StartPage-JN!CC32C55

This page shows details and results of our analysis on the malware StartPage-JN!CC32C55

Overview

StartPage-JN trojan automatically opens Microsoft Internet Explorer windows to visit pages under vod.mmdy.org. It can also change the Start and Search pages of Internet Explorer.


Minimum DAT

4894 (2006-11-13)

Updated DAT

N/A

Minimum Engine

5.1.00

File Length

8,177 bytes

Description Added

2006-11-10

Description Modified

2006-11-10

Malware Proliferation

Characteristics

The StartPage-JN writes malicious a payload into the process memory of EXPLORER.EXE and terminates itself. This thread of EXPLORER.EXE is responsible for automatically opening the following web pages using Internet Explorer:

  • http://vod.mmdy.org/
  • http://vod.mmdy.org/news
  • http://vod.mmdy.org/goodvip
  • http://vod.mmdy.org/mm
  • http://vod.mmdy.org/mp3
  • http://vod.mmdy.org/zz
  • http://vod.mmdy.org/tj
  • http://vod.mmdy.org/yx

This Trojan may also modify the registry to set Internet Explorers Start Page and Local Page to http://vod.mmdy.org.

It may also configure Windows to activate the trojan when Windows reboots, using the following registry key:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\
    {340121DC-1BEF-1A77-0106-060207060704}

A file named winpub.reg is required to perform these registry changes. This file was unavailable at the time of writing this document.

Symptoms

Internet Explorer automatically opening to show web pages as mentioned above and the presence of aforementioned registry entries and the modified start page.

Method of Infection

Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems. Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc.

Removal

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

But in some particular cases, the following steps need to be taken.

Please go to the Microsoft Recovery Console and restore a clean MBR.

On Windows XP:

  • Insert the Windows XP CD into the CD-ROM drive and restart the computer.
  • When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
  • Select the Windows installation that is compromised and provide the administrator password.
  • Issue 'fixmbr' command to restore the Master Boot Record
  • Follow onscreen instructions.
  • Reset and remove the CD from CD-ROM drive.


On Windows Vista and 7:

  • Insert the Windows CD into the CD-ROM drive and restart the computer.
  • Click on "Repair Your Computer".
  • When the System Recovery Options dialog comes up, choose the Command Prompt.
  • Issue 'bootrec /fixmbr' command to restore the Master Boot Record.
  • Follow onscreen instructions.
  • Reset and remove the CD from CD-ROM drive.

Variants