If You Have DealHelper, Then You Need Help
If you have a new toolbar in your Internet browser called DealHelper, then you have been infected with adware. DealHelper is a browser helper object that monitors your Internet activities and then delivers pop-up ads based on the content that you have been viewing and searching for.
DealHelper, like other adware programs, is annoying and will cause your computer to perform inefficiently. Plus, since it is usually installed without the permission, it should be removed immediately.
In order to manually remove DealHelper, the following processes need to be killed using Windows Task Manager:
c:\virtue\350757\dealhelper.exe
[program files]\dealhelper.com
inc\dealhelper\setup.exe
[program files]\timesync\setup.exe
[system root]\dhbrwsr.exe
[system root]\dhsvr.exe
[system root]\dhun.exe
[system root]\dhupdt.exe
[system root]\edow.exe
[system root]\system32\dp-him.exe
[system root]\system32\dp-k13w13.exe
[system root]\timesynchronize.exe
[system root]\uninstall.exe
updater.exe
You will also need to delete the following registries:
HKEY_CLASSES_ROOT\appid\{a1f53f1d-fb2d-4fe0-8ee8-7bbe69999d9f}
HKEY_CLASSES_ROOT\appid\{a57afb0f-c63e-4ae2-8a7b-bca01ba32cc5}
HKEY_CLASSES_ROOT\clsid\{1a2883f2-fdc7-4af2-b136-203adb475dd7}
HKEY_CLASSES_ROOT\clsid\{54a41ae7-b358-4d41-98bd-bbbffdf5186b}
HKEY_CLASSES_ROOT\clsid\{5e3e1dc0-239a-4067-a4a0-88902c108e58}
HKEY_CLASSES_ROOT\clsid\{6dd8b352-21a7-4c24-ac49-e9b4730c1823}
HKEY_CLASSES_ROOT\clsid\{7bc3ec59-a4a0-4638-a3bf-c20b0665947f}
HKEY_CLASSES_ROOT\clsid\{8b477303-698c-4eed-b9f6-c715842fbe33}
HKEY_CLASSES_ROOT\clsid\{8ee1aaf5-ed6b-4601-b333-cd30ffb8b39d}
HKEY_CLASSES_ROOT\clsid\{b8e910b5-7452-4a29-b121-08e8cf09ec07}
HKEY_CLASSES_ROOT\clsid\{bfef1779-0e92-45a1-bf5e-55991007f912}
HKEY_CLASSES_ROOT\clsid\{d848a3ca-0bfb-4de0-ba9e-a57f0cca1c13}
HKEY_CLASSES_ROOT\clsid\{f00586de-a432-4b9f-877d-e29cd87efdd6}
HKEY_CLASSES_ROOT\clsid\{fe4bbea8-1efd-4b8a-bd1b-341ccdbeeaa6}
HKEY_CLASSES_ROOT\dealhlpr.band
HKEY_CLASSES_ROOT\dealhlpr.band.1
HKEY_CLASSES_ROOT\dealhlpr.band\clsid
HKEY_CLASSES_ROOT\dealhlpr.band\curver
HKEY_CLASSES_ROOT\dealpop.cdealhelperpopup
HKEY_CLASSES_ROOT\dealpop.cdealhelperpopup.1
HKEY_CLASSES_ROOT\dealpop.cdealhelperpopup\clsid
HKEY_CLASSES_ROOT\dealpop.cdealhelperpopup\curver
HKEY_CLASSES_ROOT\dealpop.dealpopevents
HKEY_CLASSES_ROOT\dealpop.dealpopevents.1
HKEY_CLASSES_ROOT\dealpop.dealpopevents\clsid
HKEY_CLASSES_ROOT\dealpop.dealpopevents\curver
HKEY_CLASSES_ROOT\dhbrwsr.browserwindows
HKEY_CLASSES_ROOT\dhbrwsr.browserwindows.1
HKEY_CLASSES_ROOT\dhbrwsr.browserwindows\clsid
HKEY_CLASSES_ROOT\dhbrwsr.browserwindows\curver
HKEY_CLASSES_ROOT\dhp.dhevents
HKEY_CLASSES_ROOT\dhp.dhevents.1
HKEY_CLASSES_ROOT\dhp.dhevents\clsid
HKEY_CLASSES_ROOT\dhp.dhevents\curver
HKEY_CLASSES_ROOT\dhp.popup
HKEY_CLASSES_ROOT\dhp.popup.1
HKEY_CLASSES_ROOT\dhp.popup\clsid
HKEY_CLASSES_ROOT\dhp.popup\curver
HKEY_CLASSES_ROOT\dhsigned.dhsignedctrl.1
HKEY_CLASSES_ROOT\dhsvr.cfiledatabase
HKEY_LOCAL_MACHINE\software\classes\interface\{f3816084-9608-485a-b63b-cad8f931577e}
HKEY_LOCAL_MACHINE\software\classes\typelib\{25ab1639-3f81-45a8-8318-2dafba8b8f3d}
HKEY_LOCAL_MACHINE\software\classes\typelib\{4b76f69e-247a-4617-aba9-95774658afc5}
HKEY_LOCAL_MACHINE\software\classes\typelib\{5e19a321-635e-4ba5-8828-a5b6427cc61d}
HKEY_LOCAL_MACHINE\software\classes\typelib\{771262e0-8feb-4e78-b292-b01c4071b9d1}
HKEY_LOCAL_MACHINE\software\classes\typelib\{b82b9ecf-40ae-46f2-b98e-b87cf17f70d0}
HKEY_LOCAL_MACHINE\software\classes\typelib\{c2e2f4d7-2c20-492f-b179-d15ff876ab83}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{fe4bbea8-1efd-4b8a-bd1b-341ccdbeeaa6}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{fe4bbea8-1efd-4b8a-bd1b-341ccdbeeaa6}\installer
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{fe4bbea8-1efd-4b8a-bd1b-341ccdbeeaa6}\systemcomponent
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{d848a3ca-0bfb-4de0-ba9e-a57f0cca1c13}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d848a3ca-0bfb-4de0-ba9e-a57f0cca1c13}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/dhsigned.ocx\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/dhsigned.ocx\{fe4bbea8-1efd-4b8a-bd1b-341ccdbeeaa6}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\dealhelperbrwsr
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\dealhelperupdate
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\dsi
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\timesyncapp
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\contact
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\displayversion
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\helplink
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\installdate
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\installlocation
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\installsource
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\publisher
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\urlinfoabout
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\urlupdateinfo
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\versionmajor
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\timesync\versionminor
HKEY_CLASSES_ROOT\dhsvr.cfiledatabase.1
HKEY_CLASSES_ROOT\dhsvr.cfiledatabase\clsid
HKEY_CLASSES_ROOT\dhsvr.cfiledatabase\curver
HKEY_CLASSES_ROOT\dhsvr.dbhelper
HKEY_CLASSES_ROOT\dhsvr.dbhelper.1
HKEY_CLASSES_ROOT\dhsvr.dbhelper\clsid
HKEY_CLASSES_ROOT\dhsvr.dbhelper\curver
HKEY_CLASSES_ROOT\dhsvr.even
HKEY_CLASSES_ROOT\dhsvr.even.1
HKEY_CLASSES_ROOT\dhsvr.even\clsid
HKEY_CLASSES_ROOT\dhsvr.even\curver
HKEY_CLASSES_ROOT\dhsvr.webdealevents
HKEY_CLASSES_ROOT\dhsvr.webdealevents.1
HKEY_CLASSES_ROOT\dhsvr.webdealevents\clsid
HKEY_CLASSES_ROOT\dhsvr.webdealevents\curver
HKEY_CLASSES_ROOT\interface\{06e53101-654c-45eb-bff6-e37e13b5972a}
HKEY_CLASSES_ROOT\interface\{0b16b278-b2e3-4cbf-85b5-e058878f728f}
HKEY_CLASSES_ROOT\interface\{1da40091-14b4-4c21-8170-a2ceede90b10}
HKEY_CLASSES_ROOT\interface\{3afae37a-56a3-4850-b599-4da9a9104b82}
HKEY_CLASSES_ROOT\interface\{3d89a731-9f4a-418f-a997-2d633c7c404c}
HKEY_CLASSES_ROOT\interface\{81739076-56b7-42ec-a0aa-692794fded1a}
HKEY_CLASSES_ROOT\interface\{a2cdafb4-eb9c-4efc-bcfc-a7aa6745ff7e}
HKEY_CLASSES_ROOT\interface\{b5146c72-3328-4240-97ed-3a23dcb656cf}
HKEY_CLASSES_ROOT\interface\{bf9ee3a0-1a02-4265-a65f-ac4d4447f6bf}
HKEY_CLASSES_ROOT\interface\{c2e6831b-822b-4a1f-9ef1-1d3eb7d3e985}
HKEY_CLASSES_ROOT\interface\{c9679631-7060-443f-bd37-88f9410ed8c3}
HKEY_CLASSES_ROOT\interface\{deba1742-2bec-4b78-a987-5837971193f7}
HKEY_CLASSES_ROOT\interface\{e9468a08-f790-48ce-ad30-eadeeab9b40c}
HKEY_CLASSES_ROOT\interface\{f3816084-9608-485a-b63b-cad8f931577e}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{d848a3ca-0bfb-4de0-ba9e-a57f0cca1c13}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\dealhelperdown
HKEY_LOCAL_MACHINE\software\classes\appid\{a1f53f1d-fb2d-4fe0-8ee8-7bbe69999d9f}
HKEY_LOCAL_MACHINE\software\classes\appid\{a57afb0f-c63e-4ae2-8a7b-bca01ba32cc5}
HKEY_LOCAL_MACHINE\software\classes\appid\dhbrwsr.exe\appid
HKEY_LOCAL_MACHINE\software\classes\appid\dhsvr.exe\appid
HKEY_LOCAL_MACHINE\software\classes\clsid\{1a2883f2-fdc7-4af2-b136-203adb475dd7}
HKEY_LOCAL_MACHINE\software\classes\clsid\{54a41ae7-b358-4d41-98bd-bbbffdf5186b}
HKEY_LOCAL_MACHINE\software\classes\clsid\{54a41ae7-b358-4d41-98bd-bbbffdf5186b}\appid
HKEY_LOCAL_MACHINE\software\classes\clsid\{5e3e1dc0-239a-4067-a4a0-88902c108e58}
HKEY_LOCAL_MACHINE\software\classes\clsid\{6dd8b352-21a7-4c24-ac49-e9b4730c1823}
HKEY_LOCAL_MACHINE\software\classes\clsid\{6dd8b352-21a7-4c24-ac49-e9b4730c1823}\appid
HKEY_LOCAL_MACHINE\software\classes\clsid\{7bc3ec59-a4a0-4638-a3bf-c20b0665947f}
HKEY_LOCAL_MACHINE\software\classes\clsid\{8b477303-698c-4eed-b9f6-c715842fbe33}
HKEY_LOCAL_MACHINE\software\classes\clsid\{8ee1aaf5-ed6b-4601-b333-cd30ffb8b39d}
HKEY_LOCAL_MACHINE\software\classes\clsid\{8ee1aaf5-ed6b-4601-b333-cd30ffb8b39d}\appid
HKEY_LOCAL_MACHINE\software\classes\clsid\{b8e910b5-7452-4a29-b121-08e8cf09ec07}
HKEY_LOCAL_MACHINE\software\classes\clsid\{b8e910b5-7452-4a29-b121-08e8cf09ec07}\appid
HKEY_LOCAL_MACHINE\software\classes\clsid\{bfef1779-0e92-45a1-bf5e-55991007f912}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d848a3ca-0bfb-4de0-ba9e-a57f0cca1c13}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f00586de-a432-4b9f-877d-e29cd87efdd6}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f00586de-a432-4b9f-877d-e29cd87efdd6}\appid
HKEY_LOCAL_MACHINE\software\classes\clsid\{fe4bbea8-1efd-4b8a-bd1b-341ccdbeeaa6}
HKEY_LOCAL_MACHINE\software\classes\interface\{06e53101-654c-45eb-bff6-e37e13b5972a}
HKEY_LOCAL_MACHINE\software\classes\interface\{0b16b278-b2e3-4cbf-85b5-e058878f728f}
HKEY_LOCAL_MACHINE\software\classes\interface\{1da40091-14b4-4c21-8170-a2ceede90b10}
HKEY_LOCAL_MACHINE\software\classes\interface\{3afae37a-56a3-4850-b599-4da9a9104b82}
HKEY_LOCAL_MACHINE\software\classes\interface\{3d89a731-9f4a-418f-a997-2d633c7c404c}
HKEY_LOCAL_MACHINE\software\classes\interface\{81739076-56b7-42ec-a0aa-692794fded1a}
HKEY_LOCAL_MACHINE\software\classes\interface\{a2cdafb4-eb9c-4efc-bcfc-a7aa6745ff7e}
HKEY_LOCAL_MACHINE\software\classes\interface\{b5146c72-3328-4240-97ed-3a23dcb656cf}
HKEY_LOCAL_MACHINE\software\classes\interface\{bf9ee3a0-1a02-4265-a65f-ac4d4447f6bf}
HKEY_LOCAL_MACHINE\software\classes\interface\{c2e6831b-822b-4a1f-9ef1-1d3eb7d3e985}
HKEY_LOCAL_MACHINE\software\classes\interface\{c9679631-7060-443f-bd37-88f9410ed8c3}
HKEY_LOCAL_MACHINE\software\classes\interface\{deba1742-2bec-4b78-a987-5837971193f7}
HKEY_LOCAL_MACHINE\software\classes\interface\{e9468a08-f790-48ce-ad30-eadeeab9b40c}
On top of this, you need to delete the following files:
7.13.2004.11.32.58….0.reg
c:\virtue\350757\dealhelper.exe
[common programs]\dealhelper\uninstall dealhelper.lnk
dealhelper.com.txt
dhbrwsr.exe-35ded8aa.pf
[profile path]\locals~1\temp\_setupx.dll
[program files]\dealhelper.com inc\dealhelper\_setupx.dll
[program files]\dealhelper.com inc\dealhelper\setup.exe
[program files]\dealhelper.com inc\dealhelper\setup.ini
[program files]\timesync\_setupx.dll
[program files]\timesync\setup.exe
[program files]\timesync\setup.ini
[system root]\appsinstalled.htm
[system root]\dealhlpr.dll
[system root]\dhbrwsr.exe
[system root]\dhdom.bin
[system root]\dhdomp.bin
[system root]\dhkw.bin
[system root]\dhp.dll
[system root]\dhp2.dll
[system root]\dhsigned.ocx
[system root]\dhsvr.exe
[system root]\dhun.exe
[system root]\dhupdt.exe
[system root]\dsearch.bin
[system root]\edow.exe
[system root]\system\dealhlpr.dll
[system root]\system32\dealhlpr.dll
[system root]\system32\dp-him.exe
[system root]\system32\dp-k13w13.exe
[system root]\timesynchronize.exe
[system root]\uninstall.exe updater.exe updater.exe-0be15c50.pf
Of course, deleting all of that stuff would take a very long time and you might mistakenly delete something that you are not supposed to. Therefore, manual removal would also be dangerous.
Instead of removing DealHelper manually, you should use SpyZooka. SpyZooka is the only antispyware program that has a 100% spyware removal guarantee. It will do the work for you and get your computer back to a healthy state.