Adware in Chrome, Edge and Firefox. AV can't find the problem

Status
Not open for further replies.

Jumagoro

New Member
Thread author
Jan 23, 2021
3
Hello Guys,

first of all: Huge thanks for helping people in this forum. I'm from Germany so my english isn't the best and also the FRST-Reports are partly on german (i can translate if necessary).
To my Problem: A few days or weeks (I'm not quite sure) ago I noticed a huge amount of Ads in front of any google search within chrome, firefox and Edge. I already took following steps:
1. Reinstalled all browsers (nothing changed)
2. Searched for any malware/malicious extensions manually (nothing found)
3. Tried out different anti-virus programs (Avira, Kaspersky, Malwarebytes + Adwcleaner), but nothing was found. (I only ran / installed one at a time)
4. There is only one interesting thing: Malewarebyte's Adwcleaner can't find anything, but if I run the basic repairs afterwards, the ads are removed (until next reboot)

I also noticed the "Managed by your organization"-Label on top of the chrome settings and also can't explain why this is the case.
I hope you can help me with my case.

Best regards,
Gordian
 

Attachments

  • Addition.txt
    30.3 KB · Views: 11
  • FRST.txt
    85.6 KB · Views: 11
Last edited:

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,425
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

If the problem persists and Chrome is Synced with other Devices reset it.



Execute the suggested fix.

Restart the computer normally.
===========

Yo may still have some work to do.

Why Does Chrome Say It’s “Managed By Your Organization?”

Follow the instructions on the page.
----

Please post the Fixlog.txt and let me know what problem persists.
 

Attachments

  • fixlist.txt
    963 bytes · Views: 12

Jumagoro

New Member
Thread author
Jan 23, 2021
3
Thanks for the fast reply, unfortunately the ads are still there.

I ran the fixlist.txt you provided with FRST.
I turned off the chrome sync + deleted all stored sync-data.

Do you have any idea what adwcleaner does in the basic-repair steps (all additional configurations offline, as shown in the screenshot), since this fixes the problem until a reboot.
 

Attachments

  • adwcleaner_temp_solve_settings.PNG
    adwcleaner_temp_solve_settings.PNG
    32.4 KB · Views: 5
  • Fixlog.txt
    4.3 KB · Views: 11

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,425
Hi,

Did you check this?
Need any help to continue?
Why Does Chrome Say It’s “Managed By Your Organization?”
===

If the problem persists please run the Farbar Scan and post Fresh Logs for my review.

p.s.
Please confirm that you are using Chrome as your default browser.
 
  • Like
Reactions: upnorth

Jumagoro

New Member
Thread author
Jan 23, 2021
3
Hey Nasdaq,

thanks for your help.
I just reinstalled Windows to get a clean setup again. It seemed to me as the easiest and safest way.

Have a great day,
Gordian
 

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,425
Hi,
Thank you for the info.
This topic will be closed.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top