Solved "Felidae" Chrome Extension

Status
Not open for further replies.

LemonSoul364

New Member
Thread author
Jan 23, 2024
9
Copy & pasted from Reddit, I was recommended here!

I have no clue when this extenstion popped up on my PC, it was around the time Starfield just released, but it's definitely been a few months and I'm getting sick of it. I can't change my browser back to Google (my default), I can't even change it to Yahoo!, bing, whatever. It's stuck on this stupid "bangsearch" browser.

I can't delete the extension. I've tried looking it up so many times and I can't figure it out. But I wanna exhaust all of my free options before paying for a professional to do it. Usually I'm pretty careful about not downloading random #####, but Starfield just came out, I was broke but wanted to play it, a friend gave me a link to free download to it (obviously, it didn't work and I'm never downloading ##### like that again).

I'm really not sure what else to do at this point. It says it doesn't source from Chrome, but it doesn't say where it sources from. I've tried to use Command Prompt, I've tried going into the files to hunt extension ID down and delete it. Nothing. There's a "remove" button, but when I click it, it just doesn't respond.

I'll try anything. Thanks in advance.
 

Attachments

  • Screenshot 2024-01-22 213623.png
    Screenshot 2024-01-22 213623.png
    36.3 KB · Views: 5
  • Screenshot 2024-01-22 213909.png
    Screenshot 2024-01-22 213909.png
    15.2 KB · Views: 5
  • Like
Reactions: nicolaasjan

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
532
Hello..! Welcome to MalwareTips..! :)

My name is icotonev and I'm here to help you remove malware ..! Before we begin, please note the following:
  • First, please keep in mind most of us at MalwareTips volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.Logs from malware diagnostic or removal programs can take some time to get analyzed. Also, have in mind that all the experts here are volunteers and may not be available to assist when you post. Please, be patient, while I analyze your logs.
  • It is important to not run any tools or take any steps other than those I will provide for you.Also, do not uninstall or install any software during the procedure, unless I ask you to do so.
  • Cracked or pirated programs are not only illegal, but also can make your computer a malware target. Having such programs installed, is the easiest way to get infected. Thus, no need to clean the computer, since, soon or later, it will get infected again. If you have such programs, please uninstall them now, before we start the cleaning procedure.
  • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
  • Please attach all logs into your post unless otherwise requested.
  • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
  • If you do not reply to your topic after 5 days I will assume it has been abandoned and I will close it.

Please follow the following instruction ..:

Download Farbar Recovery Scan Tool and save it to your desktop. --> IMPORTANT

If your antivirus software detects the tool as malicious, it’s safe to allow FRST to run. It is a false-positive detection.
If English is not your primary language, right click on FRST.exe/FRST64.exe and rename to FRSTEnglish.exe/FRST64English.exe

Note
: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click the FRST icon to run the tool. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach the content of these two logs in your next reply.
---------------------------------------------------

In your next reply, please include:
  • FRST.txt
  • Addition.txt
 
Last edited:

LemonSoul364

New Member
Thread author
Jan 23, 2024
9
Hello..! Welcome to MalwareTips..! :)

My name is icotonev and I'm here to help you remove malware ..! Before we begin, please note the following:
  • First, please keep in mind most of us at MalwareTips volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.Logs from malware diagnostic or removal programs can take some time to get analyzed. Also, have in mind that all the experts here are volunteers and may not be available to assist when you post. Please, be patient, while I analyze your logs.
  • It is important to not run any tools or take any steps other than those I will provide for you.Also, do not uninstall or install any software during the procedure, unless I ask you to do so.
  • Cracked or pirated programs are not only illegal, but also can make your computer a malware target. Having such programs installed, is the easiest way to get infected. Thus, no need to clean the computer, since, soon or later, it will get infected again. If you have such programs, please uninstall them now, before we start the cleaning procedure.
  • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
  • Please attach all logs into your post unless otherwise requested.
  • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
  • If you do not reply to your topic after 5 days I will assume it has been abandoned and I will close it.

Please follow the following instruction ..:

Download Farbar Recovery Scan Tool and save it to your desktop. --> IMPORTANT

If your antivirus software detects the tool as malicious, it’s safe to allow FRST to run. It is a false-positive detection.
If English is not your primary language, right click on FRST.exe/FRST64.exe and rename to FRSTEnglish.exe/FRST64English.exe

Note
: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click the FRST icon to run the tool. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach the content of these two logs in your next reply.
---------------------------------------------------

In your next reply, please include:
  • FRST.txt
  • Addition.txt
Okay, I've downloaded them!
 

Attachments

  • FRST.txt
    42.3 KB · Views: 12
  • Addition.txt
    817.1 KB · Views: 9

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
532
Hello, LemonSoul364..! :)

  • Download the Revo Uninstaller (Free Download) and save it on your Desktop.
  • Double click on the exe file created on your Desktop to run the installer, and follow the instructions to install the program.
  • Double click the program's icon to open it.
  • Write in the search area, on the top left, the following program:
Code:
Chromstera Browser
AVG Update Helper
WebAdvisor by McAfee

  • Choose the Uninstall tab from the menu and let the program to create a Restore point.
  • Choose Scan, and then the Advanced mode scan.
  • Select all the Online Services items found, Delete and Next.
  • Let the procedure be completed and click on Finish.
  • Restart the computer.

Next ....:

Farbar Recovery Scan Tool - Fix

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system that cannot be undone


Please download the attached file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.

  • Copy/paste the following in the Search: box
Code:
Searchall: ljobicpimlkegkogfcginjfbkkopkfbg , Chromstera Browser , AVG Update Helper , WebAdvisor

  • Click Search Files button
  • When completed click OK and a Search.txt document will open on your desktop
  • Аttach the report in your reply. If the file is too large zip and upload it here.

In your next reply, please include:
  • Fixlog.txt
  • Search report
 

Attachments

  • fixlist.txt
    5.3 KB · Views: 6

LemonSoul364

New Member
Thread author
Jan 23, 2024
9
Hello, LemonSoul364..! :)

  • Download the Revo Uninstaller (Free Download) and save it on your Desktop.
  • Double click on the exe file created on your Desktop to run the installer, and follow the instructions to install the program.
  • Double click the program's icon to open it.
  • Write in the search area, on the top left, the following program:
Code:
Chromstera Browser
AVG Update Helper
WebAdvisor by McAfee

  • Choose the Uninstall tab from the menu and let the program to create a Restore point.
  • Choose Scan, and then the Advanced mode scan.
  • Select all the Online Services items found, Delete and Next.
  • Let the procedure be completed and click on Finish.
  • Restart the computer.

Next ....:

Farbar Recovery Scan Tool - Fix

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system that cannot be undone


Please download the attached file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.

  • Copy/paste the following in the Search: box
Code:
Searchall: ljobicpimlkegkogfcginjfbkkopkfbg , Chromstera Browser , AVG Update Helper , WebAdvisor

  • Click Search Files button
  • When completed click OK and a Search.txt document will open on your desktop
  • Аttach the report in your reply. If the file is too large zip and upload it here.

In your next reply, please include:
  • Fixlog.txt
  • Search report
I've attached the files for you!
 

Attachments

  • Fixlog.txt
    222.7 KB · Views: 4
  • Search.txt
    391 bytes · Views: 2

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
532
Very good..! :)

Please make some more checks..:

Run AdwCleaner (scan only)

Download AdwCleaner and save it to your desktop.
  • Double click AdwCleaner.exe to run it.
  • Click Scan Now.
    • When the scan has finished, a Scan Results window will open.
    • Click Cancel (at this point do not attempt to Quarantine anything that is found)
  • Now click the Log Filestab.
    • Double click on the latest scan log (Scan logs have a [S0*] suffix, where * is replaced by a number. The latest scan will have the largest number)
    • A Notepad file will open containing the results of the scan.
    • Please post the contents of the file in your next reply.

