Content

Startpage-N

Type
Trojan
SubType
Settings Change
Discovery Date
06/27/2003
Length
20,480 Bytes
Minimum DAT
4276 (07/09/2003)
Updated DAT
4478 (04/27/2005)
Minimum Engine
5.1.00
Description Added
06/27/2003
Description Modified
06/30/2003 3:33 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This threat is detected as Startpage-N trojan and is compressed with ASPack. On executing the trojan, the following files will be copied:

  • windows directory\msinfer.exe
  • windows SYSTEM directory\intenats.exe
  • windows SYSTEM directory\sysfile.exe
  • windows SYSTEM directory\widows.exe
The followiing registry keys will also be modified:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\
    Windows "load" [windows SYSTEM directory]\widows.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
    Run "intenats" [windows SYSTEM directory]\intenats.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
    Run "sysfile" [windows SYSTEM directory]\sysfile.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Start Page" http://www.qq3344.com/
The trojan will also modify win.ini to execute the trojan on startup:
run = windows directory\msinfer.exe.

Symptoms

Presence of the files:

  • windows directory\msinfer.exe
  • windows SYSTEM directory\intenats.exe
  • windows SYSTEM directory\sysfile.exe
  • windows SYSTEM directory\widows.exe
The above registry changes and change made to win.ini.

Method of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc.

Removal

All Users :
Use specified engine and DAT files for detection and removal. Delete files which contain this detection.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

Characteristics

Characteristics -

This threat is detected as Startpage-N trojan and is compressed with ASPack. On executing the trojan, the following files will be copied:

  • windows directory\msinfer.exe
  • windows SYSTEM directory\intenats.exe
  • windows SYSTEM directory\sysfile.exe
  • windows SYSTEM directory\widows.exe
The followiing registry keys will also be modified:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\
    Windows "load" [windows SYSTEM directory]\widows.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
    Run "intenats" [windows SYSTEM directory]\intenats.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
    Run "sysfile" [windows SYSTEM directory]\sysfile.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Start Page" http://www.qq3344.com/
The trojan will also modify win.ini to execute the trojan on startup:
run = windows directory\msinfer.exe.

Symptoms

Symptoms -

Presence of the files:

  • windows directory\msinfer.exe
  • windows SYSTEM directory\intenats.exe
  • windows SYSTEM directory\sysfile.exe
  • windows SYSTEM directory\widows.exe
The above registry changes and change made to win.ini.

Method of Infection

Method of Infection -

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc.

Removal -

Removal -

All Users :
Use specified engine and DAT files for detection and removal. Delete files which contain this detection.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A