Welcome to the Virus Encyclopedia of Panda Security.
The objective of this worm is to advertise the blog of its author, as the modifications it carries out in the system (Desktop wallpaper, Windows Explorer background, Internet Explorer start page) display the name of the author's weblog. It spreads through removable devices, like USB keys.
|First detected on:||May 19, 2010|
|Detection updated on:||May 31, 2010|
StartPage.DIH is a visual worm that carries out several modifications in the system in order to advertise the blog of its author. Despite not being a destructive malware, its payload and modifications can be annoying for the infected user, as:
- it changes the Desktop wallpaper.
- it modifies the background of the root directory of the Windows Explorer, as well as the backgroung of the taskbar when users are browsing through the Windows Explorer.
- it establishes as Internet Explorer website the weblog of the author of the worm.
StartPage.DIH spreads making copies of itself with the name FUNNY.EXE in the removable devices connected to the computer, like USB keys. Additionally, it also creates copies of itself in the mapped drives.
StartPage.DIH is easy to recognize, as it displays the following symptoms:
- When it is run, a nebulous effect os created in the computer screen and then, the Desktop wallpaper is changed to another image.
The following image belongs to the nebulous effect:
This other belongs to the Desktop wallpaper established by the worm:
- It also modifies the background oof the root directory:
- It establishes as Internet Explorer start page the following website, which belongs to a Persian weblog:
In order to understand better the process StartPage.DIH follows, an explanatory video is at your disposal.