Sophos

Sophos blogs

Troj/StartP-BY

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Protection available since 5 June 2009 10:45:02 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/StartP-BY is a Trojan for the Windows platform.

Troj/StartP-BY is likely to be seen masquerading as a legitimate application (for example, trial version of some popular software). However, the installer includes malicious content which modifies the default homepage for Internet Explorer and Firefox browsers.

For Internet Explorer, the following Registry entry is made:

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page
http://www.[removed].com/

For Firefox, the prefs.js file within each of the Mozilla profiles on the computer, is modified to set the browser.startup.homepage option to the same URL.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer