Home Malware Programs Trojans Trojan.WinREG.StartPage.bh

Trojan.WinREG.StartPage.bh

Posted: August 31, 2010

Trojan.WinREG.StartPage.bh has the capability to steal confidential information stored on an infected computer and sends the gathered data onto a remote source. Trojan.WinREG.StartPage.bh is another malicious trojan horse that may represent security risk for a compromised PC system or a network environment. Trojan.WinREG.StartPage.bh penetrates the system without the user's knowledge or permission. Trojan.WinREG.StartPage.bh redirects the homepage and can easily contact a remote server to download other harmful parasites onto the infected computer from corrupt webisites. Other symptoms for Trojan.WinREG.StartPage.bh include the computer screen flipping upside down or inverting and documents or messages printing by themselves. For the safety of your computer, Trojan.WinREG.StartPage.bh should be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AllUsersProfile%\Guest
    2 %AllUsersProfile%\Guest\Favorites
    3 %ProgramFiles%\Coopen
    4 %ProgramFiles%\Coopen\conf
    5 %ProgramFiles%\Coopen\image
    6 %ProgramFiles%\Coopen\image\Photo
    7 %ProgramFiles%\Coopen\image\Photo\local Photo
    8 %ProgramFiles%\Coopen\image\Wallpaper
    9 %ProgramFiles%\Coopen\image\Wallpaper\coopen wallpaper
    10 %ProgramFiles%\Coopen\image\Wallpaper\local wallpaper
    11 %ProgramFiles%\Coopen\Resource
    12 %ProgramFiles%\Coopen\Resource\SkinFormal
    13 %ProgramFiles%\Coopen\Templete
    14 %ProgramFiles%\Winsoftware.
    15 %ProgramFiles%\Winzp
    16 %Programs%\Coopen
    17 %Temp%\nsc8.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VBSFile\DefaultIcon]
Loading...