Windows 7: 64-bit
Hey guys. So the story starts with a friend of mine who I trust as far as computers are concerend. I ask him what program he uses to monitor his temps and its a tool called 'Core Temp' which perhaps was a good tool in the past. Since then, it seems like the developers have packaged viruses into their installer.
Here's the website. I don't recommend downloading anything:
So I did download the installer and ran it. A bunch of optional bloatware came up, all of which I skipped. Even though I chose not to install it, it still installed a few programs which I didn't want. I removed those using "uninstall a program" from the control panel. However, now Chrome and Firefox have extensions that I can't get rid of. I haven't looked too extensively into the one with FireFox but the Chrome one has me stumped. Here's some pics for context.:
Chrome extension (Dealz):
Firefox extension (Urban ladder 0.2)
Ok, so here's everything that I have since done to try and get rid of the Chrome extension.
- One of the programs I uninstalled via the control panel was called 'Dealz'
- I deleted the corresponding folder to the extension ID from "C:\Users\Trevor\AppData\Local\Google\Chrome\User Data\Default\Extensions"
- It always comes back when I run Chrome
- I also found and deleted two registry entries (one in HKEY_CURRENT_USER and one in HKEY_LOCAL_MACHINE) with the same extension ID in the area where those are kept for Chrome extension. These entries have not been put back into the registry.
- I ran a scan with Microsoft Security Essentials, but it didn't find anything.
- I did a system restore to a point yesterday, before I ran the bad installer. Nothing was changed.
- I uninstalled and reinstalled chrome. The Dealz extension was still there.
- I ran MalwareBytes anti-malware software. It found about 10 items and I fixed them all using the program.
In somewhat of desparation, I did a windows search on my C: drive for the keyword "Dealz"
Here is what came up:
The properties window:
The full highlighted text (visit at your own risk!)
I cannot see where on my hard drive these files are located. Nothing happens when I try to delete them.
So... I'm at the end of my wits here. Is there anybody that can help me out with this? I'd prefer not to format my PC if I don't have to.