Intraday malicious virus program: Trojan.Win32.StartPage.prt
Behaviour:
This is a malicious Trojan virus program.
After being executed, the virus program shall replace IE icon with a malicious one which redirect infected computer users to malicious website specified by hackers. And then, the virus program shall hijack search engine of IE Browser or, other third party web browser software in order to increasing click rate of such website specified by hackers. Also, the virus program downloads and installs badware from background system of infected devices. So this malicious Trojan virus threatens computer security seriously.
Statistics:
RISING Cloud Security reported:
From July 30th to August 1st, 2010 there were 2,497,853 devices got malicious attack via malicious Webpage Horse Hanging tech, and RISING Virus Lab has intercepted 166,326 malicious hyperlinks with webpage Horse Hanging tech. And Rising Cloud Security got 36,568 reports from end users.
Top5 Infected Website:
1, hy.tsinghua.edu.cn
with malicious hyperlink: **. cn/admin/webedit/dialog/about/n6.htm, etc.
2, mpa.hit.edu.cn/aux.show.asp?dy=210061598
with malicious hyperlink: **info/2.htm, etc.
3, www.dragontv.cn/data/tlbb/tl201019174707.html
with malicious hyperlink: **com:8081/user/inc/tl/ie.html?x, etc.
4, www.yangtse.com/baby/vote/css/dt1007142363.html
with malicious hyperlink: ** com:8081/user/inc/dt/ie.html?xx, etc.
5, grs.bsu.edu.cn
with malicious hyperlink: **org/99/511ay.htm, etc.
Notice: the symbol ‘*’ means a stochastic letter or number.
Solutions:
1. Install Rising Internet Security, or Rising Antivirus plus Rising Firewall, and get update in time.
2. Install Rising PC Doctor, and choose “Leaks” function to check the leaks or vulnerabilities exist on your computer operating system, patch your computer system in a timely manner because many viruses spread by taking advantage of Windows operating system vulnerabilities.
3. Do not browse suspicious websites, and do not run suspicious plugins; turn off or delete unnecessary system services.
4. Do not receive the suspicious file from QQ, MSN, Email, etc.
5. Open RISING Active Defense and Auto-Protect function while accessing to Internet.
*You can buy RISING Security products here or free download to try.
*If you have any questions about RISING products, please visit Rising support centre for help.