d.startpagea.com virus

In the “new” tab of Google Chrome there is a small spam virus. But something wrong with their server:

Today, the result of their spam:


<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>410 Gone</title>
</head><body>
<h1>Gone</h1>
<p>The requested resource
/widget/render/hash/a38043d186a16a54eea354cb79f97e75

is no longer available on this server and there is no forwarding address.
Please remove all references to this resource.</p>
<hr>
<address>Apache/2.2.16 (Debian) Server at d.startpagea.com Port 80</address>
</body></html>

The avast antivirus has never see that it was a virus. How is it treated?

run AdwCleaner …and click clean
run Malwarebytes and remove what it find http://forum.avast.com/index.php?topic=53253.0

attach logs here

did that help?

AdwCleaner help me, thank you.

The log of AdwCleaner:


***** [ Services ] *****

[#] Service Deleted : DefaultTabSearch
[#] Service Deleted : DefaultTabUpdate

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Program Files\DefaultTab
Folder Deleted : C:\Program Files\MyPC Backup 
Folder Deleted : C:\Users\Sasha\AppData\Roaming\DefaultTab
Folder Deleted : C:\Users\Sasha\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
File Deleted : C:\Users\Sasha\AppData\Roaming\Mozilla\Firefox\Profiles\6osrhaky.default\Extensions\addon@defaulttab.com.xpi
File Deleted : C:\Users\Sasha\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\Sasha\AppData\Roaming\Mozilla\Firefox\Profiles\6osrhaky.default\searchplugins\bingp.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\Default Tab
Key Deleted : HKCU\Software\DefaultTab
Key Deleted : HKCU\Software\AppDataLow\Software\DefaultTab
Key Deleted : HKLM\Software\Default Tab
Key Deleted : HKLM\Software\DefaultTab
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab Chrome
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16686


-\\ Mozilla Firefox v25.0 (en-US)

[ File : C:\Users\Sasha\AppData\Roaming\Mozilla\Firefox\Profiles\6osrhaky.default\prefs.js ]


-\\ Google Chrome v29.0.1547.76

[ File : C:\Users\Sasha\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [4244 octets] - [29/10/2013 21:12:27]
AdwCleaner[S0].txt - [4226 octets] - [29/10/2013 21:23:21]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4286 octets] ##########

attach the logs…
below the box you post in see… attachment and other options

Attached

your Malwarebytes log say no action taken … did you not click remove selected after scan?

if not, update malware bytes, run new quick scan, make sure evrything is marked for removal and…click remove selected

do you still have the problem?

After AdwCleaner I don’t have problem with my browser (google chrome). I clicked remove selected and now, I take a full scan. 8 objects detected… I’ll wait the end of scan… finished