Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Spyware? malware? Or just plain weird...? [Solved]


  • This topic is locked This topic is locked

#16
navymandan

navymandan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
No redirects. Chrome works like it's suppose to in Incognito mode.
  • 0

Advertisements


#17
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK tedious bit now

Start chrome normally
Disable all addons/extensions
Check that there are no redirects
If none, then enable the extensions one at a time checking for redirects between each
Once you have determined which extension it is could you let me know
  • 0

#18
navymandan

navymandan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
The ONLY extension (I didn't know I had this one...)

Posted Image
  • 0

#19
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Disable that extension and then see if the redirects still occur. If they do we will have to cleanly uninstall Chrome and then re-install
  • 0

#20
navymandan

navymandan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
disabled, works like it should...

close, re-open, the extension comes back

deleted the extension from chrome, it works like it should

close, re-open, the extension comes back

uninstalled chrome using built-in Add/Remove Programs function

awaiting further instructions...
  • 0

#21
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets now remove the leftovers from Chrome. This programme can be deleted from the desktop on completion

Please download OTM
  • Save it to your desktop.
  • Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files 
    C:\Users\Daniel Benton\AppData\Local\Google
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    
    :Commands 
    [emptytemp] 
    

  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM and reboot your PC.

THEN

Download and install a fresh copy of Chrome from here https://www.google.c...s.html#security
  • 0

#22
navymandan

navymandan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
All processes killed
========== FILES ==========
C:\Users\Daniel Benton\AppData\Local\Google\CrashReports folder moved successfully.
C:\Users\Daniel Benton\AppData\Local\Google folder moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Daniel Benton
->Temp folder emptied: 20949349 bytes
->Temporary Internet Files folder emptied: 43885139 bytes
->Java cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 8539 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 55718 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 41755 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 2277109 bytes

Total Files Cleaned = 64.00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 09032013_085525

Files moved on Reboot...
C:\Users\Daniel Benton\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File C:\Users\Daniel Benton\AppData\Local\Temp\~DF7A40A56CD665B862.TMP not found!
File C:\Users\Daniel Benton\AppData\Local\Temp\~DF8A83AA559BC8544F.TMP not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\1bikeride-ipad_sm_1378151788[1].jpg not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\1n_rdp4QvAAEBQEEo2Acr2UEB.medium[1].jpg not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\43b40e735eb7362085d95bef7cc2bf65[1].gif not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\90595-thumb[1].jpg not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\ads[1].js not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\crossdomain[7].xml not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\crossdomain[8].xml not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\default[5].jpg not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\g[1].json not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\jstag[1].js not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\pubcode.min[1].js not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\riCA094IST.gif not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\riCA70EYZA.gif not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\snoozn2[1].jpg not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YVR7ABGF\spell_shadow_animatedead[1].gif not found!
File C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VGPMJRP2\activity;src=3385394;type=bluek355;cat=vnc_a945;u10=xXdsVyQq999TYYPu;ord=1[1].gif not found!
C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JJQ987OU\i[1] moved successfully.
C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7D3PIGOK\index[1].htm moved successfully.
File move failed. C:\Users\Daniel Benton\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot...
  • 0

#23
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Once you have re-installed chrome (if you still want it :) ) take it for a test drive
  • 0

#24
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP