Trojan.Win32.StartPage.dh

tag:Trojans  

Once launched, the Trojan creates the following record in the system registry:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
  1. Delete the original Trojan file (the location varies depending on how the Trojan originally penetrated the victim machine).
  2. Delete the following file: %Windir%\secure.html
  3. Delete the following registry key value: [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]

    This Trojan program changes the user's Internet Explorer home page, without the user's knowledge or consent.

    The Trojan itself is a Windows PE EXE file 3072 bytes in size.

    Payload

©Virus-Encyclopedia.com All Rights Reserved.