Sophos

Troj/Startpa-Z

Aliases
  • Trojan.Win32.StartPage.cl
  • StartPage-AX
  • Win32/StartPage.CL
  • Trojan.Bookmarker.E
  • TROJ_BOOKMARK.E
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from May 2004 (3.81)
Protection available since 31 March 2004 11:29:11 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Startpa-Z is a simple Trojan that makes changes to Internet Explorer settings via the registry.

Troj/Startpa-Z changes the default start page of Internet Explorer to the URL http://aifind.info/ and will add a list of URLs containg adult content to the favourites folder. The Trojan will also change the following registry entries:

HKCU\Software\Microsoft\Internet Explorer\Styles\
Use My Stylesheet = 1

HKCU\Software\Microsoft\Internet Explorer\Styles\
User Stylesheet = <Windows>\hh.htt

HKLM\Software\Microsoft\Internet Explorer\Styles\
Use My Stylesheet = 1

HKLM\Software\Microsoft\Internet Explorer\Styles\
User Stylesheet = <Windows>\hh.htt

The stylesheet file hh.htt is detected by Sophos Anti-Virus as Troj/Startpa-BG.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer