Share via

Virus installing chrome extension from ProgramData folder

Anonymous
2022-01-08T13:43:29+00:00

Hi, It loooks like I have the same issue as described in the post below:

https://answers.microsoft.com/en-us/protect/forum/all/hi-i-need-help-with-a-very-stubborn-virus-who/59977fb0-e116-4101-b7c4-04087f3acfb9?page=1

Here Is the content of the folder that installs the extension "UEmbedDoc" on Google Chrome.

When I search something on google it opens a new tab with a fake search engine.

The Path "C:\Program Files (x86)\OptimizationProgram\Micrqex_Yllcfg.dll" doesn't exist on my PC.

Can anyone help me get rid of it?

Attached the autoruns log: https://drive.google.com/file/d/1WPdlWL9EImjNKSplosgyNX33Q\_njmUve/view?usp=sharing

Thank you in advance!

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

  1. _AW_ 67,256 Reputation points Volunteer Moderator
    2022-01-08T13:53:26+00:00

    Hi, I can't seem to get Autoruns to load the log, but usually scanning with Malwarebytes removes this mal extension.

    https://www.malwarebytes.com/mwb-download

    Let me know how things go. If Malwarebytes can't remove it, post logs from FRST.

    https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. _AW_ 67,256 Reputation points Volunteer Moderator
    2022-01-08T14:12:25+00:00

    That's good to hear! :)

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-01-08T14:07:31+00:00

    Hi, I can't seem to get Autoruns to load the log, but usually scanning with Malwarebytes removes this mal extension.

    https://www.malwarebytes.com/mwb-download

    Let me know how things go. If Malwarebytes can't remove it, post logs from FRST.

    https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ 

    Thank you very much _AW_!

    Malwarebytes has managed to detect and remove it.

    It looks like it is gone for now.

    Was this answer helpful?

    0 comments No comments