Author Topic: Browser Hijack Chromestart4.ru  (Read 4090 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Browser Hijack Chromestart4.ru
« on: August 28, 2016, 06:14:34 PM »
Somehow a browser hijack has installed itself on my laptop (http://chromestart4.ru/i/rt4.html). I have scaned with Avast, Malwarebytes, Norton Power Eraser and Windows Malicious Software Removal tool and none of them were able to to find it. I did a search on my machine for any part of the file and did not find anything. I did the same search in my registry and did not find anything. I checked my installed programs and did not find anything that should not be there. I also checked my chrome extensions and did not see a problem. I checked my Chrome setting to see if the home page had been change and it was not. It is still set to www.google.com. My last resort was to try a system restore; however, my system protection was turned of for my drive and system restore for some reason. When I turned them back on it said I had no restore points so I could not role back. I am out of thoughts and thought I would contact the professionals to see if you guys can come up with a fix for this thing. I search the net for answers but there seems to be only one site that offers a solution which is to download their malware program. Makes me think that they probably are responsible for the exploit in the first place. This is the site address for the tool/program (http://www.freezingcomputer.com/tag/remove-chromestart4-ru/). The name of the program is Spyhunter 4.  I have not downloaded it cause WOT and Avast do not have a reputation rating for it.

The hijacker only seems to appear when I open my browser and originally start to go to (http://mir2sky1.com/882Bh) but then reverts to (http://chromestart4.ru/i/rt4.html) which looks like a cheap copy of google.com. I checked the mir2shy1 address for a rep rating but it appears to be a new site. Again I really think Spyhunter 4 and the exploit are within the same family. Thanks for your help.

« Last Edit: August 28, 2016, 06:18:31 PM by jorhyan »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Browser Hijack Chromestart4.ru
« Reply #2 on: August 28, 2016, 08:43:14 PM »
SpyHunter will only remove what it detect if you pay

You may try clear your browsers with AdwCleaner > http://www.bleepingcomputer.com/download/adwcleaner/

If still a problem follow instructions in the guide Eddy gave link to and a malware expert will assist you






REDACTED

  • Guest
Re: Browser Hijack Chromestart4.ru
« Reply #3 on: August 29, 2016, 03:10:25 PM »
Thanks guys. After running two more scans with Avast and Malwarebytes last night and not finding anything, I finally uninstalled Chrome and Firefox and it appears to be gone. If it shows again then I will post. Thanks again.

REDACTED

  • Guest
Re: Browser Hijack Chromestart4.ru
« Reply #4 on: August 31, 2016, 09:35:36 PM »
after various checks with anti-malware applications...

Chromestart4.ru is simple to solve (i have solved )

go to google/firefox application folder
and delete

google.bat, google.bat.exe and... all .lnk files (in their locations),
firefox.bat, firefox.bat.exe and... all .lnk files (in their locations)

is the same for all browser... i believe
« Last Edit: August 31, 2016, 09:37:42 PM by walalo »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Browser Hijack Chromestart4.ru
« Reply #5 on: August 31, 2016, 09:44:44 PM »
That is not a real solution.
It had to come from somewhere and that is not removed with what you tell.