基本介紹
Trojan/StartPage.lh
病毒長度:20,992 位元組(壓縮後) 62,464 位元組(解壓後)
病毒類型:木馬
危害等級:*
影響平台:Win9X/2000/XP/NT/Me/2003
傳播過程及特徵:
1.修改註冊表:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Bar" = http://auto.ie.searchforge.com/
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"atpanel"= regsvr32.exe /s %Program Files%\Common Files\Microsoft Shared\Web Folders\pubplace.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"nvpdep" = regsvr32 /s /u %Windir%\dnserr.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page" = http://auto.ie.searchforge.com/
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant" = http://auto.ie.searchforge.com/
2.生成檔案:
%Program Files%\Common Files\Microsoft Shared\Web Folders\pubplace.dll --- 12,800 位元組
%Program Files%\Internet Explorer\readme.txt --- 386 位元組