StartPage-JC

This page shows details and results of our analysis on the malware StartPage-JC

Overview

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.


Minimum DAT

4707 (2006-02-28)

Updated DAT

4707 (2006-02-28)

Minimum Engine

5400.1158

File Length

Description Added

2006-02-28

Description Modified

2006-02-28

Malware Proliferation

Characteristics

StartPage-JC is a start page trojan that installs as a Browser Helper Object which changes the default Internet Explorer start page to http://www.my990.com. This trojan also changes other Internet Explorer related settings.

Upon execution, it installs itself as a Browser Helper Object.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{B4BA88E2-18D2-4B24-87E4-DC4C030D756C}

Modifies the start page and default search page to http://www.my990.com.

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main

"Local Page"="http://www.my990.com"
"Search Page"="http://www.my990.com"
"Start Page"="http://www.my990.com"
"Default_Page_URL"="http://www.my990.com"
"Default_Search_URL"="http://www.my990.com"
"Enable Browser Extensions"="yes"
"Search Bar"="http://www.my990.com"
"Window Title"="http://www.my990.com"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main

"Default_Page_URL"="http://www.my990.com"
"Default_Search_URL"="http://www.my990.com"
"Local Page"="http://www.my990.com"
"Search Page"="http://www.my990.com"
"Start Page"="http://www.my990.com"
"Search Bar"="http://www.my990.com"
"Window Title"="http://www.my990.com"

In addition to this the trojan also disables the option of manually modifying Internet Explorer's start page by adding the following registry key.

HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel
"HomePage"=dword:00000001

Adds a button in the Tools menu of Internet Explorer.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{7F4CBA8C-FC91-4F7C-8DC7-311273D273EA}

"ButtonText"=""
"Clsid"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"
"Default Visible"="YES"
"Exec"="http://www.my990.com"
"HotIcon"="%SystemRoot%\\Downloaded Program Files\\IEUBmy99.dll,102"
"Icon"="%SystemRoot%\\Downloaded Program Files\\IEUBmy99.dll,101"
"MenuStatusBar"="http://www.my990.com"
"MenuText"=""

Redirects the following sites to http://www.my990.com.