Run Malwarebytes (scan only)
  • Download Malwarebytes and save it to your Desktop.
  • Once downloaded, close all programs and Windows on your computer.
  • Double-click on the icon on your desktop named MBSetup.exe. This will start the installation of MBAM onto your computer.
  • Follow the instructions to install the program.
  • When finished, double click the program's icon created on your Desktop.
  • Click the little gear on the top right (Settings) and when it opens, click the Security tab and make sure about the following:
Code:
Under the title Scan Options, all the options are checked.
Under the title Windows Security Center (Premium only) the option is NOT checked.
Under the title Potentially unwanted items all options are set to Always.

  • Click on the little gear to return to the main menu and select Scan. The program will start scanning your computer. This may take about 10 minutes, but in some cases it may be take longer.
  • When finished, you will see the Threat Scan Summary window open.
  • If threats are not found, click View Report and proceed to the two last steps below.

    If threats are found,
    make sure that all threats are not selected,close the program and proceed to the next steps below.
    • Open Malwarebytes again, click on the Scanner, and then on the Reports tab.
    • Find the report with the most recent date and double click on it.
    • Click on Export and then Copy to Clipboard.
    • Paste its content here, in your next reply.

In your next reply, please post:
  1. The AdwCleaner[S0*].txt
  2. The Malwarebytes report
 

LemonSoul364

New Member
Thread author
Jan 23, 2024
9
Very good..! :)

Please make some more checks..:

Run AdwCleaner (scan only)

Download AdwCleaner and save it to your desktop.
  • Double click AdwCleaner.exe to run it.
  • Click Scan Now.
    • When the scan has finished, a Scan Results window will open.
    • Click Cancel (at this point do not attempt to Quarantine anything that is found)
  • Now click the Log Filestab.
    • Double click on the latest scan log (Scan logs have a [S0*] suffix, where * is replaced by a number. The latest scan will have the largest number)
    • A Notepad file will open containing the results of the scan.
    • Please post the contents of the file in your next reply.

Run Malwarebytes (scan only)
  • Download Malwarebytes and save it to your Desktop.
  • Once downloaded, close all programs and Windows on your computer.
  • Double-click on the icon on your desktop named MBSetup.exe. This will start the installation of MBAM onto your computer.
  • Follow the instructions to install the program.
  • When finished, double click the program's icon created on your Desktop.
  • Click the little gear on the top right (Settings) and when it opens, click the Security tab and make sure about the following:
Code:
Under the title Scan Options, all the options are checked.
Under the title Windows Security Center (Premium only) the option is NOT checked.
Under the title Potentially unwanted items all options are set to Always.

  • Click on the little gear to return to the main menu and select Scan. The program will start scanning your computer. This may take about 10 minutes, but in some cases it may be take longer.
  • When finished, you will see the Threat Scan Summary window open.
  • If threats are not found, click View Report and proceed to the two last steps below.

    If threats are found,
    make sure that all threats are not selected,close the program and proceed to the next steps below.
    • Open Malwarebytes again, click on the Scanner, and then on the Reports tab.
    • Find the report with the most recent date and double click on it.
    • Click on Export and then Copy to Clipboard.
    • Paste its content here, in your next reply.

In your next reply, please post:
  1. The AdwCleaner[S0*].txt
  2. The Malwarebytes report
Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 1/27/24
Scan Time: 9:41 PM
Log File: aef3138e-bd86-11ee-a025-f889d2a9ce86.json

-Software Information-
Version: 4.6.8.311
Components Version: 1.0.2249
Update Package Version: 1.0.80176
License: Trial

-System Information-
OS: Windows 11 (Build 22621.3007)
CPU: x64
File System: NTFS
User: Averee-PC\theno

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 266094
Threats Detected: 7
Threats Quarantined: 0
Time Elapsed: 1 min, 33 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 2
Generic.Malware/Suspicious, C:\PROGRAM FILES\MICROSOFT\EDGWEBOPT\OPTIMIZERSERVICE.EXE, No Action By User, 0, 392686, , , , , 3FE3B5C235FBC1C6482E3CD520E927A6, 2E0DC02C21AF7A18481A965799EE07788528223E8FC5EDD485402B1EA2A5E30A
Generic.Malware/Suspicious, C:\PROGRAM FILES\MICROSOFT\EDGWEBOPT\OPTIMIZEOPERATOR.EXE, No Action By User, 0, 392686, , , , , DB374D52933EE7F4915D907E47BED82D, 547FCA846D4541C61F3E4E91031DA89EE61EF0C49ABA18D01DC02AC6590917FF

Module: 2
Generic.Malware/Suspicious, C:\PROGRAM FILES\MICROSOFT\EDGWEBOPT\OPTIMIZERSERVICE.EXE, No Action By User, 0, 392686, , , , , 3FE3B5C235FBC1C6482E3CD520E927A6, 2E0DC02C21AF7A18481A965799EE07788528223E8FC5EDD485402B1EA2A5E30A
Generic.Malware/Suspicious, C:\PROGRAM FILES\MICROSOFT\EDGWEBOPT\OPTIMIZEOPERATOR.EXE, No Action By User, 0, 392686, , , , , DB374D52933EE7F4915D907E47BED82D, 547FCA846D4541C61F3E4E91031DA89EE61EF0C49ABA18D01DC02AC6590917FF

Registry Key: 1
Generic.Malware/Suspicious, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\OptimizerService, No Action By User, 0, 392686, , , , , ,

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 2
Generic.Malware/Suspicious, C:\PROGRAM FILES\MICROSOFT\EDGWEBOPT\OPTIMIZERSERVICE.EXE, No Action By User, 0, 392686, 1.0.80176, , shuriken, , 3FE3B5C235FBC1C6482E3CD520E927A6, 2E0DC02C21AF7A18481A965799EE07788528223E8FC5EDD485402B1EA2A5E30A
Generic.Malware/Suspicious, C:\PROGRAM FILES\MICROSOFT\EDGWEBOPT\OPTIMIZEOPERATOR.EXE, No Action By User, 0, 392686, 1.0.80176, , shuriken, , DB374D52933EE7F4915D907E47BED82D, 547FCA846D4541C61F3E4E91031DA89EE61EF0C49ABA18D01DC02AC6590917FF

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)
 

Attachments

  • AdwCleaner[S00].txt
    4.9 KB · Views: 4

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
532
Hi, LemonSoul364..! :) Thank you..!

AdwCleaner (Clean mode)

The section at the bottom under Pre-Installed Software is software that was apparently installed when the device was new by your PC manufacturer (in this case HEWLETT-PACKARD). Personally, I don't keep anything from this software that I don't use/need. But it's your computer, so the decision is yours.

To proceed, please do the following:
  • Double click AdwCleaner.exe on your Desktop, to run it as you did before.
  • Click Scan Now.
  • When the scan has finished a Scan Results window will open.
  • Please check all the boxes and then click Quarantine.
  • Click Next.
    • If any pre-installed software was found on your machine, a prompt window will open. Click OK to close it.
    • Check any pre-installed software items you want to remove.
    • Click Quarantine.
  • A prompt to save your work will appear.
    • Click Continue when you're ready to proceed.
  • A prompt to restart your computer will appear.
    • Click Restart Now.
  • Once your computer has restarted:
    • If it doesn't open automatically, please start AdwCleaner.
    • Click the Log Files tab.
    • Double click on the latest Clean log (Clean logs have a [C0*] suffix, where * is replaced by a number, the latest scan will have the largest number)
    • A Notepad file will open containing the results of the removal.
    • Please post the contents of the file in your next reply.


Run Malwarebytes (Clean mode)

  • Double click the program's icon on your Desktop, as you did before.
  • Click the little gear on the top right (Settings) and when it opens, click the Security tab and make sure about the following:
Code:
Under the title Scan Options, all the options are checked.
Under the title Windows Security Center (Premium only) the option is unchecked.
Under the title Potentially unwanted items all options are set to Always.

