All symptoms as described; I have recently downloaded several Chrome extensions but even after eliminating the more likely of culprits the issue remains. As I said, I followed all the instructions in the redirect virus removal article, all programs found and eliminated threats, I reset my Chrome settings and still have this issue.

After reading through some similar threads I can tell you that this happens on almost every site, every time I click a link it redirects and opens the same page in a new tab. Nearly every keyword related to computers is a green, underlined link that, when hovered over, provides a link to an ad/more malware.

Thanks in advance for any guidance.
 

Attachments

TwinHeadedEagle

Removal Expert
Staff member
Verified
Hello,


Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.

Running it on another one may cause damage and render the system unstable.

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    icon and select
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finishes FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
 

Attachments

TwinHeadedEagle

Removal Expert
Staff member
Verified
One more scan. How is your computer behaving now?

Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    icon and select
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.


  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 
Still the same only now my Twitter account has been hacked. I was informed of a login in Toronto (not me) and changed my password. Not 5 minutes later I was informed of another login in Toronto and changed my password to one generated by LastPass which is encrypted. Just hoping like hell they don't have access to my bank accounts.
 

Attachments

TwinHeadedEagle

Removal Expert
Staff member
Verified
Fix with AdwCleaner

Please download AdwCleaner by Xplode and save the file to your Desktop.
  • Right-click on
    icon and select
    Run as Administrator to start the tool.
  • Accept the Terms of use.
  • Wait until the database is updated.
  • Click Scan.
  • When finished, please click Clean.
  • Your PC should reboot now.
  • After reboot, logfile will be opened. Copy its content into your next reply.
Note: Reports will be saved in your system partition, usually at C:\Adwcleaner
 
# AdwCleaner v6.044 - Logfile created 05/03/2017 at 12:34:57
# Updated on 28/02/2017 by Malwarebytes
# Database : 2017-03-02.1 [Local]
# Operating System : Windows 10 Home (X64)
# Username : Sam - DESKTOP-NV17STL
# Running from : C:\Users\Sam\Downloads\AdwCleaner.exe
# Mode: Clean
# Support : Customer Support & Help Center



***** [ Services ] *****



***** [ Folders ] *****



***** [ Files ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****



***** [ Scheduled Tasks ] *****



***** [ Registry ] *****



***** [ Web browsers ] *****



*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [7467 Bytes] - [04/03/2017 15:34:21]
C:\AdwCleaner\AdwCleaner[C2].txt - [821 Bytes] - [05/03/2017 12:34:57]
C:\AdwCleaner\AdwCleaner[S0].txt - [7243 Bytes] - [04/03/2017 15:33:32]
C:\AdwCleaner\AdwCleaner[S1].txt - [1286 Bytes] - [05/03/2017 12:34:47]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1039 Bytes] ##########
 

TwinHeadedEagle

Removal Expert
Staff member
Verified
Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.

Running it on another one may cause damage and render the system unstable.

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    icon and select
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finishes FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
 

Attachments

Seems to be fixed!!

Fix result of Farbar Recovery Scan Tool (x64) Version: 05-03-2017
Ran by Sam (05-03-2017 13:00:48) Run:2
Running from C:\Users\Sam\Downloads
Loaded Profiles: Sam (Available Profiles: Sam)
Boot Mode: Normal
==============================================

fixlist content:
*****************
2017-02-25 15:49 - 2017-02-25 16:15 - 00000000 ____D C:\Users\Sam\AppData\Roaming\tagspaces
2017-02-25 15:42 - 2017-02-25 15:42 - 00000000 ____D C:\Program Files\TaglibHandler
2017-02-25 15:42 - 2017-02-25 15:42 - 00000000 ____D C:\Program Files (x86)\TaglibHandler
2017-02-25 15:36 - 2017-02-25 15:36 - 00000000 ____D C:\Users\Sam\AppData\Local\Computer_ConQuest_Ltd
2017-02-25 15:31 - 2017-02-25 16:16 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Rummage
2017-02-20 09:20 - 2016-11-29 00:29 - 00000634 _____ C:\Users\Sam\Documents\tumblr.txt
2017-02-18 14:39 - 2017-02-18 14:39 - 00000000 ____D C:\Users\Sam\AppData\LocalLow\uTorrent
2017-02-18 14:07 - 2017-02-18 14:07 - 00000000 ____D C:\Users\Sam\AppData\Roaming\BitLord
2017-02-18 14:07 - 2017-02-18 14:07 - 00000000 ____D C:\Users\Sam\AppData\Local\BitLord
2017-02-18 14:07 - 2017-02-18 14:07 - 00000000 ____D C:\Users\Sam\.BitLord
2017-02-18 13:58 - 2017-02-18 15:14 - 00000000 ____D C:\Users\Sam\AppData\Roaming\TunnelBear
2017-02-18 13:58 - 2017-02-18 13:58 - 00000000 ____D C:\Users\Sam\AppData\Local\IsolatedStorage
2017-02-18 13:52 - 2017-02-18 13:52 - 00000000 ____D C:\Users\Sam\AppData\Local\drmingw
2017-02-18 13:52 - 2017-02-18 13:52 - 00000000 ____D C:\ProgramData\dbg
*****************

C:\Users\Sam\AppData\Roaming\tagspaces => moved successfully
C:\Program Files\TaglibHandler => moved successfully
C:\Program Files (x86)\TaglibHandler => moved successfully
C:\Users\Sam\AppData\Local\Computer_ConQuest_Ltd => moved successfully
C:\Users\Sam\AppData\Roaming\Rummage => moved successfully
C:\Users\Sam\Documents\tumblr.txt => moved successfully
C:\Users\Sam\AppData\Roaming\TunnelBear => moved successfully
C:\Users\Sam\AppData\Local\IsolatedStorage => moved successfully
C:\Users\Sam\AppData\Local\drmingw => moved successfully
C:\ProgramData\dbg => moved successfully

==== End of Fixlog 13:00:48 ====