Threat Database Trojans Trojan:Win32/Startpage.UY

Trojan:Win32/Startpage.UY

By Domesticus in Trojans

Trojan:Win32/Startpage.UY is a Trojan that changes the home page and search settings for the hijacked web browser such as Google Chrome, Internet Explorer, Mozilla Firefox and Opera to http://ecostartpage.com. PC users may unknowingly download and initiate Trojan:Win32/Startpage.UY on the vulnerable PCs, thinking it is a genuine application or file. After Trojan:Win32/Startpage.UY has performed its payload, it downloads the certain file, which deletes its copy. Trojan:Win32/Startpage.UY sets the start page and default search engine in Internet Explorer by modifying several registry entries. Trojan:Win32/Startpage.UY sets the start page and default search engine in Google Chrome by modifying the default preferences. Trojan:Win32/Startpage.UY creates a default settings folder in Mozilla Firefox. Trojan:Win32/Startpage.UYsets a preferences file into the folder with the certain settings. Trojan:Win32/Startpage.UY sets the start page by modifying the certain file in Opera.

Aliases

12 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Ikarus Trojan.Win32.StartPage
AhnLab-V3 Trojan/Win32.StartPage
Sophos Mal/Generic-L
AntiVir TR/Drop.Agent.mhe
DrWeb Trojan.StartPage.22540
Comodo UnclassifiedMalware
Kaspersky Trojan.Win32.StartPage.dcr
Avast Win32:Trojan-gen
F-Prot W32/MalwareF.LOYG
K7AntiVirus Trojan
McAfee Generic StartPage!ci
CAT-QuickHeal Trojan.Agent.IRC

SpyHunter Detects & Remove Trojan:Win32/Startpage.UY

File System Details

Trojan:Win32/Startpage.UY may create the following file(s):
# File Name MD5 Detections
1. %TEMP%\suicide.exe
2. prefs.js
3. EcoStartPage.xml
4. %APPDATA%\Opera\Opera\operaprefs.ini
5. 89a282928c2b671f2301ec772cc96054 89a282928c2b671f2301ec772cc96054 0
6. a17944d2fa99b3ed50bd69c69425837f a17944d2fa99b3ed50bd69c69425837f 0
7. ce18153c0e5a3912efce652d5635788b ce18153c0e5a3912efce652d5635788b 0
8. a2fe2dcd2149e2644cfd9b1030729335 a2fe2dcd2149e2644cfd9b1030729335 0
9. msngserv.exe 731f313680af50f9375243fb5a7f8079 0

Registry Details

Trojan:Win32/Startpage.UY may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{GUID} "URL" = "http://ecostartpage.com/index.php?q={searchTerms}"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Start Page" = "http://ecostartpage.com"

Trending

Most Viewed

Loading...