Sophos

Troj/StartPa-EM

Aliases
  • Trojan.Win32.StartPage.tg
  • StartPage-BQ
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 17 January 2005 09:45:09 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/StartPa-EM is a Windows Trojan that changes the Internet Explorer start page.

In order to run automatically at computer logon the Trojan copies itself to %SYSTEM%\inetsrv.exe and %SYSTEM%\ielogon.exe and creates the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Internet Server
%SYSTEM%\inetsrv.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe %SYSTEM%\inetsrv.exe

Troj/StartPa-EM also changes the default Internet Explorer start page by creating the following registry entry:

HKCU\Software\Microsoft\Internet Explorer\Main\Start Page

The Trojan also changes the following registry entry from:

HKCR\txtfile\shell\open\command
@
C:\WINDOWS\NOTEPAD.EXE %1

to:

HKCR\txtfile\shell\open\command
@
%SYSTEM%\ielogon.exe "%1"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer