[Discussion] For victims of RazerChat. How to know if you're still infected by it.

Also found a notepad with a file named as chrome_installer,

[0726/093031:ERROR:uninstall.cc(799)] Error loading registry hive: 3 [0726/093041:ERROR:google_update_util.cc(97)] Failed to launch ("C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /uninstall): The system cannot find the file specified. (0x2) [0726/093607:VERBOSE1:setup_main.cc(1599)] Command Line: "C:\Users\Fyuryus\AppData\Local\Temp\CR_41E82.tmp\setup.exe" --install-archive="C:\Users\Fyuryus\AppData\Local\Temp\CR_41E82.tmp\CHROME.PACKED.7Z" --multi-install --chrome --verbose-logging --do-not-launch-chrome --system-level /installerdata="C:\Windows\TEMP\guiE771.tmp" [0726/093607:VERBOSE1:setup_main.cc(1601)] multi install is 1 [0726/093607:VERBOSE1:setup_main.cc(1604)] system install is 1 [0726/093607:VERBOSE1:installer_state.cc(117)] Install distribution: Google Chrome [0726/093607:VERBOSE1:installer_state.cc(126)] Install distribution: Google Chrome binaries [0726/093607:VERBOSE1:install_util.cc(277)] Windows NT 6.1 SP1 [0726/093607:VERBOSE1:setup_main.cc(735)] Installing to C:\Program Files (x86)\Google\Chrome\Application [0726/093607:VERBOSE1:setup_main.cc(459)] Created path C:\Program Files (x86)\Google\Chrome\Temp [0726/093607:VERBOSE1:setup_main.cc(1361)] Installing Chrome from compressed archive C:\Users\Fyuryus\AppData\Local\Temp\CR_41E82.tmp\CHROME.PACKED.7Z [0726/093607:VERBOSE1:lzma_util.cc(82)] Opening archive C:\Users\Fyuryus\AppData\Local\Temp\CR_41E82.tmp\CHROME.PACKED.7Z [0726/093607:VERBOSE1:lzma_util.cc(89)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source57768_782 [0726/093612:VERBOSE1:lzma_util.cc(82)] Opening archive C:\Program Files (x86)\Google\Chrome\Temp\source57768_782\chrome.7z [0726/093612:VERBOSE1:lzma_util.cc(89)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source57768_782 [0726/093612:VERBOSE1:setup_main.cc(1404)] unpacked to C:\Program Files (x86)\Google\Chrome\Temp\source57768_782 [0726/093612:VERBOSE1:setup_util.cc(250)] Looking for Chrome version folder under C:\Program Files (x86)\Google\Chrome\Temp\source57768_782\Chrome-bin [0726/093612:VERBOSE1:setup_util.cc(261)] directory found: 44.0.2403.107 [0726/093612:VERBOSE1:setup_main.cc(1415)] version to install: 44.0.2403.107 [0726/093612:VERBOSE1:install.cc(329)] