 Posted: Thu Apr 08, 2004 0:55 am    Post subject: What I did when I got HJed is install RegCleaner (Free) and delete to back-up any suspicious program. Then I went to the start-up folder in RC and sent suspicious items to the back-up folder (so I could easily put them back if I messed up). I had to send about 4 at a time until I found the booger and then put the rest back. It seems that you have something re-installing this program each time you boot up and until you get the thing out of your start-up, I think it will keep reappearing.

 Posted: Thu Apr 08, 2004 7:27 am    Post subject: Please submit entries here  http://www.lavahelp.com/submit/index.html  C:\PROGRAM FILES\ARES\ARES.EXE You may need to be in Safe Mode to find it. Close all open windows, put a check beside these entries, Fixed Check R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html O4 - HKCU\..\Run: [ares] "C:\PROGRAM FILES\ARES\ARES.EXE" -h REBOOT Go to these folder(s) and delete C:\PROGRAM FILES\ARES\ARES.EXE (entire ARES folder) Some free programs that will help you not get infected Spywareblaster:  www.javacoolsoftware.com  IE-Spyads:  http://www.staff.uiuc.edu/~ehowes/resource.htm  Also, paid versions of Ad-aware 6 (Plus) will prevent re-infection, BTW I am a volunteer for Ad-aware

 normmork wrote: BTW I am a volunteer for Ad-aware
And a very appreciated member here at

 In addition to SpywareBlaster 3.1 and IE-Spyad (both of which I have installed on every one of my computers) ... Also consider the companion program SpywareGuard 2.2:  http://www.javacoolsoftware.com/spywareguard.html

 Posted: Thu Apr 08, 2004 9:14 am    Post subject: winchester 73 Spywareguard is freeware md55- A new refernce file was released yesterday for Ad-aware 6, please use the globe icon in AA6 to update it.

 Posted: Thu Apr 08, 2004 11:17 am    Post subject: These two files keep on coming back. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\start.chm::/start.html They dont' appear right after reboot. It takes them a few min after before they take over teh home page again. I installed the spyblaster program you said of. Any thoughts on this hijacking?

 So they can get a full picture, please post a new HJT log. And, don't worry, even if it takes a while to get to the bottom of this, they have other resources

 Posted: Thu Apr 08, 2004 11:53 am    Post subject: Try removing them in Windows Safe MOde  http://service1.symantec.com/SUPPORT/tsgen...2409420406  Look for a file called autorun.inf and rename it to autorun.bak, this is a bit of a long shot. aLOS STARTER.CHM OR STARTER.EXE MAke sure you have all the Windows security and IE updates for your OS installed Please clean out all cookies, internet temp folder, and temp folder

 Posted: Thu Apr 08, 2004 16:59 pm    Post subject: Sorry, can you clarify what you want with the files STARTER.CHM and STARTER.EXE I'll go do what you want now and I'll post a new log after.

 I believe he would like you to search for those files -- as they may be lurking someplace.
 Posted: Thu Apr 08, 2004 17:16 pm    Post subject: I found the files STARTER.EXE but not STARTER.CHM. Should I delete them?

 md55, please submit that starter.exe file as you did the others to  http://www.lavahelp.com/submit/index.html.  I'm not sure who is going to be online tonight, but will leave them a message that you've posted.
Your complete logfile didn't post. Please pick up from here and post to the Summary.

 Quote: Winpup32 Object recognized! Type : File Data : hellexts.exe Category : Malware Comment : Object : C:\WINDOWS\SYSTEM\ FileSize : 64 KB Copyright : <

Thanks.
 Posted: Thu Apr 08, 2004 17:57 pm    Post subject: it ends there though, I don't know why.

 Go to C:\Program Files\Lavasoft\Ad-aware 6\Logs and find the logfile with today's date. Double click to open it, click Edit | Select all, Edit | Copy. Then post the logfile as a reply.
 Posted: Thu Apr 08, 2004 21:33 pm    Post subject: DAMNIT!!! i got the same start.chm and start.html problem this is the only place that talking about this hijack??? i delete those 2 files and they keep popping back up plz help fast!!! or i could just reformat
 Posted: Thu Apr 08, 2004 21:37 pm    Post subject: it changes your homepage to a place that has advertisements and all of them lead to master-search.com and u know its a stupid site cuz when u go to the main website, it says "having problems with our program? use this to remove it. you will need to leave it open for 2 hours to remove the file." meaning its probably a dialer or something
