VBS_STARTPGE.SMG
Windows 2000, XP, Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan may arrive bundled with malware packages as a malware component.
TECHNICAL DETAILS
Varies
VBS
No
22 Sep 2010
Arrival Details
This Trojan may arrive bundled with malware packages as a malware component.
Dropping Routine
This Trojan drops the following files:
- C:\Documents and Settings\All Users\Start Menu\³ÌÐò\Æô¶¯\ÌÚѶQQ.lnk - non-malicious file
Other Details
This Trojan does the following:
- It searches for .LNK files (shortcut files) in the following locations:
%Application Data%\Microsoft\Internet Explorer\Quick Launch
%Desktop%
%Start Menu%
C:\Documents and Settings\All Users\Desktop
C:\Documents and Settings\All Users\Start MenuIt checks if the said shortcut files point to the following files:
360SE.exe
Maxthon.exe
Maxthon2.exe
SogouExplorer.exe
TTraveler.exe
TheWorld.exeIf it finds a match, it then appends any of the following to the target path:
%Program Files%\Common Files\winie.html;
%Program Files%\NetMeeting\ie.html
http://www.{BLOCKED}h.cn/?360
http://www.{BLOCKED}dh.cn/?360
http://www.{BLOCKED}dh.cn/?360
http://www.78{BLOCKED}.cn/?361
http://www.{BLOCKED}h.cn/?361
http://www.{BLOCKED}dh.cn/?360
http://www.{BLOCKED}q.com/?ss2
http://www.{BLOCKED}60.cn
SOLUTION
8.900
7.482.05
22 Sep 2010
Step 1
Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.
Step 2
Search and delete this file
Step 3
Scan your computer with your Trend Micro product to delete files detected as VBS_STARTPGE.SMG. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.