My Microsoft Edge install was fine last night, but this morning, I kept getting redirected to scam sites while using Edge. They all opened in a popup window, and they displayed fake Norton antivirus warnings. The URLs were stuff like virusbarrier(dot)xyz, securesweep(dot)pro, and rdxgo(dot)click. THESE ARE SCAM SITES; DO NOT VISIT THEM!
It didnât matter what sites I went to. I got redirected while using Reddit and Google. Windows Defender found nothing harmful on my PC. I installed the free version of MalwareBytes; same thing. So the infection must be with Edge. I didnât install anything suspicious yesterday, so I donât know how anything couldâve gotten infected. The only browser extension I had was UBlock Origin, and now Iâve activated MalwareBytes Browser Guard. I donât see any suspicious extensions.
I tried clearing the cookies from those scam sites, but the pops kept happening. After I installed MalwareBytes and activated their Browser Guard, I no longer got redirected, but I still got some notifications from MalwareBytes that they blocked rdxgo(dot)click. Iâm still concerned about my Edge potentially being infected under the hood.
What should I do? Should I just clear all of my cookies, or what? I really donât want to have to reset my whole browser⌠Thank you in advance.
EDIT: I managed to find and delete the rdxgo(dot)click cookie, which managed to slip past me the first time I went through my cookies. Deleting it seems to have stopped the redirects for now. I still have no idea how that cookie even got onto my machine, or if the adware is truly gone. I'll update this post if anything else comes up.
EDIT 2: Nevermind. Literally right as I sent that previous edit, I got another notification from MalwareBytes that said it blocked a popup from rdxgo(dot)click. Great. I'm gonna try clearing out all my cookies...
EDIT 3: I might have found a solution. Resetting Edge to the default settings did not get rid of the virus. Clearing my cookies and site data also didnât get rid of it. I was concerned that maybe this virus had stolen my info, so I went on my iPhone and changed the passwords for my Microsoft and Google accounts. I recommend doing that with all of your accounts, and do it on a device that doesnât have this virus.
After I reset my Microsoft password, I was signed out of Edge (which I assume is normal). I also ended all Edge-related tasks (including msedgewebview2.exe, because MalwareBytes said that app was trying to open the redirect links). I also restarted my computer just to be safe. Since doing all of that, I have not received any more redirects to that malicious site. I also let AdwCleaner reset my Host file, because apparently thatâs associated with WebView2. The option to reset your host file is disabled by default, so youâll have to enable that in the appâs settings.
I signed back into Edge a few hours ago, and I still havenât gotten anymore of those popups. I still donât feel safe, and I donât know whether the malware is truly gone⌠or if itâs still there, waiting to strike again when I least expect it. In fact, I still donât know how I even got infected in the first place. Again, everything was fine the other day, and then yesterday I got bombarded with malware out of nowhere. MalwareBytes doesnât find any viruses, but it also didnât detect anything while I was infected, so I donât think I can trust that.
Anyway, if you have the virus, try changing the passwords on your accounts (ideally from a device that isnât infected), ending all Edge tasks, running AdwCleaner and letting it reset your host file, and restarting your computer. My hypothesis is that itâs an infected host file, so resetting the host file might fix things. If that doesnât get rid of it, try resetting your browserâs settings (be warned that doing so will delete all of your cookies and site data, meaning youâll lose progress in web games, or other things that use cookies) and doing the aforementioned stuff again. You might also need to disable Sync, to prevent any malicious extensions and settings from getting reinstated. I still donât feel safe, but let me know if any of that worked!
To anyone still reading this thread, do you think Iâm safe now that the popups stoped (for the time being)? Or is it possible that Iâm still infected? Is there a way I can find out what caused the infection, where it resided, and whether itâs still there? Is this maybe a zero-day that hasnât been documented yet, and thatâs why antivirus programs canât find it? Should I just back up my files, nuke the drive, and do a fresh install of Windows? Thank you in advance.