but nothing helps...is a trojan doing this? What steps can I do to identify and remove it? Or is it sombody logging in from the outside?

thanks in advance, any thoughts would be appreciated.

-Jim
JimOliver is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 08-25-2009, 02:54 PM   #2 (permalink)
Registered User
 
Suncoast's Avatar
 
Join Date: Jul 2009
Location: Largo, FL, USA
Posts: 389
OS: XPP, Linux, 2003, Cisco


Re: HelpAssistant Account hacked?

You should be in one of the Security Forums Here.

http://www.techsupportforum.com/security-center/
Suncoast is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-28-2009, 07:08 AM   #3 (permalink)
Registered User
 
Join Date: Oct 2009
Location: Dutch, but living in Spain
Posts: 3
OS: WinXP SP3


Re: HelpAssistant Account hacked?

Hi, I'm having the same problem. Don't know how to disable the HelpAssistant, so I deleted it using "net user HelpAssistant /Delete". That works but after rebooting the directory C:\Documents and Settings\HelpAssistant is back and growing ...
Anyone? Thanks!
Madimad is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-29-2009, 01:16 AM   #4 (permalink)
Registered User
 
Join Date: Oct 2009
Posts: 1
OS: Xp Sp3


Re: HelpAssistant Account hacked?

I have the same problem, there is a solution?
lepr8 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-29-2009, 04:26 AM   #5 (permalink)
Registered User
 
Join Date: Oct 2009
Posts: 2
OS: XP SP3


Re: HelpAssistant Account hacked?

Hello,
the problem it's a trojan (win32.mebroot.bz) that install itself in the mbr.
Just start XP recovery console from XP CD and run fixmbr.
After a reboot, disable HelpAssistant account and remove it from Administrators group.
Pitta322 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-30-2009, 04:10 AM   #6 (permalink)
Registered User
 
Join Date: Oct 2009
Location: Dutch, but living in Spain
Posts: 3
OS: WinXP SP3


Re: HelpAssistant Account hacked?

Thanks Pitta322,
But running fixmbr reports:
" *** Caution ***
This computer appears to have a non-standard or invalid master boot reord.
FIXMBR may damage your partition tables if you proceed.
This could cause all the partitions on the current hard disk to become
inaccessible.
If you're not having problems accessing your drive do not continue. "

Chicken? Me? Might be, but what if indeed all the partitions on my hard disk become inaccessible?
Madimad is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-30-2009, 07:05 AM   #7 (permalink)
Registered User
 
Join Date: Oct 2009
Posts: 2
OS: XP SP3


Re: HelpAssistant Account hacked?

Madimad,
I NEVER lose any data answering Yes to a fixmbr command.
In any case, if you can do a backup before it will be better.
Pitta322 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-30-2009, 08:09 AM   #8 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 41,580
OS: Windows 7, XP-Pro, Vista, Linux


Blog Entries: 1
Re: HelpAssistant Account hacked?

If you have used a 3rd partitioning program to format the disk, the FIXMBR command will nuke the partition! That warning is correct!
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 10-30-2009, 09:38 AM   #9 (permalink)
Registered User
 
Join Date: Oct 2009
Location: Dutch, but living in Spain
Posts: 3
OS: WinXP SP3


Thumbs Up Re: HelpAssistant Account hacked?

If I am a chicken, I'm a brave one!
The FIXMBR did work ok, the HelpAssistant user did not appear again and my disc seems pretty ok.
Thank you all!
Madimad is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 08:56 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85