Browser Keeps Changing to Bing or Yahoo Despite Default Browser Being Different

Status
Not open for further replies.

Shadowkitt10

New Member
Thread author
Sep 7, 2023
3
This has happened recently, today in fact; I can still access google chrome, but the initial search keeps changing to bing or yahoo despite the default browser being set to Chrome. As long as I quickly open a new tab and re-enter my search, it directs me to google chrome.

Here is a list of what I have tried:
  • Removed all other search engines from the list in settings and ensuring the default is set to google.
  • Changing and even straight up removing McAfee as it worked for others; has not solved the issue for me.
  • Reset settings in the google chrome settings option.
  • Ran two separate malware scans, nothing pops up and no changes either. Did this through computer settings;
    • 1st: Virus and threat protection -> quick scan.
    • 2nd: scan options -> Microsoft Defender Antivirus (offline scan).
  • Removed all browser extensions, suspicious or not. Even had to delete a folder in hidden files for one as it did not have a remove option; it was called PongoPygmaeus. I can not find a single thing about it online. It just sends me to searches of the Bornean orangutan, regardless of if I include "brower extension" in the search bar. I have no idea if this browser extension has actually been removed, or if it even is malware; depsite the file being gone, it still shows as installed? I removed it via C:\Users\your username\Appdata\Local\Google\Chrome\User Data\Default\Extensions

I am at a complete loss of what to do.
 

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

In order to give your sound advice I need to see what was installed on this compromised computer.

Please. download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file:
In the Reply section in the bottom of the topic Select Click the Attach Files.
Navigate to the location of the File.
Click the file. It will appear in the reply section.
Click the Post Reply button.

Please post the logs for my review.

Wait for further instructions
 
  • Like
Reactions: Shadowkitt10

Shadowkitt10

New Member
Thread author
Sep 7, 2023
3
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

In order to give your sound advice I need to see what was installed on this compromised computer.

Please. download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file:
In the Reply section in the bottom of the topic Select Click the Attach Files.
Navigate to the location of the File.
Click the file. It will appear in the reply section.
Click the Post Reply button.

Please post the logs for my review.

Wait for further instructions
Hi,

I have scanned and uploaded the files. If there are any issues with them and need to be re-uploaded or re-scanned, let me know.
 

Attachments

  • Addition.txt
    60.4 KB · Views: 6
  • FRST.txt
    60.7 KB · Views: 4

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hi,

You did good.

Remove these programs in bold using the Control Panel > Programs > Programs and Features...
Chromstera (HKLM-x32\...\Chromstera) (Version: 117.0.5903.0 - The Chromstera Authors)
Chromstera Browser (HKLM\...\Chromstera Browser 1.0.0.0) (Version: 1.0.0.0 - Chromstera Premium Solutions)

Restart the computer normally after the removal.
<<<>>>

Now exedute this fix.

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.
 

Attachments

  • Fixlist.txt
    7.4 KB · Views: 4
  • Like
Reactions: Shadowkitt10

Shadowkitt10

New Member
Thread author
Sep 7, 2023
3
Hi,

You did good.

Remove these programs in bold using the Control Panel > Programs > Programs and Features...
Chromstera (HKLM-x32\...\Chromstera) (Version: 117.0.5903.0 - The Chromstera Authors)
Chromstera Browser (HKLM\...\Chromstera Browser 1.0.0.0) (Version: 1.0.0.0 - Chromstera Premium Solutions)

Restart the computer normally after the removal.
<<<>>>

Now exedute this fix.

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.
Hello again,

I was able to remove Chromstera no problem, however I did get a pop up from Windows Installer when trying to uninstall Chromstera Browser, "This action is only valid for products that are currently installed." I searched my computer to ensure that it really wasn't on my computer. Just thought I would make note of that.

I have tested multiple searches of random topics online, and so far all of them are via google chrome without me having to do anything :).
 

Attachments

  • Fixlog.txt
    26.9 KB · Views: 4
  • Like
Reactions: nicolaasjan

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hi,

The prgrams were removed from the computer but for some unkinown reasons are still listed in the registry.

You can remove them by following the insformation on tihis page.

If at any time you need advice before proceeding let me know.

p.s.
Nothing bad can come from these remnant entries.
 
  • Like
Reactions: Shadowkitt10
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top