Chrome Extension 'AzaleaRhododendron', Unable to Remove, Bing Redirecting

Status
Not open for further replies.

marteis

New Member
Thread author
Sep 13, 2023
3
Hello! Recently in an attempt to download a textbook for school, I unfortunately was careless in downloading the PDF and ended up downloading a type of malware. The download was simply titled 'apps.exe', and despite immediately deleting it the moment I realized my mistake, it has already taken effect.

I believe it is a Bing redirecting virus. Whenever I open Chrome and search something, it will refresh to searchokay.com and multiple websites before redirecting to Bing. I ran multiple virus and malware tools such as MalwareBytes and AVG Internet Security. Each tool says there is no more detectable threat and the problem has been removed after the initial scan, but it is very much still around. I reset all my Google settings, and I have come to find a Google extension that I can neither turn off nor remove titled 'AzaleaRhododendron'. I think this might the source, but I am not very knowledgeable on these things..

I've seen some people have similar problems and find solutions, so I have attached some screenshots and the reports necessary! Thank you in advanced, even just for taking the time to read through this :)
 

Attachments

  • image 1.png
    image 1.png
    29.1 KB · Views: 5
  • image 22.png
    image 22.png
    27.2 KB · Views: 6
  • Addition.txt
    72.1 KB · Views: 5

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Remove this Hijacker program in bold using the Control Panel > Programs > Programs and Features...
Chromstera Update (HKLM\...\Chromstera Update 1.0.0.0) (Version: 1.0.0.0 - Chromstera Browser Research)
<<<>>>

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.
 

Attachments

  • Fixlist.txt
    12.9 KB · Views: 8

marteis

New Member
Thread author
Sep 13, 2023
3
Hello! Thank you for your help! I attempted to remove the hijacker program as you instructed, but whenever I do I receive a pop-up (screenshot attached). Could this be because I had deleted the program in the middle of starting it up? I remember when I realized it was malware, I stopped it mid-program and deleted it.

Otherwise, my Google Chrome has returned to normal and no longer redirects to Bing, and the extension is gone! I will attach the Fixlog as requested.
 

Attachments

  • Fixlog.txt
    30.3 KB · Views: 3
  • image (2).png
    image (2).png
    6.3 KB · Views: 2

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hi,

Good work.

You are correct the bad program was removed but there is still some remant items in he registry.

You can used this directive to remove the registry entry.

If at any time you need help please ask.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top