Computing.Net > Forums > Security and Virus > StartPage-CD is a virus?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

StartPage-CD is a virus?

Reply to Message Icon

Name: ER4S3R
Date: March 15, 2004 at 08:45:46 Pacific
OS: Windows XP
CPU/Ram: AMD/512
Comment:

Hi Guys,

Has anybody heard of a virus called StartPage-CD, McAfee caught it last night when I extracted a dos game called "Super Mario 2 South Park" which was in my hotmail inbox sent to me by a friend.

However McAfee couldn't delete or quarantine the virus (not sure if it is). It created some files in my Local Settings/Temp dir which couldn't be deleted either, until I tried safe mode (see screenshots below marked NEW).

Click HERE for Screenshots

I was wondering if anybody could confirm whether it is in fact a virus? Searched Symantec and McAfee databases, no results lol.

ER4S3R.
Thx in advance.

____________________________________________
### Nobody believes the official spokesman, but everybody trusts an unidentified source ###



Sponsored Link
Ads by Google

Response Number 1
Name: blender
Date: March 15, 2004 at 10:02:17 Pacific
Reply:

Also known as troj_bookmark.a (trend micro)

Removes your IE favorites and replaces with a crappy list of url's.
Changes IE homepage to http://webcoolsearch.com

Look on nortons site for trojan bookmarker.

Here's the url for trend micro's write-up:

http://de.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=TROJ_BOOKMARK.A

CWShredder might kill it too.
_______________________________________

I never give up!

Windows Update


0

Response Number 2
Name: voldemort
Date: March 15, 2004 at 10:17:54 Pacific
Reply:

try a online scan

http://www.antivirus.com

they have a free online antivirus scan


0

Response Number 3
Name: ER4S3R
Date: March 15, 2004 at 10:26:16 Pacific
Reply:

Thank-you blender! so that's what it was, fortunately I think McAfee prevented it from running, which is why my IE favourites are still left intact. :-D

IMHO, those damn webcoolsearch peepz @ http://webcoolsearch.com/ need to be taught a lesson. They're getting away with murder, maybe somebody ought carry out dos attacks on their website (just an opinion :-P).

Cheers blender!

ER4S3R.

____________________________________________
### Nobody believes the official spokesman, but everybody trusts an unidentified source ###


0

Response Number 4
Name: blender
Date: March 15, 2004 at 20:04:40 Pacific
Reply:

ER4S3R

Likely mcafee did stop it...When you tried extracting the zip file you should have gotten zip errors (access denied) when mcafee stopped it.
When you extracted the file...it would extract to a temp directory first before installing.
Thing I find with mcafee is when downloading zip files mcafee does not see the virus until unzipped or manual scan is done on the file itself. It will find it when exracting tho.

I'm quite sure you are not the only one wanting to trash CWS sites.
They would be really hard to attack tho cus they have hundreds (mabye thousands) of affiliate sites doing the same crap, and new sites joining in every day!
As soon as some are discovered..they are taken down and new ones put up.
Persistant b***ards they are!

Cheers!
__________________________

I never give up!

Windows Update


0

Response Number 5
Name: ER4S3R
Date: March 16, 2004 at 03:45:22 Pacific
Reply:

Yes I hope it didn't install any hidden stuff in the registry lol. I thought I'd do another scan with AVG in safe mode just in case, turned out to be clean.

The workloads for most AV software are getting harder, as the viru$-writers get more advanced. Hopefully laws will become tighter and those low-lifes B@****s at CWS will get what's coming to them.

Thx for the input

ER4S3R.



____________________________________________
### Nobody believes the official spokesman, but everybody trusts an unidentified source ###


0

Related Posts

See More



Response Number 6
Name: bobbob911
Date: April 6, 2004 at 07:24:22 Pacific
Reply:

Hello,

I have this same problem. McAfee is flagging a file in local settings\temp\gate.exe\GATE.EXE, however this file does not exist.

I tried CWShredder and it finds nothing.

mcafee gives be the warning every day when it runs.

Any ideas?

Thanks!

Andy K.


0

Response Number 7
Name: monteith
Date: April 13, 2004 at 09:34:06 Pacific
Reply:

McAfee's online scan found the same file on my computer. I had to change the search settings from the default to search for hidden files and folders to find it. The files were in C:\Documents and Settings\<account name>\Local Settings\Temp.

Hope this helps.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: StartPage-CD is a virus?

Is a virus capable of doing this? www.computing.net/answers/security/is-a-virus-capable-of-doing-this/10158.html

Is This A Virus??? www.computing.net/answers/security/is-this-a-virus/13799.html

is this a Virus? www.computing.net/answers/security/is-this-a-virus/20899.html