Reply
i7
Contributor
i7
Posts: 54
Registered: ‎11-08-2008

92869.rhelper.com

Encountered this on a pc running up to date NIS2009.  Full system scan finds nothing.  Should NIS2009 defs find/fix this?  It continually tries to connect to this site on port 8653.  See ThreatExpert report.

http://www.threatexpert.com/report.aspx?uid=a215e3a2-02ed-489b-a8f2-6b9f78c1ff44

 

How can I remove this garbage?

Regular Contributor
Compumind
Posts: 892
Registered: ‎10-08-2008

Re: 92869.rhelper.com

[ Edited ]

Hi i7 -

 

Weird! It should, judging by the older date of this.

 

Download, Install and Update - Malwarebyte's AntiMalware - www.malwarebytes.org - disconnect from the Internet and run a complete system scan.

 

Let's see if MBAM picks it up and throws it into Quarantine. If so, then delete it.

 

Did *you* submit this to ThreatExpert?  Additionally, If you can get to the actual file also submit it at:

 

https://submit.symantec.com/websubmit/retail.cgi

 

Let us know what the result is.

 

 :smileysurprised:

Message Edited by Compumind on 05-26-2009 03:06 PM

Compumind

NIS 2009, XP-SP3, Vista-SP2, IE 8

i7
Contributor
i7
Posts: 54
Registered: ‎11-08-2008

Re: 92869.rhelper.com

Have run MBAM, SAS and Spybot and nothing flags.  I did not submit it as it appears exactly the same as the one previously posted on ThreatExpert.  Unfortunately I deleted the primary file but stopped short of doing anything further (such as registry edits).
Regular Contributor
Compumind
Posts: 892
Registered: ‎10-08-2008

Re: 92869.rhelper.com

[ Edited ]

Hi i7 -

 

Ok. Let's then try this:

 

http://www.emsisoft.com/en/software/stick/

 

We will evaluate from there.

 

TIA :smileysurprised:

Message Edited by Compumind on 05-26-2009 03:12 PM

Compumind

NIS 2009, XP-SP3, Vista-SP2, IE 8

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: 92869.rhelper.com

[ Edited ]

Try a Hijackthis log to see if there is anything it was attached to that might still be there.  When you ran the MBAM did you disable system restore?

 

http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

 

You could paste it here for one of the pros to have a look at.

Message Edited by delphinium on 05-26-2009 12:14 PM
Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Regular Contributor
Compumind
Posts: 892
Registered: ‎10-08-2008

Re: 92869.rhelper.com

[ Edited ]

Hi i7 -

 

The 8653 port is a valid TCP, UDP number.

 

How do you *know* that it is trying to connect, if NIS 2009 (and others) do not detect it?

 

Please also visit this site and run all the Port tests -  https://www.grc.com/x/ne.dll?bh0bkyd2 - are these in "stealth" mode?

 

Again, let us know. We will check the System Restore Points, after this is complete.

 

Thanks.

 

:smileyindifferent:

Message Edited by Compumind on 05-26-2009 03:24 PM

Compumind

NIS 2009, XP-SP3, Vista-SP2, IE 8

i7
Contributor
i7
Posts: 54
Registered: ‎11-08-2008

Re: 92869.rhelper.com

Firewall logs show the connection occurs every 2min.  Netstat also shows the outgoing connection on port 8653.  Have captured the IP it is going to (in China).  Connection is through a router.  NIS firewall is not blocking it. 

 

Will not have access to the infected computer until later today.

Regular Contributor
Compumind
Posts: 892
Registered: ‎10-08-2008

Re: 92869.rhelper.com

Hi i7 -

 

OK. Please let us know.

 

BTW - What operating system are you using?

 

:smileyindifferent:

Compumind

NIS 2009, XP-SP3, Vista-SP2, IE 8

i7
Contributor
i7
Posts: 54
Registered: ‎11-08-2008

Re: 92869.rhelper.com

fully patched XP SP3.  System restore was turned off then back on so no old restore points
Regular Contributor
Compumind
Posts: 892
Registered: ‎10-08-2008

Re: 92869.rhelper.com

[ Edited ]

Hi I7 -

 

Good - so please follow the steps in order (that you have not done yet) so we could isolate and eradicate.

 

Look forward to hearing from you.

 

TIA

 

:smileyhappy:

 

BTW - has any "weird" software been installed on this computer, lately?

Message Edited by Compumind on 05-26-2009 04:00 PM

Compumind

NIS 2009, XP-SP3, Vista-SP2, IE 8