Jump to content

Search the Community

Showing results for tags 'chrome extension'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


Forums

  • Announcements
    • Malwarebytes News
    • Beta Testing Program
  • Malware Removal Help
    • Windows Malware Removal Help & Support
    • Mac Malware Removal Help & Support
    • Mobile Malware Removal Help & Support
    • Malware Removal Self-Help Guides
  • Malwarebytes for Home Support
    • Malwarebytes for Windows Support Forum
    • Malwarebytes for Mac Support Forum
    • Malwarebytes for Android Support Forum
    • Malwarebytes for iOS Support
    • Malwarebytes Privacy
    • Malwarebytes Browser Guard
    • False Positives
    • Comments and Suggestions
  • Malwarebytes for Business Support
    • Malwarebytes Endpoint Protection
    • Malwarebytes Incident Response (includes Breach Remediation)
    • Malwarebytes Endpoint Security
    • Malwarebytes Business Products Comments and Suggestions
  • Malwarebytes Tools and Other Products
    • Malwarebytes AdwCleaner
    • Malwarebytes Junkware Removal Tool Support
    • Malwarebytes Anti-Rootkit BETA Support
    • Malwarebytes Techbench USB (Legacy)
    • Malwarebytes Secure Backup discontinued
    • Other Tools
    • Malwarebytes Tools Comments and Suggestions
  • General Computer Help and Security Updates
    • BSOD, Crashes, Kernel Debugging
    • General Windows PC Help
  • Research Center
    • Newest Rogue-Ransomware Threats
    • Newest Malware Threats
    • Newest Mobile Threats
    • Newest IP or URL Threats
    • Newest Mac Threats
    • Report Scam Phone Numbers
  • General
    • General Chat
    • Forums Announcements & Feedback

Find results in...

Find results that contain...


Date Created

  • Start

    End


Last Updated

  • Start

    End


Filter by number of...

Joined

  • Start

    End


Group


AIM


MSN


Website URL


ICQ


Yahoo


Jabber


Location


Interests

Found 10 results

  1. Hello - Need some help please! Working on a computer that keeps getting the same 59 threats even after MWB says they are quarantined. I have also run ADWcleaner and it also keeps finding threats, not as many and sometime none but I can't seem to keep the system clean. All 59 treats are for MindSpark and all are located/related to Chrome extensions. Attached are the log files from a scan with FarBar. Any suggestion would be appreciated!! Addition.txt FRST.txt
  2. Hi, our browser extension gets flagged as "PUP.Optional.Legacy" which is wrong. Please correct this or tell us what we have to do to avoid getting flagged. Tested date: 2018-03-09OS: Win 10 x64AdwCleaner version: 7.0.8.0Chrome version: Version 64.0.3282.186 (Offizieller Build) (64-Bit)MyJD addon version: 3.2.16 We also got complaints in our own support forum: https://board.jdownloader.org/showthread.php?t=72927 (Yes that is a while ago but the problem does still exist) Best regards, pspzockerscene - JDownloader Support
  3. What is Your mini Truetest? The Malwarebytes research team has determined that Your mini Truetest is adware. These adware applications display advertisements not originating from the sites you are browsing. How do I know if my computer is affected by Your mini Truetest? You may see this entry in your Chrome Extensions: and this warning during install: You may also see this type of advertisements: How did Your mini Truetest get on my computer? Adware applications use different methods for distributing themselves. This particular one was downloaded from the Webstore. How do I remove Your mini Truetest? Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Your mini Truetest? You may have to remove the Extension manually under Tools > More Tools > Extensions. Click on the bin behind the Your mini Truetest entry and confirm Remove in the prompt. How would the full version of Malwarebytes help protect me? We hope our application and this guide have helped you eradicate this adware. The web protection module blocks some of the connections the adware tries to make: Technical details for experts Possible signs in FRST logs: CHR Extension: (Your mini Truetest) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd [2017-07-24] Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0 Adds the file 128x128.png"="7/24/2017 12:05 PM, 3393 bytes, A Adds the file 19x19.png"="7/24/2017 12:05 PM, 623 bytes, A Adds the file 38x38.png"="7/24/2017 12:05 PM, 1491 bytes, A Adds the file 48x48.png"="2/13/2017 1:47 PM, 16050 bytes, A Adds the file 64x64.png"="2/13/2017 1:46 PM, 16238 bytes, A Adds the file cs.js"="2/13/2017 2:17 PM, 1119 bytes, A Adds the file manifest.json"="7/24/2017 12:05 PM, 1020 bytes, A Adds the file popup.html"="2/8/2017 3:16 PM, 442 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\_locales\en Adds the file messages.json"="7/24/2017 12:05 PM, 131 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\_metadata Adds the file computed_hashes.json"="7/24/2017 12:05 PM, 839 bytes, A Adds the file verified_contents.json"="2/8/2017 4:04 PM, 2372 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings] "icepgilpdfnecncejolijhnognpbgcgd"="REG_SZ", "4C8A73397D60E921AC0812192E361BEC0039ED93C6B286D92186A53F168B122E" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 7/24/17 Scan Time: 1:07 PM Log File: mbamTrueTest.txt Administrator: Yes -Software Information- Version: 3.1.2.1733 Components Version: 1.0.160 Update Package Version: 1.0.2425 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 339228 Threats Detected: 16 Threats Quarantined: 16 Time Elapsed: 2 min, 38 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 5 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\_locales\en, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\_metadata, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\_locales, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\ICEPGILPDFNECNCEJOLIJHNOGNPBGCGD, Quarantined, [9706], [419417],1.0.2425 File: 11 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\_locales\en\messages.json, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\_metadata\computed_hashes.json, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\_metadata\verified_contents.json, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\128x128.png, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\19x19.png, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\38x38.png, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\48x48.png, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\64x64.png, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\cs.js, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\manifest.json, Quarantined, [9706], [419417],1.0.2425 PUP.Optional.TrueTestMini, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\icepgilpdfnecncejolijhnognpbgcgd\13.6226.213_0\popup.html, Quarantined, [9706], [419417],1.0.2425 Physical Sector: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat. We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  4. I couldn't figure out why Chrome kept opening a new browser tab and accessing unitysoft.org until recently. I'm posting this here so that others that are running into this issue can find a real answer to this problem. My Chrome browser was opening a new tab every now and then telling me that my plugin (or extension?) was updated, but it never told me which plugin was updated. The small print showed the website unitysoft.org at the bottom of the page. When you look that up, you get presented with tons of fake "remove the unitysoft.org computer virus" websites. These were likely created by the extension maker to lure people into infection. I decided to block unitysoft.org using a blocker extension and was able to figure out which extension was accessing that site (because the extension failed when the site was blocked). It turns out to be Popup Blocker Pro. If you're using the Popup Blocker Pro Chrome extention, there is something illegitimate going on. I've since uninstalled it and reported it to Google. The extension works great AND it wants to infect your computer at the same time.
  5. Hi, just found and installed "Searchlock" app in Chrome Webstore, don't think its a problem but I installed on my Windows PC with default Chrome browser + use Malwarebytes 3.0.6 + when I do a search Malwarebytes pops up and blocks outgoing, but tells me I can exclude or allow if I want to.. (so far I have not allowed anything MBytes blocked) should I tell it to exclude (allow) this? This seems to be a legit application, and I want to trust this app and eager to try this out. Thank you.
  6. Hello! I have a problem. When i'm browsing google chrome, malwarebytes keeps on telling me that it blocked tradeadexchange.com. I knew that it was some sort of adware or malware, so I scanned for it. I scanned with multiple programs, MalwareBytes, Avast!, AdwCleaner, HitmanPro, and JRT. I first scanned with MalwareBytes and it found 3 to 5 threats. I scanned with adwcleaner and it found 60 threats. JRT found a few. Avast! and HitmanPro found nothing. At first I thought I was clean or mostly clean. After a few days, it kept on popping up: Blocked, tradeadexchange.com. the IP I saw as I was posting this is 104.197.47.161. Is this a malware that I should be concerned about or could it be fine if I left it on my system?
  7. I have been using this extension for more than a year without issue. Recently I have been getting this pop-up everytime I use the Infinity New Tab extension. Is this a false positive? Should I be worried about it? I did not want to exclude it if it could possibly be true.
  8. Malwarebytes claims malicious software but been on PC 5 months first time its ever warned me ? I got a long list of this "PUP.Optional. chrome extension " its under Users/App data, /Local/Google/chrome extension
  9. Hi all, I discovered a Google chrome extension which I was unable to install even after following various instructions given on another forum. In the end I had to restore the system to remove it however it just reinstalled itself. The extension was called UTubeAdbliock 2.2 installed by Enterprise Policy. I suspect it was responsible for causing a blue screen crash and pop up prizes etc. I came across a forum form this website (which I am unable to link for some reason) titled ''is it safe to remove all that Malwarebytes found'' . I carefully followed the instructions on it and used the Malwarebytes tool which found around 50 threats which I removed, I used ADWCleaner which found about 30 or so threats and removed and I used Junkware removal tool which also found numerous threats and cleaned. The next instruction was to use the ESET Online Scanner which has found threats. the message which came up from the log says the following, C:\Windows\Temp\RegistryOptimizer.exe multiple threats I am just looking for advice as to what I should do next, thanks, Eddie
  10. First time posting here so let me know if im in the wrong place or whether i've done something incorrect. anyway hopefully this isn't too long but basically i don't know if anyone has heard of the DERP trolling incident where they took down multiple games within the last few weeks but during the whole incident i clicked on their twitter and when i did this my chrome instantly shut down without warning or anything happening, loaded it up and everything was back to normal. well a few days ago i noticed i got allot of random ads popping up on my browsers which i never had happen before as i have pop ups disabled and also adblock on chrome. Wondering why this was happening i went to check my unisntall a programs file and found there was a file that i never downloaded called "SaveNeeWWaApipz". anyway i uninstalled it thinking this would solve the issue but when it kept occurring i checked my chrome extensions and it was there under the same name, so summed up every time i delete it and check the extensions its back and im still getting ads. only occurred since that incident with DERP trolling twitter shutting down my browser not sure if its just a coincidence or whether they gave me a virus, have no idea how to get rid of it but its fairly annoying now. thanks to anyone who can give any assistance.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.