browser hijacker chrome - redirects to bing, ask.com

Status
Not open for further replies.

keea

New Member
Thread author
May 19, 2023
11
Hi,
A few days ago I noticed that my Chrome browser would get re-directed to either ask.com or bing. I removed all my extensions and ran a bunch of scans, some of which detected malware, which I deleted. But it hasn't solved the problem. I've reset chrome settings.

The problem persits...I've downloaded Guardio, which sees the browser hijacker (as search-location), and blocks the re-direction. But it is causing other syncing issues with my accounts, and i'd like to take care of the issue once and for all.

Any tips? Thanks alot
 

Attachments

  • Addition.txt
    87.2 KB · Views: 6
  • FRST.txt
    72.9 KB · Views: 10

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Please download Malwarebytes Anti-Malware from Malwarebytes or
from BleepingComputer

Right-click on the MBAM icon and select Run as administrator to run the tool.
Click Yes to accept any security warnings that may appear.
Once the MBAM dashboard opens, on the right detail pane click on the word "Current" under the Scan Status to update the tool database.
On the left menu pane click the Settings tab, and then select the Protection tab on the top.
Under the Scan Options, turn on the button Scan for rootkits and Scan within archives.
Click the Scan tab on the right detail pane, select Threat Scan and click the Start Scan button
Note: The scan may take some time to finish, so please be patient.
If potential threats are detected, ensure to check mark all the listed items, and click the Quarantine Selected button.
While still on the Scan tab, click the View Report button, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
The log can also be viewed by clicking the log to select it, then clicking the View Report button.

Please post the log for my review.

Note: If asked to restart the computer, please do so immediately.

Let me know if the problem persists.
===
 

keea

New Member
Thread author
May 19, 2023
11
Thanks Nasdaq.

Here is the report from Malwarebytes
It didn't seem to have found anything.

Let me know if there's other steps I can take, thanks alot
 

Attachments

  • malwarebytesreport.txt
    1.2 KB · Views: 4

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===



Please post the Fixlog.txt and let me know if the problem persists.
 

Attachments

  • Fixlist.txt
    11.5 KB · Views: 12

keea

New Member
Thread author
May 19, 2023
11
The problem is still happening. Here is the Fixlog.

Thanks alot
 

Attachments

  • Fixlog.txt
    47.6 KB · Views: 2

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Let's search the registry:
Run the Farbar program. There is a Search Registry button on the FRST Console. Paste this term in bold in the box and click OK.

Search registry: ask.com


Post the logs for my review.
 
  • Like
Reactions: oldschool

keea

New Member
Thread author
May 19, 2023
11
I pasted ask.com in the box and ran the search registry.

Here is the log

Thank you!
 

Attachments

  • SearchReg.txt
    582 bytes · Views: 3

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

There was a syntax error in my fixlist.

Please do this.

Launch Notepad, and copy/paste all the blue instructions below to it.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]


Then, disconnect from the Internet!
Next,
Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
Optional if the following programs are in your computer.
Note that since the Domains are deleted SpywareBlaster protection must be re-enabled. Spybot's Immunize feature must be used again, also you have to re-install IE-SpyAd if installed.

Restart the computer normally.

Let me know if the problem persists.
 

keea

New Member
Thread author
May 19, 2023
11
Hi, I ran the fixme.reg file.
Should I also download Spyware Blaster if i don't have it on my computer?

The problem is still there - when I do a search in the box, i can see that it first links to search-location.com before redirecting to bing.
Thx!
 

keea

New Member
Thread author
May 19, 2023
11
Unfortunately I have a PC and not a Mac, is there a version for PC?
Thanks
 

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

As in post no 6. paste this in the search box and then click the search Registry Button.

search-location.com[
 

keea

New Member
Thread author
May 19, 2023
11
Thanks, it doesn't seem like it has found anything.

When I open a Chrome tab, it now goes directly to Search Marquis (before it used to show up as google on opening).

Do you think it is worth reformatting the computer?
Or do you think there are still steps we can take to try to find this thing?

Thanks again for your help
 

Attachments

  • SearchReg.txt
    247 bytes · Views: 3

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Possibly my fault if nothing was found.
There was an error in my syntax.


As in post no 6. paste this in the search box and then click the search Registry Button.

Change this search-location.com[

to

search-location.com


copy and paste the text to make sure.
 

keea

New Member
Thread author
May 19, 2023
11
Hey thanks, ran it again !
 

Attachments

  • SearchReg.txt
    251 bytes · Views: 3

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

No need to reformat this computer.
Only Chome is the issue.

The problem could be coming from Syncing Chrome with other Devices.

If the problem persists and Chrome is Synced with other Devices reset it.
It could be any device, phone, tablet other computers etc... Make sure you check it our.



Execute the suggested fix.

Restart the computer normally.
===========

If all fails Delete and reinstall Chrome.

Uninstall Google Chrome

Select the Windows 10 Operating System and follow the directives.

Make sure you Restart the computer when done.

The reinstall chrome. Follow these directives.

Download & install Google Chrome


Select the Windows operating system and install a fresh copy.

If at any time you need instructions please ask before proceeding.

Keep me posted.
 

keea

New Member
Thread author
May 19, 2023
11
Hey, I've followed these instructions, and uninstalled and re-installed chrome. and my new tabs still lead to Search Marquis.

What would you suggest at this point?
Thanks
 

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Firefox being your default browser try the following.

Clean the Firefox Cache.
<<<>>>


Mae sure it's not a Syncing issue.

If the problem persists and you are Syncing Firefox it with other Devices reset it.

Navigate to this page and Remove it as suggested.


When done restart the computer normally.

If all is well.

Return to your Firefox Account and Click the Connect button. (Your call)

Reset the sync if you want.

Restart the computer normally.
<<<>>>

Remove Firefox using the instructions one this page.

Restart the computer normally.

If the problem is not solved try this.

Make sure that you have reset Firefox's syncing.

If the problem persists and you are Syncing Firefox it with other Devices reset it.

Navigate to this page and Remove it as suggested.


When done restart the computer normally.

If all is well.

Return to your Firefox Account and Click the Connect button. (Your call)

Reset the sync if you want.

Restart the computer normally.
<<<>>>

In the event that all fails:

Remove and re-install Firefox it may be compromised.

Navigate to this page.

Follow all the directives


You can then reinstall Firefox if you want it.

p.s.
This process will not remove your Firefox profile data (such as bookmarks and passwords), since that information is stored in a different location.
Follow the suggested directives.
<<<>>>
 

keea

New Member
Thread author
May 19, 2023
11
Hi, I've never used Firefox. I was using Chrome.
I've switched to Brave which seems to have solved the issue.
It's just frustrating that I can't use Chrome in the end. But thanks alot for your help!
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top