Trojan.Win32.StartPage.au

tag:Trojans  

The Trojan changes the values of the following system registry keys:

[HKLM\Software\Microsoft\Internet Explorer\Styles]
"Use My Stylesheet" = "1"
"User Stylesheet" = "%WinDir%\hh.htt"

[HKCU\Software\Microsoft\Internet Explorer\Main]
"Start Page" = "http://aifind.info/"
"Search Page" = "http://aifind.info/"
"Search Bar" = "http://aifind.info/"

[HKCU\Software\Microsoft\Internet Explorer]
"SearchURL" = http://aifind.info/

It adds the following files to the current user's "Favorites":

!!! Exclusive Youngest Porn !!!.url
80 old daddies brutally fucking their daughters.url
CENSORED YOUNGEST PORN.url
Fresh XXX pics  
  

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

  1. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  2. Delete the following system registry keys: (see What is a system registry and how do I use it for details on how to edit the registry).
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
    "Control" = "rundll32.exe C:\WINDOWS\system32\ctrlpan.dll,Restore ControlPanel"
  3. Modify the following system registry key parameter:
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs" = "ctrlpan.dll"

    to the original value:

    "AppInit_DLLs" = " "
  4. Revert the following system registry key values:
    [HKLM\Software\Microsoft\Internet Explorer\Styles]
    "Use My Stylesheet" = "1"
    "User Stylesheet" = "%WinDir%\hh.htt"
    
    [HKCU\Software\Microsoft\Internet Explorer\Main]
    "Start Page" = "http://aifind.info/"
    "Search Page" = "http://aifind.info/"
    "Search Bar" = "http://aifind.info/"
    
    [HKCU\Software\Microsoft\Internet Explorer]
    "SearchURL" = http://aifind.info/
  5. Delete the file dropped by the Trojan: %WinDir%\hh.htt
  6. Delete the following files from "Favorites":
    !!! Exclusive Youngest Porn !!!.url
    80 old daddies brutally fucking their daughters.url
    CENSORED YOUNGEST PORN.url
    Fresh XXX pics  

    This Trojan modifies the configuration of Microsoft Internet Explorer without the knowledge or consent of the user. It is a Windows DLL file. The file is 5,120 bytes in size. It is packed using UPX. The unpacked file is approximately 7KB in size.

    Installation

    This Trojan will be installed on the victim machine by other Trojan programs.

    When launched, the Trojan creates the following file:

    %WinDir%\hh.htt

    In order to ensure that the Trojan is launched automatically each time the system is booted, the Trojan registers its executable file in the system registry:

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
    "Control" = "rundll32.exe C:\WINDOWS\system32\ctrlpan.dll,Restore ControlPanel"
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs" = "ctrlpan.dll"
    Payload

©Virus-Encyclopedia.com All Rights Reserved.