Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | April 2005 (3.92) |
| Protection available since | 7 March 2005 14:34:45 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/StartPa-PB is a Start page Trojan.
Troj/StartPa-PB will modify the Start and Search page settings of Internet Explorer. The Trojan will also intercept attempts to start other web browsers and then display a predefined website with them.
Troj/StartPa-PB will copy itself to the Windows folder as DBG.EXE and RUNDLL.EXE.
In order to run automatically each time a user logs in, Troj/StartPa-PB will set the following registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
svchost
%WINDOWS%\rundll16.exe
In order to run automatically each time an EXE file is run, Troj/StartPa-PB will set the following registry entry:
HKCR\exefile\shell\open\command
(Default)
%WINDOWS%\dbg.exe "%1" %*
Troj/StartPa-PB will then intercept attempts to run instances of FIREFOX.EXE, IEXPLORE.EXE, MOZILLA.EXE, NETSCP.EXE and OPERA.EXE and redirect their starting page to a predefined website.
Troj/StartPa-PB will modify the Start and Search pages of Internet Explorer by setting the following registry entries:
HKCU\Software\Microsoft\Internet Explorer\Main
Start Page
<URL>
HKCU\Software\Microsoft\Internet Explorer\Main
Search Page
<URL>
HKCU\Software\Microsoft\Internet Explorer\Main
Search Bar
<URL>
HKCU\Software\Microsoft\Internet Explorer\Main
Use Search Asst
no
HKLM\Software\Microsoft\Internet Explorer\Main
Start Page
<URL>
HKLM\Software\Microsoft\Internet Explorer\Main
Search Page
<URL>
HKLM\Software\Microsoft\Internet Explorer\Main
Search Bar
<URL>
HKLM\Software\Microsoft\Internet Explorer\Main
Use Search Asst
no
Troj/StartPa-PB will intercept URLs prefixed with "www" and redirect them through a predefined website by setting the following registry entry:
HKLM\Microsoft\Windows\CurrentVersion\URL\Prefixes
www
<URL>
Troj/StartPa-PB will drop the following shortcut files into the user's Favorites folder:
Teens Anal Fucking.url
Porn.url
Sex Explorer.url
Troj/StartPa-PB will attempt to disable the handling of certain types of web page by moving the following registry entries:
HKCR\PROTOCOLS\Handler\its\CLSID to HKCR\PROTOCOLS\Handler\its\CLSID0
HKCR\PROTOCOLS\Handler\ms-its\CLSID to HKCR\PROTOCOLS\Handler\ms-its\CLSID0
