Author Message

๑۞๑

Joined: 11 Apr 2002
Posts: 5711
Location: miami

 Posted: Thu Apr 08, 2004 0:55 am    Post subject: What I did when I got HJed is install RegCleaner (Free) and delete to back-up any suspicious program. Then I went to the start-up folder in RC and sent suspicious items to the back-up folder (so I could easily put them back if I messed up). I had to send about 4 at a time until I found the booger and then put the rest back. It seems that you have something re-installing this program each time you boot up and until you get the thing out of your start-up, I think it will keep reappearing.

Joined: 08 Dec 2003
Posts: 204

 Posted: Thu Apr 08, 2004 7:27 am    Post subject: Please submit entries here  http://www.lavahelp.com/submit/index.html  C:\PROGRAM FILES\ARES\ARES.EXE You may need to be in Safe Mode to find it. Close all open windows, put a check beside these entries, Fixed Check R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html O4 - HKCU\..\Run: [ares] "C:\PROGRAM FILES\ARES\ARES.EXE" -h REBOOT Go to these folder(s) and delete C:\PROGRAM FILES\ARES\ARES.EXE (entire ARES folder) Some free programs that will help you not get infected Spywareblaster:  www.javacoolsoftware.com  IE-Spyads:  http://www.staff.uiuc.edu/~ehowes/resource.htm  Also, paid versions of Ad-aware 6 (Plus) will prevent re-infection, BTW I am a volunteer for Ad-aware

Joined: 18 Jan 2001
Posts: 13529
Location: Upstate, NY

Posted: Thu Apr 08, 2004 7:32 am    Post subject:

 normmork wrote: BTW I am a volunteer for Ad-aware
And a very appreciated member here at

_________________
Freedomlist.com (March 1, 2000 - 2013)

Take a walk through my Security Garden

Malware Response Team

Joined: 01 Mar 2004
Posts: 481
Location: Somewhere along Tobacco Road, North Carolina

 Posted: Thu Apr 08, 2004 7:58 am    Post subject: In addition to SpywareBlaster 3.1 and IE-Spyad (both of which I have installed on every one of my computers) ... Also consider the companion program SpywareGuard 2.2:  http://www.javacoolsoftware.com/spywareguard.html _________________Speak softly, but carry a Winchester Member of , the Alliance of Security Analysis Professionals

Joined: 08 Dec 2003
Posts: 204

 Posted: Thu Apr 08, 2004 9:14 am    Post subject: winchester 73 Spywareguard is freeware md55- A new refernce file was released yesterday for Ad-aware 6, please use the globe icon in AA6 to update it.

Joined: 04 Apr 2004
Posts: 104

 Posted: Thu Apr 08, 2004 11:17 am    Post subject: These two files keep on coming back. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html They dont' appear right after reboot. It takes them a few min after before they take over teh home page again. I installed the spyblaster program you said of. Any thoughts on this hijacking?

Joined: 18 Jan 2001
Posts: 13529
Location: Upstate, NY

 Posted: Thu Apr 08, 2004 11:40 am    Post subject: So they can get a full picture, please post a new HJT log. And, don't worry, even if it takes a while to get to the bottom of this, they have other resources _________________Freedomlist.com (March 1, 2000 - 2013) Take a walk through my Security Garden

Joined: 08 Dec 2003
Posts: 204

 Posted: Thu Apr 08, 2004 11:53 am    Post subject: Try removing them in Windows Safe MOde  http://service1.symantec.com/SUPPORT/tsgen...2409420406  Look for a file called autorun.inf and rename it to autorun.bak, this is a bit of a long shot. aLOS STARTER.CHM OR STARTER.EXE MAke sure you have all the Windows security and IE updates for your OS installed Please clean out all cookies, internet temp folder, and temp folder

Joined: 04 Apr 2004
Posts: 104

 Posted: Thu Apr 08, 2004 16:59 pm    Post subject: Sorry, can you clarify what you want with the files STARTER.CHM and STARTER.EXE I'll go do what you want now and I'll post a new log after.

Joined: 18 Jan 2001
Posts: 13529
Location: Upstate, NY

 Posted: Thu Apr 08, 2004 17:10 pm    Post subject: I believe he would like you to search for those files -- as they may be lurking someplace._________________Freedomlist.com (March 1, 2000 - 2013) Take a walk through my Security Garden
Guest

Guest

 Posted: Thu Apr 08, 2004 17:16 pm    Post subject: I found the files STARTER.EXE but not STARTER.CHM. Should I delete them?

Joined: 18 Jan 2001
Posts: 13529
Location: Upstate, NY

 Posted: Thu Apr 08, 2004 17:27 pm    Post subject: md55, please submit that starter.exe file as you did the others to  http://www.lavahelp.com/submit/index.html.  I'm not sure who is going to be online tonight, but will leave them a message that you've posted._________________Freedomlist.com (March 1, 2000 - 2013) Take a walk through my Security Garden
Guest

Joined: 18 Jan 2001
Posts: 13529
Location: Upstate, NY

Posted: Thu Apr 08, 2004 17:49 pm    Post subject:

Your complete logfile didn't post. Please pick up from here and post to the Summary.

 Quote: Winpup32 Object recognized! Type : File Data : hellexts.exe Category : Malware Comment : Object : C:\WINDOWS\SYSTEM\ FileSize : 64 KB Copyright : <

Thanks.
_________________
Freedomlist.com (March 1, 2000 - 2013)

Take a walk through my Security Garden
Guest

 Posted: Thu Apr 08, 2004 17:57 pm    Post subject: it ends there though, I don't know why.

Joined: 18 Jan 2001
Posts: 13529
Location: Upstate, NY

 Posted: Thu Apr 08, 2004 18:28 pm    Post subject: Go to C:\Program Files\Lavasoft\Ad-aware 6\Logs and find the logfile with today's date. Double click to open it, click Edit | Select all, Edit | Copy. Then post the logfile as a reply._________________Freedomlist.com (March 1, 2000 - 2013) Take a walk through my Security Garden
Guest

Guest

 Posted: Thu Apr 08, 2004 21:33 pm    Post subject: DAMNIT!!! i got the same start.chm and start.html problem this is the only place that talking about this hijack??? i delete those 2 files and they keep popping back up plz help fast!!! or i could just reformat
Guest

 Posted: Thu Apr 08, 2004 21:37 pm    Post subject: it changes your homepage to a place that has advertisements and all of them lead to master-search.com and u know its a stupid site cuz when u go to the main website, it says "having problems with our program? use this to remove it. you will need to leave it open for 2 hours to remove the file." meaning its probably a dialer or something
 All times are GMT - 5 HoursGoto page Previous  1, 2, 3, 4, 5  Next