yy008.com
hkliuhecai.com
57666.net
6mm.cc
3494.com
987t.com
hao123.com
hk5.net
3619.com
ypt668.net
ypt668.com
hm888.com
xg4.net
1181.net
zs188.com
zphp01.com
6hcn.net
ok5555.com
12kk.com
22336688.com
22336688.net
2676.com
3825.net
hk052.com
38689.com
66058.com
marksix3721.com
tm3494.com
6232.com
3815.net
6808.net
0015.net
3739.com
6769.com
11339.com
13777.com
13778.com
0336.com
005566.com
6769.net
299669
6968.net
4929.com
49ok.com
5lh.com
6269.com
88uu.net
51238.com
9791.com
98170.net
9891.com
apaijingying.com
cpxz.com
fh128.com
fu642.com
139500.com
hk10000.com
hk136.com
hk266.net
hk286.com
hktm868.com
hp98.com
k568.net
kkhkk.com
kksix.com
kktk.net
lhc.cn
sz0808.com
3322.net
t939.com
te118.com
my112.com
tk6666.com
tm948.com
22336688
4329.com
98886.com
94tk.com
96tk.net
fa899.com
fu18.net
168tk.com
xxxkkk.com
xg321.com
xgbbs.com
xgmark688.com
xgsix6.com
xgtk.net
y128.com
y385.com
xytk.net
33384.com
qq163.com
48q.com
518588.com
5668a.com
662858.com
68123.com
6he6.com
87666.com
9691.com
cg998.com
fa3721.com
2266.cn
hk776.com
hk799.com
hk90888.com
hkxytu.net
k186.com
kk878.net
3799.com
lhc6789.com
mshktm.com
marsix1888.com
my880.com
my99999.com
vv56.com
sm868.com
fh789.com
tk1818.com
tk88.net
tk89.com
tu789.net
tu9.com
tu998.net
tuku678.com
v5678.com
hk669.net
xgty.net
55553.com
tm996.com
zs118.com
0098.net
116.cn
2516.net
2612.org
3618.org
38tk.com
4424.net
53666.com
55138.com
4388.net
58123.net
5k6k.com
5q98.com
67678.com
6ge.com
77123.com
5811.com
987f.com
hj88.com
hjtk.net
xytu.com
tjsix.com
hkak.com
hko2000.com
kk9988.com
mk567.com
mmtu.net
ok188.com
k45678.com
tbz666.net
yptbbs.cn
tk00852
tk22.com
tk999.com
tuku6.com
tuqu.net
w9898.com
wwztk.net
xgtk.com
xgtuku.com
zdr4498.com
zdr5598.com
138128.com
138888.com
268888.com
7702.com
328k.com
33789.com
456456.com
56588.net
6589.com
6ge.net
6hxx.net
xkwl.net
770880.net
44466.com
8wo.net
99998888.com
bc2004.com
c456.net
gttk.net
hk772.com
hk9797.net
hkcai.com
hklh.com
1976.com
k1699.com
lhctk.net
my179.com
nease.net
okok999.com
kktkk.com
3817.net
3817.com
sy118.com
t899.com
td49.com
tu668.net
1-49m.net
xg007.com
ok666666.com
58v.net
xghh.com
xgtu.com
xgtu8.com
31288.com
yyy333.net
hkjc.com
7005.com
ok06.com
k1234.com
kw888.com
hkball.net
qq666.net
baidu888.com
3309.net
t818.com
k169.com
00852.com
hk2538.com
6148.com
y889.net
25688.com
55689.com
57666.com
3814.com
hok868.com
4467.com
98756.net
778778.com
www.5811.com
hk96.cn
xg58.com
9967.com
xg08.com
818ok.com
hok888.com
78kk.com
520666.net
shequn.net
88366.com
hkkkkk.com
good666666.com
616ok.com
3505.net
tu18.com
fa868.net
chinaadd.com
haohz.com
6661888.net
ziyun88.com
373721.com
89880.com
lh468.com
55448.com
hk368.net
yyy8888.com
xgcbw.com
yy5588.com
yy8866.com
5866.net
168666.com
49666.com
558855.com
8uu.com
hk815.net
sk66.com
xglh688.com
1686.net
sm818.com
669888.com
949494.com
tm258.com
6039.com
23331.com
6hecai.org
hk9876.com
3859.net
3859.com
hongkongjockeyclub.com
tm118.net
xg5677.com
k4567.com
67799.com
5166888.com
99949.com
878999.net
336339.com
94388.com
kk7321.com
5389.com
66uu.net
h555.com
hongkongbxj.com
aabb88.com
hk6636.com
00889.com
887898.com
xg638.com
98756.org
44544.com
y6y6.com
mkxy.com
265.com
90bf.com
bet007.com
yahoo.com
netsh.com
qq.com
ym2004.com
777hhh.com
zdao.com
cc456.com
kk76.com
y933.net
38788.com
mn2008.com
33767.net
k6666.com
xgokok.com
kk9k.com
kkkwww.com
vv94.cn
qq788.net
70008.com
tmw666.com
664488.com
kv520.net
7619.net
hk444.net
4619.com
hkh99.com
shequnhk.net
hk88666.com
lg688.com
kk568.com
77339.com
hh889.com
y566.com
561888.com
hk468.net
aa28.com
x1888.com
556k.com
58gg.com
xg8666.com
hk8068.com
tm1118.com
wzdq.net
158666.com
1185.net
hk99w.com
k96.net
tm159.com
99178.com
994477.com
tm80.com
16668.net
123163.com
vv68.com
49tt.com
75518.com
xp9000.com
004005.com
00851.com
48668.com
889966.com
my118.net
125666.com
tk12.com
6wo.net
66128.com
tm886.com
6898.net
334499.com
4756.com
191100.com
8552.net
12kk.net
699899.com
3c6.com
01988.com
23188.com
ww880.com
sportscn.com
yisou.com
zhongsou.com
kingsoft.com
62788.com
hongkong163.com
cg998.net
4394.com
8552.ne
six777.com
ok400.com
google0.com
88gg.com
6778.com
49007.com
hp8088.com
tm5868.net
kk1298.com
3817.cn
3817.cc
308444.com
308444.net
wztg.net
876543.net
55499.com
55499.net
hktxbb.com
2526.net
3078.com
222yyy.com
sixshequn.com
99662.com
678f.com
004005.net
7228.com
as118.com
7855.com
56568.com
ok337.com
8687.net
ty33.com
hk133.com
7855.net
ty28.com
58120.com
k16008.com
123858.com
k858.com
6636k.com
123858.net
6636k.net
lh21.com
003002.com
hk6h6.com
ip3721.com
mc8888.com
kai8.com
7855.cn
mx118.com
ok38.com
88377.com
88377.net
ty33.net
57778.com
hk833.com
55658.com
55890.com
25038.com
58558.net
hk6767.com
49-01.com
h9918.com
135138.com
21cn.com

Symptoms

Modified default start page in Internet Explorer.

Method of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc.

Removal

A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.

 

Variants