Home Malware Programs Browser Hijackers Luckystarting.com

Luckystarting.com

Posted: January 21, 2017

Threat Metric

Threat Level: 5/10
Infected PCs: 6,975
First Seen: January 21, 2017
Last Seen: October 17, 2023
OS(es) Affected: Windows


LuckyStarting.com is a search site that acquires its results from third-party sources, such as Yahoo. Potentially Unwanted Programs (PUPs) are promoting this website by installing a custom version of a Web browser, which redirects your searches and locks your homepage. Although malware experts see no unsafe content on the website, you may want to remove LuckyStarting.com hijackers from your PC with the anti-malware products you'd use for similar potential scourges.

A Little Bad Luck for a Browser

Browser-hijacking programs that take the option of where you go on the Web out of your hands are a common sight on freeware domains with too-generous hosting policies. However, most Potentially Unwanted Programs fitting into this category also fall under the side classification of being browser toolbars, extensions or other add-ons. Recent LuckyStarting.com hijackers are using a somewhat different method: placing a separate browser onto your computer automatically.

LuckyStarting.com hijackers install a specially-modified variant of the Chromium browser, resembling Chrome, in most respects. However, the PUP's authors locked both the browser's homepage and its default search engine configuration to LuckyStarting.com. After looking at this website, malware experts concluded that LuckyStarting.com is not unsafe but provides no features of benefit to any of its traffic; it has no independent search capabilities and only can redirect any users to another engine, such as the Yahoo Search. When doing so, LuckyStarting.com also may inject advertising content or affiliate links out of the control of the other company.

Another, similarly suspicious feature of LuckyStarting.com's custom browser is that its installation process modifies your file associations by default, to encourage you to use this browser when double-clicking on HTML files, and similar content. Although changing file associations often is an optional component of various programs' installation routines, legitimate software always requests consent from the user and clearly denotes the change visually.

Don't Let Luck be a Factor in Your Web-Surfing

Since LuckyStarting.com's search hijacker routinely changes its brand name (currently, the software uses 'Fishjane' for its host directory), you may not be able to identify this Potentially Unwanted Program before it installs itself. Most PUPs bundle themselves into the installers of other applications, such as media players, codec packs, or torrents for both legal and illegal downloads. Content downloaded from less trustworthy sources like freeware websites associated with adware and browser hijackers historically always should be under some suspicion for carrying unwanted programs with their desired ones.

Most PC users should uninstall LuckyStarting.com's hijacker, along with its custom browser, instead of trying to modify the already-modified Web browser back into a 'blank slate' status. Web browsers downloaded from safe hosts always should allow you to select your homepage and search engine without forcing you to use any site, regardless of the domain's safety or lack of it. Most anti-adware and anti-malware programs include varying degrees of protection from browser hijackers, bundle-concealed installers, and other, unwanted applications.

LuckyStarting.com's owners are unlikely to have any interest in using their practices to promote anything other than a little extra profit for some simple search hijackings. Although a LuckyStarting.com hijacker is far from being a Trojan or spyware, that caveat is, like with other PUPs, a case of damning with faint praise.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathluckystarting[1].xmlHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{D751E92C-AB44-45E6-9733-427FE2C37FD8}

Related Posts

Loading...