Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Help Needed: Removing Persistent Browser Hijacker
#3
(06-19-2024, 05:23 PM)Shorter_513 Wrote: As far as I know, this "managed by the administrator" trick is done through changing registry settings. If you are aware of how to work with registry, consider deleting the following keys:

HKEY_CURRENT_USER\Software\Google\Chrome
HKEY_CURRENT_USER\Software\Policies\Google\Chrome
HKEY_LOCAL_MACHINE\Software\Google\Chrome
HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome
HKEY_LOCAL_MACHINE\Software\Policies\Google\Update
HKEY_LOCAL_MACHINE\Software\WOW6432Node\Google\Enrollment

In this one, remove the CloudManagementEnrollmentToken value:

HKEY_LOCAL_MACHINE\Software\WOW6432Node\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}

To finish off, go to the Chrome directory in the Program Files (x86), find the Policies directory and delete it. This should hopefully do the job.

That took some time, but looks like it is gone! The "managed by administrator" thing disappeared and I removed the changes. Also reset the browser just for a good measure. Thank you!
Reply


Messages In This Thread
RE: Help Needed: Removing Persistent Browser Hijacker - by Chris Johnson - 06-20-2024, 06:16 PM

Forum Jump:


Users browsing this thread: 7 Guest(s)