accidentally downloaded chromestera and my browser redirects to yahoo and bing everytime I search.

Status
Not open for further replies.

Forbid822

New Member
Thread author
Oct 30, 2023
6
Hello, as the title described, I think chromestera had infected my browser as it is difficult to use the browser due to this malware. Could you please assist me on this issue?
 

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

The cause is a bad extension hidden in the a Group Policy.
Run this fix so that we can find out what we are dealing with.

Download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system. and save it to a folder on your computer%27s Desktop. Ensure that you are in an Administrator Account Double-click to run it. When the tool opens click Yes to disclaimer. Check the boxes as seen here:
L7kNU5y.jpg
Press Scan button. It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply. The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply. Please attach the logs for my review. How to attach a file to your reply: In the Reply section in the bottom of the topic Click the %22more reply Options%22 button. [img=[URL]http://deeprybka.trojaner-board.de/eset/eng/attachlogs.png[/URL]] Let me know what problems persists. Wait for further instructions p.s. This program is updated often. If it%27s identified as suspicious by your Anti-Virus program trust it if Downloaded from the link I provided. OR, you should restore the program from the Quarantine folder. ====']https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/[/URL]]Choose the 32 or 64 bit version for your system.[/url]
and save it to a folder on your computer's Desktop.
Ensure that you are in an Administrator Account
Double-click to run it. When the tool opens click Yes to disclaimer.
Check the boxes as seen here:
L7kNU5y.jpg

Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Please attach the logs for my review.
How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
[img=[URL]http://deeprybka.trojaner-board.de/eset/eng/attachlogs.png[/URL]]

Let me know what problems persists.

Wait for further instructions

p.s.
This program is updated often.
If it's identified as suspicious by your Anti-Virus program trust it if Downloaded from the link I provided.
OR, you should restore the program from the Quarantine folder.
====
 

Forbid822

New Member
Thread author
Oct 30, 2023
6
Hi, thank you for your reply, these are the 2 files generated
 

Attachments

  • Addition.txt
    51.3 KB · Views: 2
  • FRST.txt
    63.9 KB · Views: 2

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hi,

Remove this program in bold using the Control Panel > Programs > Programs and Features...
Chromstera (HKLM-x32\...\Chromstera) (Version: 119.0.6019.0 - The Chromstera Authors)
<<<>>>

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.
 

Attachments

  • Fixlist.txt
    8.3 KB · Views: 4

Forbid822

New Member
Thread author
Oct 30, 2023
6
hi, i think everything has been sorted out, thank you.
 

Attachments

  • Fixlog.txt
    26.2 KB · Views: 1
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top