CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer
image Press Release: Trojan Directs Browsers to Pornographic Websites image
Cyber Security
anee writes "A new variant of the StartPage Trojan spreads via Internet Explorer vulnerabilities and emails carrying “.zip” and “.exe” files. Security Experts at the leading AntiVirus and Content Security firm MicroWorld Technologies, inform that ‘BAT.StartPage.b’ changes Internet Explorer settings, lowers security levels and installs itself in the registry.

“StartPage Trojan had been one of the most annoying and hard to remove Trojans right from its first variant,” says Aneesh Paliwal, Security Analyst, MicroWorld Technologies. “Like some of its earlier versions, ‘StartPage.b’ too changes browser favorites and adds many pornographic sites to it. Many times while trying to access Google or Yahoo, the Trojan redirects you to these websites and other vexing ones.”

Most spin-offs of this Trojans are Java applets, VBScripts or JavaScripts or Windows Registry export/import files in REG format. Though these Trojans are detected by many AntiVirus Software, most of them fail to remove the malware completely. In those cases it’s observed that, after a cleaning process the Trojan sprouts back in action with new names and process IDs.

What’s peculiar about the new variant StartPage.b is that it registers itself as Internet Explorer components and modifies browser actions. This means the Trojan can also work as browser helpers and subsequently mislead you to malicious websites.

“Trojans are the most dangerous form of malware that the world is fighting today. You have hundreds of Trojan families with countless members in each, with intermingling behaviors and upgrading capabilities. Many of them use a small rootkit component to hide themselves from the reach of security software too. We at MicroWorld swear by our Proactive Protection in Real-Time, so these sneaky breeds never find an entry in your computer in the first place,” says Govind Rammurthy, CEO, MicroWorld Technologies.

AntiVirus And Content Security products eScan and MailScan from MicroWorld are the world’s most advanced solutions with their fastest detection rate and unique, patent pending MWL technology. These solutions block all kinds of script Viruses, Active X driven malware and vulnerability exploits to protect you from Trojans like StartPage varieties. With their proven efficiency in proactive defense, MicroWorld brings in Futuristic Security for enterprises as well as home users.

To protect the internal network of organizations against attacks via the Internet, MicroWorld has developed a revolutionary firewall branded as eConceal, offering great usability and advanced stealth mode. To be launched in June 2006, eConceal provides customizable security with user-defined Rules for Packet Filtering and Access Control.
"
Posted on Wednesday, 24 May 2006 @ 12:05:25 UTC by Paul (3909 reads)
[ Trackback ]
image

"Press Release: Trojan Directs Browsers to Pornographic Websites" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· HotScripts
· Apple
· Google Search Engine
· W3 Consortium
· More about Cyber Security
· News by Paul


Most read story about Cyber Security:
Booby Trapped software!

block bottom
Article Rating
spacer
Average Score: 2.5
Votes: 2


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer