I have a problem with my laptop.
Everytime I open Chrome or click a link in Chrome my Avast pops up with:
Object: http://…/sync2/?q=…
Infection: URL:Mal
Process: C:.…\chrome.exe
It started a while ago but I never achieved to fix it.
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
FF Extension: No Name - C:\Users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\ag6u4kg6.default\extensions\addon@defaulttab.com.xpi [Not Found]
FF Extension: No Name - C:\Users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\ag6u4kg6.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Sara\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-06-21]
CHR StartMenuInternet: Google Chrome - chrome.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\Users\Public\AlexaNSISPlugin.1560.dll
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-09-2014
Ran by Sara at 2014-09-30 17:48:00 Run:1
Running from C:\Users\Sara\Downloads
Loaded Profile: Sara (Available profiles: Sara)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
FF Extension: No Name - C:\Users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\ag6u4kg6.default\extensions\addon@defaulttab.com.xpi [Not Found]
FF Extension: No Name - C:\Users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\ag6u4kg6.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Sara\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-06-21]
CHR StartMenuInternet: Google Chrome - chrome.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\Users\Public\AlexaNSISPlugin.1560.dll
EmptyTemp:
CMD: bitsadmin /reset /allusers
*****************
C:\Users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\ag6u4kg6.default\extensions\addon@defaulttab.com.xpi not found.
C:\Users\Sara\AppData\Roaming\Mozilla\Firefox\Profiles\ag6u4kg6.default\extensions\a9719e64-232b-4695-ae9c-a89cd7f2aa84@ca1279df-bc0d-44a8-97ef-19301c922b68.com not found.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} not found.
C:\Users\Sara\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb => Moved successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKCU\SOFTWARE\Policies\Google" => Key deleted successfully.
C:\Users\Public\AlexaNSISPlugin.1560.dll => Moved successfully.
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
Unable to cancel {CA065FC7-BA12-4ED5-A667-E999962FDB0C}.
0 out of 1 jobs canceled.
========= End of CMD: =========
EmptyTemp: => Removed 1.8 GB temporary data.
The system needed a reboot.
==== End of Fixlog ====