We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Help please

mrbadexample
mrbadexample Posts: 10,805 Forumite
Part of the Furniture 10,000 Posts Combo Breaker Photogenic
edited 14 October 2013 at 7:12PM in Techie Stuff
I want to remove the Babylon and Delta search tabs from Chrome, but can't seem to shift them.

Help please,
Cheers,
MBE
If you lend someone a tenner and never see them again, it was probably worth it.
«1

Comments

  • debitcardmayhem
    debitcardmayhem Posts: 13,409 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    edited 13 October 2013 at 8:35PM
    Open the file in notepad and change system32 to system42 and I believe there is a XXXXX.exe that the forum doesnt like either .... (not sure what the XXXXX is tho) you could use DDS but why do you want to post the HJT log for ?

    Edited use F3 to find and then replace all...

    Edited yet again ... i typed system32 and it was ok doh but there is a bug around the posting software
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy

    CEC Email energyclub@moneysavingexpert.com
  • mrbadexample
    mrbadexample Posts: 10,805 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker Photogenic
    Thanks.

    Girlfriend's netbook has Babylon and Delta searches opening up in Google Chrome. Also painfully slow to start.

    I didn't understand your post, and what's DDS? :huh:
    If you lend someone a tenner and never see them again, it was probably worth it.
  • Thanks.

    Girlfriend's netbook has Babylon and Delta searches opening up in Google Chrome. Also painfully slow to start.

    I didn't understand your post, and what's DDS? :huh:
    Another program (somewhat like HJT) but if it is Bablylon and Delta thenI would run adwcleaner http://www.bleepingcomputer.com/download/adwcleaner/dl/125/ and for info look here http://www.bleepingcomputer.com/download/adwcleaner/
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy

    CEC Email energyclub@moneysavingexpert.com
  • mrbadexample
    mrbadexample Posts: 10,805 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker Photogenic
    Nice one, I'll give that a bash and let you know how I get on. :D
    If you lend someone a tenner and never see them again, it was probably worth it.
  • Nice one, I'll give that a bash and let you know how I get on. :D
    I would also run a quick a quick scan with malwarebytes afterwards too. http://downloads.malwarebytes.org/mbam-download.php
    Oh and post the logs from adw and malwarebytes someone smart will come and look them over.
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy

    CEC Email energyclub@moneysavingexpert.com
  • mrbadexample
    mrbadexample Posts: 10,805 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker Photogenic
    I had already run MWB, but to no avail. I've run the ADWC but something's still there. Now when I open Chrome 4 tabs open - Bablyon Search, Delta Search and Google (this might be the homepage duplicated).

    I'll find the ADWC log...
    If you lend someone a tenner and never see them again, it was probably worth it.
  • mrbadexample
    mrbadexample Posts: 10,805 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker Photogenic
    # AdwCleaner v3.007 - Report created 13/10/2013 at 21:54:41
    # Updated 09/10/2013 by Xplode
    # Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
    # Username : Viki1 - VIKI
    # Running from : C:\Documents and Settings\Viki1\My Documents\Downloads\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Deleted : C:\Documents and Settings\All Users\Application Data\Babylon
    Folder Deleted : C:\Documents and Settings\All Users\Application Data\BrowserDefender
    Folder Deleted : C:\WINDOWS\system32\BrowserDefender
    Folder Deleted : C:\Documents and Settings\Viki1\Local Settings\Application Data\Conduit
    Folder Deleted : C:\Documents and Settings\Viki1\Application Data\DSite
    File Deleted : C:\WINDOWS\system32\conduitEngine.tmp

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
    Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
    Key Deleted : HKCU\Software\5f55dbdee73fb949
    Key Deleted : HKLM\SOFTWARE\5f55dbdee73fb949
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1339827
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
    Key Deleted : HKCU\Software\BabSolution
    Key Deleted : HKCU\Software\dsiteproducts
    Key Deleted : HKCU\Software\YahooPartnerToolbar
    Key Deleted : HKLM\Software\Babylon
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\Software\DataMngr
    Key Deleted : HKLM\Software\Tarma Installer
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094

    ***** [ Browsers ] *****

    -\\ Internet Explorer v8.0.6001.18702

    Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

    -\\ Google Chrome v30.0.1599.69

    [ File : C:\Documents and Settings\Viki1\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

    Deleted : urls_to_restore_on_startup

    *************************

    AdwCleaner[R0].txt - [4799 octets] - [13/10/2013 21:49:07]
    AdwCleaner[S0].txt - [4662 octets] - [13/10/2013 21:54:41]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4722 octets] ##########
    If you lend someone a tenner and never see them again, it was probably worth it.
  • closed
    closed Posts: 10,886 Forumite
    edited 13 October 2013 at 10:59PM
    send mse the email, they might actually fix it one day

    https://forums.moneysavingexpert.com/discussion/4758878

    http://forums.moneysavingexpert.com/showpost.php?p=63412799&postcount=14

    but hijackthis is not much use for chrome issues.
    !!
    > . !!!! ----> .
  • OK now post a malwarebytes log, and let us know if babylon and delta have disappeared
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy

    CEC Email energyclub@moneysavingexpert.com
  • mrbadexample
    mrbadexample Posts: 10,805 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker Photogenic
    MWB log:

    Malwarebytes Anti-Malware 1.75.0.1300
    https://www.malwarebytes.org

    Database version: v2013.10.08.06

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 8.0.6001.18702
    Viki1 :: VIKI [administrator]

    13/10/2013 23:15:31
    mbam-log-2013-10-13 (23-15-31).txt

    Scan type: Full scan (C:\|D:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 251799
    Time elapsed: 1 hour(s), 10 minute(s), 43 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 5
    C:\Documents and Settings\Viki1\Local Settings\Temp\QuickShare1.exe (PUP.Optional.QuickShare.A) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Viki1\Local Settings\Temp\BabylonTB.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Viki1\Local Settings\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Viki1\Local Settings\Temp\wajam_download.exe (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Viki1\My Documents\Downloads\FreeZipSetup.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.

    (end)
    If you lend someone a tenner and never see them again, it was probably worth it.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.5K Work, Benefits & Business
  • 602.8K Mortgages, Homes & Bills
  • 178K Life & Family
  • 260.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.