Sophos

Troj/StartPa-PB

Aliases
  • Trojan.Win32.StartPage.pb
  • BackDoor-AZV
  • trojan
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2005 (3.92)
Protection available since 7 March 2005 14:34:45 (GMT)
Detected by All Sophos products

Action

More Information

Troj/StartPa-PB is a Start page Trojan.

Troj/StartPa-PB will modify the Start and Search page settings of Internet Explorer. The Trojan will also intercept attempts to start other web browsers and then display a predefined website with them.

Troj/StartPa-PB will copy itself to the Windows folder as DBG.EXE and RUNDLL.EXE.
In order to run automatically each time a user logs in, Troj/StartPa-PB will set the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
svchost
%WINDOWS%\rundll16.exe

In order to run automatically each time an EXE file is run, Troj/StartPa-PB will set the following registry entry:

HKCR\exefile\shell\open\command
(Default)
%WINDOWS%\dbg.exe "%1" %*

Troj/StartPa-PB will then intercept attempts to run instances of FIREFOX.EXE, IEXPLORE.EXE, MOZILLA.EXE, NETSCP.EXE and OPERA.EXE and redirect their starting page to a predefined website.

Troj/StartPa-PB will modify the Start and Search pages of Internet Explorer by setting the following registry entries:

HKCU\Software\Microsoft\Internet Explorer\Main
Start Page
<URL>

HKCU\Software\Microsoft\Internet Explorer\Main
Search Page
<URL>

HKCU\Software\Microsoft\Internet Explorer\Main
Search Bar
<URL>

HKCU\Software\Microsoft\Internet Explorer\Main
Use Search Asst
no

HKLM\Software\Microsoft\Internet Explorer\Main
Start Page
<URL>

HKLM\Software\Microsoft\Internet Explorer\Main
Search Page
<URL>

HKLM\Software\Microsoft\Internet Explorer\Main
Search Bar
<URL>

HKLM\Software\Microsoft\Internet Explorer\Main
Use Search Asst
no

Troj/StartPa-PB will intercept URLs prefixed with "www" and redirect them through a predefined website by setting the following registry entry:

HKLM\Microsoft\Windows\CurrentVersion\URL\Prefixes
www
<URL>

Troj/StartPa-PB will drop the following shortcut files into the user's Favorites folder:

Teens Anal Fucking.url
Porn.url
Sex Explorer.url

Troj/StartPa-PB will attempt to disable the handling of certain types of web page by moving the following registry entries:

HKCR\PROTOCOLS\Handler\its\CLSID to HKCR\PROTOCOLS\Handler\its\CLSID0

HKCR\PROTOCOLS\Handler\ms-its\CLSID to HKCR\PROTOCOLS\Handler\ms-its\CLSID0

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer