Content

StartPage-B

Type
Trojan
SubType
-
Discovery Date
07/30/2002
Length
127,489 bytes
Minimum DAT
4217 (08/07/2002)
Updated DAT
4478 (04/27/2005)
Minimum Engine
5.1.00
Description Added
08/08/2002
Description Modified
08/08/2002 5:40 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This Trojan is compressed with the UPX packer. When run, it will modify the Internet Explorer start page setting. This is accomplished by changing a setting in the registry.

The start page is set to a Russian web page, http://yandex.8n.com. This website will redirect to www.porta.ru/index.html.

Symptoms

Modified default start page in Internet Explorer

Method of Infection

This Trojan will modify the registry numerous times to run at Windows startup. Due to the multiple entries, the system may become slow and unresponsive after the Trojan loads into Windows memory.

Removal

AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

Aliases

  • BackDoor.Pyand (DrWeb)
  • Trojan.Win32.StartPage.b (AVP)

Characteristics

Characteristics -

This Trojan is compressed with the UPX packer. When run, it will modify the Internet Explorer start page setting. This is accomplished by changing a setting in the registry.

The start page is set to a Russian web page, http://yandex.8n.com. This website will redirect to www.porta.ru/index.html.

Symptoms

Symptoms -

Modified default start page in Internet Explorer

Method of Infection

Method of Infection -

This Trojan will modify the registry numerous times to run at Windows startup. Due to the multiple entries, the system may become slow and unresponsive after the Trojan loads into Windows memory.

Removal -

Removal -

AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A