  • Click on the little gear to return to the main menu and select Scan. The program will start scanning your computer. This may take about 10 minutes, but in some cases it may be take longer.
  • When finished, you will see the Thread Scan Summary window open.
  • If threats are not found, click View Report and proceed to the two last steps below.
  • If threats are found, make sure that all threats are selected, and click on Quarantine/Remove selected.
  • You may need to restart the computer.
  • Open Malwarebytes again, click on the Scanner, and then on the Reports tab.
  • Find the report with the most recent date and double click on it.
  • Click on Export and then Copy to Clipboard.
  • Paste its content here, in your next reply.


Fresh FRST logs

Please run FRST tool once more, and attach for me fresh logs:
  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produce two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach these two logs in your next reply.

In your next reply, please post:
  1. The AdwCleaner[C0*].txt
  2. The Malwarebytes report
  3. Fresh FRST logs
  4. Feedback: let me know about how is the computer running. Please, include any issue and concern right now.
 
Last edited:

LemonSoul364

New Member
Thread author
Jan 23, 2024
9
Hi, LemonSoul364..! :) Thank you..!

AdwCleaner (Clean mode)

The section at the bottom under Pre-Installed Software is software that was apparently installed when the device was new by your PC manufacturer (in this case HEWLETT-PACKARD). Personally, I don't keep anything from this software that I don't use/need. But it's your computer, so the decision is yours.

To proceed, please do the following:
  • Double click AdwCleaner.exe on your Desktop, to run it as you did before.
  • Click Scan Now.
  • When the scan has finished a Scan Results window will open.
  • Please check all the boxes and then click Quarantine.
  • Click Next.
    • If any pre-installed software was found on your machine, a prompt window will open. Click OK to close it.
    • Check any pre-installed software items you want to remove.
    • Click Quarantine.
  • A prompt to save your work will appear.
    • Click Continue when you're ready to proceed.
  • A prompt to restart your computer will appear.
    • Click Restart Now.
  • Once your computer has restarted:
    • If it doesn't open automatically, please start AdwCleaner.
    • Click the Log Files tab.
    • Double click on the latest Clean log (Clean logs have a [C0*] suffix, where * is replaced by a number, the latest scan will have the largest number)
    • A Notepad file will open containing the results of the removal.
    • Please post the contents of the file in your next reply.


Run Malwarebytes (Clean mode)

  • Double click the program's icon on your Desktop, as you did before.
  • Click the little gear on the top right (Settings) and when it opens, click the Security tab and make sure about the following:
Code:
Under the title Scan Options, all the options are checked.
Under the title Windows Security Center (Premium only) the option is unchecked.
Under the title Potentially unwanted items all options are set to Always.

  • Click on the little gear to return to the main menu and select Scan. The program will start scanning your computer. This may take about 10 minutes, but in some cases it may be take longer.
  • When finished, you will see the Thread Scan Summary window open.
  • If threats are not found, click View Report and proceed to the two last steps below.
  • If threats are found, make sure that all threats are selected, and click on Quarantine/Remove selected.
  • You may need to restart the computer.
  • Open Malwarebytes again, click on the Scanner, and then on the Reports tab.
  • Find the report with the most recent date and double click on it.
  • Click on Export and then Copy to Clipboard.
  • Paste its content here, in your next reply.


Fresh FRST logs

Please run FRST tool once more, and attach for me fresh logs:
  • Double-click on the FRST icon to run it, as you did before. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produce two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach these two logs in your next reply.

