StartPage-JN trojan automatically opens Microsoft Internet Explorer windows to visit pages under vod.mmdy.org. It can also change the Start and Search pages of Internet Explorer.
|
Minimum DAT
4894 (2006-11-13) Updated DATN/A |
Minimum Engine
5.1.00 File Length8,177 bytes |
Description Added
2006-11-10 Description Modified2006-11-10 |
The StartPage-JN writes malicious a payload into the process memory of EXPLORER.EXE and terminates itself. This thread of EXPLORER.EXE is responsible for automatically opening the following web pages using Internet Explorer:
This Trojan may also modify the registry to set Internet Explorers Start Page and Local Page to http://vod.mmdy.org.
It may also configure Windows to activate the trojan when Windows reboots, using the following registry key:
A file named winpub.reg is required to perform these registry changes. This file was unavailable at the time of writing this document.
Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems. Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc.
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
But in some particular cases, the following steps need to be taken.
Please go to the Microsoft Recovery Console and restore a clean MBR.
On Windows XP:
On Windows Vista and 7: