Chrome extension resistant to being removed

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • AfroGufo
    PCHF Member
    • May 2021
    • 19

    #1

    Chrome extension resistant to being removed

    Hello everyone, first time asking for help here.

    The issue started a couple weeks ago, when after doing a Google search another tab opened itself with the same search but on Bing. After checking the extensions, I noticed one called xHostGoogle, so I removed it but next time I started Chrome it was there again. I then tried several other methods which I’ll list below, but everytime even if it worked Chrome would shut down after a few minutes, then reopen with the same pages and the extension up an running again. Here’s a list of what I’ve tried thus far:
    • removing the extension
    • disabling the extension
    • checking the extension’s ID and manually deleting it on Windows’ registry
    • running Windows Defender and Malwarebytes, both of which found nothing
    • running AdwCleaner and Junkware Removal Tool, both of which keep finding 2 to 3 issues, quarantining and deleting them, but for it to being as usual a few minutes later
    • uninstalling Chrome, removing the leftover folders and files and re-installing
    • disabling account sync, doing all of the above before and after

    What I’ve found out:
    • the issue is local, as my laptop on shared network with a synced Chrome does not have the issue
    • the issue is not dependant on internet access
    • the issue is cross-user, as I have two Windows 10 accounts running on the machine
    • AdwCleaner says the problem is associated with a certain Speedbit, but no similar program is present on the list of installed apps, nor does it appear to be running or be allowed at the system startup
    • when inspected, the extension leads to a hidden folder in Programs with 4 files in it, consisting of a transparent image file, one json file and two info files
    • after the execution of the more successful methods (i.e. those who manage to make the extension go away at least for a few minutes), the extension comes back by closing any active Chrome window, processing for a few seconds, then reopening all windows and tabs, with the extension now running again
    • the extension seems to be loaded everytime Chrome is launched, as for several seconds no Chrome button works at startup (bookmarks, options etc)

    That is all I’ve gathered thus far. The problem, in all fairness, is little more than a nuisance, but it’s fairly disturbing for me personally since I’ve always managed to either keep my machines clean or resolve any issues by myself. Thank you in advance for the help.
  • veeg
    PCHF Director
    • Jul 2016
    • 8982

    #2
    Hello

    Hopefully or malware experts will be with you soon..

    jmarket

    Comment

    • jmarket
      PCHF Owner
      • Jan 2015
      • 7634

      #3
      Hello and welcome to PCHF

      Please download the FRST 32 bit or FRST 64bit version to suit your operating system. It is important FRST is downloaded to your desktop.

      If you are unsure if your operating system is 32 or 64 Bit please go HERE.

      Once downloaded right click the FRST desktop icon and select “Run as administrator” from the menu.



      If you receive any security warnings, or the User Account Control warning opens at any time whilst using FRST you can safely allow FRST to proceed.
      Frst will open with two dialogue boxes, accept the disclaimer.


      Accept the default whitelist options,
      If the additions.txt options box is not checked please select it.
      Then select “Scan”



      Frst will take a few minutes to scan your computer, and when finished will produce two log files on your desktop, FRST.txt, and Addition.txt. They will display immediately on the desktop, but can be reopened later as a notepad file.



      Please Copy and Paste the contents of these logs in your next post for review by our Security Team

      Comment

      • AfroGufo
        PCHF Member
        • May 2021
        • 19

        #4
        Thanks for the rapid reply, jmarket. I tried to post the logs but they are quite lenghty, so much so that I think the forum doesn’t much like them because it won’t let me post them. Is there a way I can attach the txt files or put the text into a collapsible that won’t break the forum?

        Comment

        • jmarket
          PCHF Owner
          • Jan 2015
          • 7634

          #5
          If it won’t let you upload, then please attach the files to you next post

          Comment

          • AfroGufo
            PCHF Member
            • May 2021
            • 19

            #6
            Ok, here are the files:

            Comment

            • AfroGufo
              PCHF Member
              • May 2021
              • 19

              #7
              That didn’t work for some reason. Trying again from another computer.

              Comment

              • AfroGufo
                PCHF Member
                • May 2021
                • 19

                #8
                Nothing. I’m starting to think this forum hates me ahahah
                Anyway, I put them on my Drive, this should work. Sorry for the post spam.

                Comment

                • jmarket
                  PCHF Owner
                  • Jan 2015
                  • 7634

                  #9
                  Thank you for the upload Sometimes if the log is too big it will reject it but I’m working on a way to upload bigger log files in excess of 2MB.

                  Give me some time to review your logs and I’ll have some feedback for you

                  Comment

                  • AfroGufo
                    PCHF Member
                    • May 2021
                    • 19

                    #10
                    Thanks a bunch!
                    On a side note, my Instagram profile has just been hacked and I’ve been made to follow 300+ accounts, it’s probably related somehow. Instagram was the only place I didn’t have two-factors authentication for, my bad.

                    Comment

                    • jmarket
                      PCHF Owner
                      • Jan 2015
                      • 7634

                      #11
                      Oh no.

                      Were you logged into Instagram when your account got hacked? If so, you most likely have cookie-stealing malware.

                      I’m still reviewing your logs here. I would advise if you’re able to log out of Instagram on your infected computer and change your password on an uninfected device.

                      Comment

                      • AfroGufo
                        PCHF Member
                        • May 2021
                        • 19

                        #12
                        I’m not sure, certainly I wasn’t logged into it via the infected computer. I accessed my IG profile with it only once months ago.
                        For now, I have logged out of all other devices other than my phone, enabled two-factors authentication and updated all my passwords for good measure.

                        Btw, thanks for the effort and advices, and for running this community, I mean it.

                        Comment

                        • Rustys
                          PCHF Member
                          • Jul 2016
                          • 7862

                          #13
                          jmarket

                          Comment

                          • jmarket
                            PCHF Owner
                            • Jan 2015
                            • 7634

                            #14
                            My apologies. I’ve been extremely busy with work and I’m in the middle of a car purchase. I have not forgotten your issue @AfroGufo and I will get into the logs tonight or tomorrow morning. Have you had any NEW symptoms since then?

                            Comment

                            • jmarket
                              PCHF Owner
                              • Jan 2015
                              • 7634

                              #15
                              Thank you for your patience.

                              I have a fix here for you, but before I can give you that, I do see that you have Bittorrent installed. This MUST be removed before we can begin cleaning your machine. I believe you have received malware from a torrent you downloaded.

                              Comment

                              Working...