A technician resolves a browser hijacking issue on a user's computer by clearing browser settings, resetting the default search engine, and removing unauthorized extensions. However, as soon as the user restarts the computer and launches the web browser, the search engine and homepage immediately revert back to the malicious redirection site. Which of the following is the MOST likely cause of the persistent browser modification?
- A malicious background process or scheduled task is restoring the unauthorized settings upon reboot.Answer
- BThe web browser's temporary internet files and cached cookies were not cleared prior to performing the browser reset.
- CStale authentication entries stored within Windows Credential Manager are redirecting web traffic.
- DThe workstation is currently being targeted by a social engineering spear phishing campaign.
Answer
A malicious background process or scheduled task is restoring the unauthorized settings upon reboot.
The correct answer highlights that a background startup mechanism, such as a scheduled task or persistent process, is actively restoring the malicious browser configuration upon reboot. When manual browser resets fail to persist across system reboots, technicians must investigate auto-start locations and active background processes to eliminate the root malware component.
Step-by-Step Solution
Key Concept
Browser Hijacker Persistence & Remediation