Sophos

Troj/StartPa-MN

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 13 September 2004 13:26:45 (GMT)
Last updated 14 September 2004 09:22:36 (GMT)
Detected by All Sophos products

Action

More Information

Troj/StartPa-MN is a Trojan which modifies the Internet Explorer Start-Page and changes the Search options.

When run the Trojan creates two helper files system32.exe and mspxs32.dll in the Windows system folder and runs system32.exe. The following registry entries are created so that the Trojan may auto-start on user logon or computer restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Win32 Explorer = %SYSTEM%\explorer32.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Win32 Explorer = %SYSTEM%\explorer32.exe

Troj/StartPa-MN also lowers the Internet Explorer security settings allowing running of scripts and downloading of files.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer