sp.html spyware homepage high jacker Severity HIGH

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Don (arcadeguy_at_hotmail.com)
Date: 07/04/04


Date: 3 Jul 2004 17:29:09 -0700

if anyone gets this dam about.hml page with the popup about your IP
address your a victim.

I have been tracing this thing down in the registry and the winnt
folder
very hard to find
very reproductive.

files it created:
ideb.dll
sp.html
and many others

#######################
its a virus:

http://www.pandasoftware.com/virus_info/encyclopedia/ficha.aspx?iddeteccion=105595

Infection strategy

StartPage.FH is a DLL (Dynamic Link Library) that is registered with
the browser Internet Explorer. This DLL changes the browser's home
page.

StartPage.FH creates the file SP.HTML in the Windows temporary
directory. This file contains the web site displayed when the Internet
Explorer is launched.

StartPage.FH creates the entries in the Windows Registry, among
others:

HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Internet Explorer\ Main
Search Page = %tempdir%\ sp.html
where %tempdir% is the Windows temporary directory.
HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main
Start Page = about:blank
 
Means of transmission

StartPage.FH does not spread automatically using its own means. It
needs the attacking user's intervention in order to reach the affected
computer. The means of transmission used include, among others, floppy
disks, CD-ROMs, e-mail messages with attached files, Internet
downloads, FTP, IRC channels, peer-to-peer (P2P) file sharing
networks, etc.

Further Details

StartPage.FH is 30,720 bytes in size and it is compressed.

###################

the fix:

Is my computer infected by StartPage.FH?
  
In order to make absolutely sure that StartPage.FH has not affected
your computer, you have the following options:

Carry out a full scan of your computer using Panda Antivirus, after
checking that it is updated. If it isn't and you are a registered
Panda Software client, update it by clicking here.
Check the computer with Panda ActiveScan, Panda Software's free,
online scanner, which will quickly detect any possible viruses.
 
  
How to remove StartPage.FH?
  
If Panda Antivirus or Panda ActiveScan detects StartPage.FH during the
scan, it will automatically offer you the option of deleting it. Do
this by following the program's instructions.

Additional notes:

If your computer has Windows Millenium installed, click here to
permanently remove all trace of the virus.
If your computer has Windows XP installed, click here to permanently
remove all trace of the virus.
  
How can I protect my computer from StartPage.FH?
  
In order to keep your computer protected, bear the following tips in
mind:

Install a good antivirus in your computer. Click here to get the Panda
antivirus solution that best suits your needs.
Keep your antivirus updated. If automatic updates are available,
configure your antivirus to use them.
Keep your permanent antivirus protection enabled at all times.
For more detailed information about how to protect your computer
against viruses and other threats, click here.
 
##########################

I cant wait for the next SP fix so IE wont have holes like this again.

cheers



Relevant Pages

  • Re: sp.html spyware homepage high jacker Severity HIGH
    ... I also wouldn't expect Panda or any other virus software ... There are 2 DLLs involved, the "BHO" DLL which you see in your log and the ... "Windows" and close RegLite. ... > If Panda Antivirus or Panda ActiveScan detects StartPage.FH during the ...
    (microsoft.public.windowsxp.general)
  • Re: Error loading WINDOWS
    ... Search For Hidden Or System Files In Windows XP ... Then do a registry search for everything that refers to cbdfuoev.dll. ... UPDATE your antivirus software and run a full system scan. ... UPDATE whatever anti-spyware applications that you have and run a full ...
    (microsoft.public.windowsxp.basics)
  • Re: Microsoft JET Database Engine error 80004005
    ... > First, windows didn't start in normal way, I only could start in Security ... so I tried uninstall Panda Antivirus but in security mode I couldn't ... > becouse in this mode the Windows Installer doesn't work. ...
    (microsoft.public.inetserver.asp.db)
  • panda and windows xp stop error
    ... I have installed Panda internet security on my computer (Windows xp Home ... I have been using only Panda since 2004 and don’t have any other antivirus. ... I tried to download and install Panda again but the stop error repeats. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Microsoft JET Database Engine error 80004005
    ... >But I installed the Panda BusinesSecure Antivirus and since then I have had ... >becouse in this mode the Windows Installer doesn't work. ... >Internet Users, have all permissions. ...
    (microsoft.public.inetserver.asp.db)