Jump to content

Weird Virus Problem in Chrome

MattShnoop
Go to solution Solved by Shoob,

Go to chrome://extensions and see if there's anything suspecious there.

Just today I've started seeing a weird problem which I can immediately pin is some sort of virus or malware:

 

Chrome alert saying "linustechtips.com says: Your computer is infected. You have to check it with antivirus." It gives me the options "OK" and "Cancel".

 

I can tell from both the nature of this message and it's language that it is not official. 

 

It happens on multiple sites. First, on Blender's website, when I went to check it's version history. Next, on my Facebook, then YouTube, and now on LTT forums.

It even happens when I open a new tab: Immediately upon hitting CTRL+T, I get his message:

"An embedded page at www.google.ca says: Your computer is infected. You have to check is with antivirus."

 

Hitting either OK, Cancel, or ESC, brings me to a blank page with this URL:

URL is "tttps://chromeupdates.top/s.html

 

My first instinct was to run a full antivirus scan (Avast Pro Antivirus), and an Adware scan (Adware Remover Tool by TSA), however I've realized that if this alert is in itself a virus, and it's telling me to run an antivirus scan, it probably is best to not listen to it: for whatever reason.

 

I've tested in Edge, and it seems not to happen there: it is a Chrome only problem.

 

Any ideas as to the first step I should take?

 

EDIT: I just updated to the most recent version of Chrome, and it still happens. It now is happening with every page I open, instead of every few.

Edited by MattShnoop

PC Specs

CPU: AMD Ryzen 7 5800X

Motherboard: Asus TUF GAMING x570-PLUS (Wi-Fi) ATX AM4

RAM: 32GB G.Skill Trident Z DDR4-3600 CL18

Graphics: ASUS GTX 1080

Case: NZXT S340 Elite

PSU: Corsair RM750 (2019)

Displays: ASUS VS247 & ASUS VH169

 

Link to comment
Share on other sites

Link to post
Share on other sites

Go to chrome://extensions and see if there's anything suspecious there.

From salty to bath salty in 2.9 seconds

 

Link to comment
Share on other sites

Link to post
Share on other sites

Get adw_cleaner.

 

It used to be private and now it's owned by malwarebytes, and for all my problems it's worked wonders.

https://toolslib.net/downloads/viewdownload/1-adwcleaner/

Want to know which mobo to get?

Spoiler

Choose whatever you need. Any more, you're wasting your money. Any less, and you don't get the features you need.

 

Only you know what you need to do with your computer, so nobody's really qualified to answer this question except for you.

 

chEcK iNsidE sPoilEr fOr a tREat!

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, Pandalf said:

Go to chrome://extensions and see if there's anything suspecious there.

You're amazing. Nothing suspicious was in my extensions, however when I booted up Chrome this morning I was told that Chrometana needed new persmissions. I thought nothing of it, Extensions usually do when they update.

 

I just did a quick test and disabling Chrometana stops the problem. 

 

(For info, Chrometana basically intercepts Cortana's and Bing searches and turns them into Google searches)

PC Specs

CPU: AMD Ryzen 7 5800X

Motherboard: Asus TUF GAMING x570-PLUS (Wi-Fi) ATX AM4

RAM: 32GB G.Skill Trident Z DDR4-3600 CL18

Graphics: ASUS GTX 1080

Case: NZXT S340 Elite

PSU: Corsair RM750 (2019)

Displays: ASUS VS247 & ASUS VH169

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, MattShnoop said:

You're amazing. Nothing suspicious was in my extensions, however when I booted up Chrome this morning I was told that Chrometana needed new persmissions. I thought nothing of it, Extensions usually do when they update.

 

I just did a quick test and disabling Chrometana stops the problem. 

 

(For info, Chrometana basically intercepts Cortana's and Bing searches and turns them into Google searches)

Solution: Kill Cortana.

 

I actually got it to work. Really scrappy way to get it out, but I think I finally actually deleted cortana off the system.

The problem is when I did that there's no search function in the start menu -_-

 

Want to know which mobo to get?

Spoiler

Choose whatever you need. Any more, you're wasting your money. Any less, and you don't get the features you need.

 

Only you know what you need to do with your computer, so nobody's really qualified to answer this question except for you.

 

chEcK iNsidE sPoilEr fOr a tREat!

Link to comment
Share on other sites

Link to post
Share on other sites

12 minutes ago, MattShnoop said:

You're amazing. Nothing suspicious was in my extensions, however when I booted up Chrome this morning I was told that Chrometana needed new persmissions. I thought nothing of it, Extensions usually do when they update.

 

I just did a quick test and disabling Chrometana stops the problem. 

 

(For info, Chrometana basically intercepts Cortana's and Bing searches and turns them into Google searches)

You're welcome. Reviews on the extension suggest it really installs some malware. It's a shame that Google allows such stuff to go through.

From salty to bath salty in 2.9 seconds

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Pandalf said:

You're welcome. Reviews on the extension suggest it really installs some malware. It's a shame that Google allows such stuff to go through.

It's odd: it was behaving fine until this morning. Truly a shame.

PC Specs

CPU: AMD Ryzen 7 5800X

Motherboard: Asus TUF GAMING x570-PLUS (Wi-Fi) ATX AM4

RAM: 32GB G.Skill Trident Z DDR4-3600 CL18

Graphics: ASUS GTX 1080

Case: NZXT S340 Elite

PSU: Corsair RM750 (2019)

Displays: ASUS VS247 & ASUS VH169

 

Link to comment
Share on other sites

Link to post
Share on other sites

Rip Chrometana I guess. It was a really useful extension. Don't know what would drive them to do this.

Link to comment
Share on other sites

Link to post
Share on other sites

On 6/17/2017 at 7:25 PM, MagicBall said:

Rip Chrometana I guess. It was a really useful extension. Don't know what would drive them to do this.

Just to clear this up, their account got compromised, and someone released an update with malware in it

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×