Home Malware Programs Browser Hijackers Startgo123.com

Startgo123.com

Posted: June 29, 2016

Threat Metric

Ranking: 8,314
Threat Level: 5/10
Infected PCs: 21,791
First Seen: June 29, 2016
Last Seen: October 16, 2023
OS(es) Affected: Windows


Startgo123.com is a suspicious search platform that the experts encourage you to avoid. Startgo123.com is associated with a persistent Web add-on that may enter inconspicuously. The experts call these parasites browser hijackers because they may cause a variety of unpleasant changes to Google Chrome, Mozilla Firefox and Internet Explorer. Startgo123.com has been designed for one simple reason, which is to cause page impressions on promoted third-party sites. To accomplish its mission, Startgo123.com may display manipulated results. Startgo123.com places sponsored links above those that match your query in the best possible way. Unlike legit search providers, Startgo123.com may not label its ads properly. This means that you may start going to sponsored domains without even suspecting the corresponding links were included artificially. This way, it is possible to start wasting time on platforms irrelevant to your search terms. An even greater risk is that some of the affiliated sites may be unsafe. If they offer you an update for Java/Adobe or a brand new program, you should refuse because it may be threatening. It is also advisable to ignore all security warnings as they may try to make you dial bogus support agents. The browser hijacker related to Startgo123.com may enter when you install software bundles silently. This approach may be misleading if the user doesn't pay attention to the details. You should never click on the 'I agree' and 'Next step' buttons without reading the text. The experts remind you that the 'Advanced' installation guides usually provide a list of all application included in the bundle. This way, you should succeed in keeping the unwanted ones away. Once the parasite enters, it may make Startgo123.com your homepage automatically. The most efficient method to eliminate this parasite from your Web clients is to use special security software.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttp_www.startgo123.com_0.localstoragehttp_www.startgo123.com_0.localstorage-journalRegexp file mask%WINDIR%\system32\NetUtils2016.dll%WINDIR%\system32\NetUtils2016.exe%WINDIR%\SysWOW64\NetUtils2016.exeHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\DOMStorage\startgo123.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.startgo123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\startgo123.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.startgo123.comSYSTEM\ControlSet001\Services\NetUtils2016SYSTEM\ControlSet001\Services\NetUtils2016srvSYSTEM\ControlSet002\Services\NetUtils2016SYSTEM\ControlSet002\Services\NetUtils2016srvSYSTEM\CurrentControlSet\Services\NetUtils2016SYSTEM\CurrentControlSet\Services\NetUtils2016srv

Additional Information

The following directories were created:
%PROGRAMFILES%\Mozilla Firefox\browser\features\googletestNT@mozillaonline.com%PROGRAMFILES(x86)%\Mozilla Firefox\browser\features\googletestNT@mozillaonline.com
The following cookies were detected:
startgo123.com
The following URL's were detected:
startgo123.com
Loading...