In your next reply, please post:
  1. The AdwCleaner[C0*].txt
  2. The Malwarebytes report
  3. Fresh FRST logs
  4. Feedback: let me know about how is the computer running. Please, include any issue and concern right now.
I just checked out my browser and looked something up and it looks like it's back to normal so far!
Here are the reports:

---------------------------------------------------------

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 1/29/24
Scan Time: 11:28 AM
Log File: 7aa457e4-bec3-11ee-a850-f889d2a9ce86.json

-Software Information-
Version: 4.6.8.311
Components Version: 1.0.2249
Update Package Version: 1.0.80250
License: Trial

-System Information-
OS: Windows 11 (Build 22621.3007)
CPU: x64
File System: NTFS
User: Averee-PC\theno

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 266106
Threats Detected: 4
Threats Quarantined: 4
Time Elapsed: 1 min, 11 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 1
Generic.Malware/Suspicious, C:\PROGRAM FILES\MICROSOFT\EDGWEBOPT\OPTIMIZERSERVICE.EXE, Quarantined, 0, 392686, , , , , 3FE3B5C235FBC1C6482E3CD520E927A6, 2E0DC02C21AF7A18481A965799EE07788528223E8FC5EDD485402B1EA2A5E30A

Module: 1
Generic.Malware/Suspicious, C:\PROGRAM FILES\MICROSOFT\EDGWEBOPT\OPTIMIZERSERVICE.EXE, Quarantined, 0, 392686, , , , , 3FE3B5C235FBC1C6482E3CD520E927A6, 2E0DC02C21AF7A18481A965799EE07788528223E8FC5EDD485402B1EA2A5E30A

Registry Key: 1
Generic.Malware/Suspicious, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\OptimizerService, Quarantined, 0, 392686, , , , , ,

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 1
Generic.Malware/Suspicious, C:\PROGRAM FILES\MICROSOFT\EDGWEBOPT\OPTIMIZERSERVICE.EXE, Quarantined, 0, 392686, 1.0.80250, , shuriken, , 3FE3B5C235FBC1C6482E3CD520E927A6, 2E0DC02C21AF7A18481A965799EE07788528223E8FC5EDD485402B1EA2A5E30A

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)
 

Attachments

  • AdwCleaner[C01].txt
    2.3 KB · Views: 3
  • FRST.txt
    47.5 KB · Views: 2
  • Addition.txt
    814.4 KB · Views: 2

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
532
Have you created these profiles ..? Do you know ..?

Code:
CHR Profile: C:\Users\theno\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-01-26]
CHR Profile: C:\Users\theno\AppData\Local\Google\Chrome\User Data\Profile 3 [2024-01-26]
 

LemonSoul364

New Member
Thread author
Jan 23, 2024
9
Have you created these profiles ..? Do you know ..?

Code:
CHR Profile: C:\Users\theno\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-01-26]
CHR Profile: C:\Users\theno\AppData\Local\Google\Chrome\User Data\Profile 3 [2024-01-26]
As far as today, I haven't made any new profiles.
 

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
532
The unknown profiles remove this way:

  1. Open Chrome.
  2. In the upper right corner, click on the button with your name or person icon.
  3. Click the Change User button.
  4. Select the person you want to remove. ( Profile 1 Profile 3 )
  5. In the upper right corner of the Contacts icon, tap.
  6. Click Delete this person.
  7. Confirm by clicking Delete this person.
 

LemonSoul364

New Member
Thread author
Jan 23, 2024
9
The unknown profiles remove this way:

  1. Open Chrome.
  2. In the upper right corner, click on the button with your name or person icon.
  3. Click the Change User button.
  4. Select the person you want to remove. ( Profile 1 Profile 3 )
  5. In the upper right corner of the Contacts icon, tap.
  6. Click Delete this person.
  7. Confirm by clicking Delete this person.

Oh, well I have 3 accounts and they're all ones I've made.
 

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
532
The system looks clean..! Here is our final step..:

  • Download KpRm and save it to your Desktop (see here if you must use Chrome)
  • Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
  • Right click on the icon and select Run as administrator
  • Click Yes on the Disclaimer
  • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
  • Click Run
  • Click OK on All operations are completed
  • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
  • You are free to remove any other tools/reports still remaining
  • Please copy and paste its contents in your next reply.
 

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
532
That is all..! I mark the topic as SOLVED...!
Thank you for placing your trust in MalwareTips..!
Stay Safe...! :)
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top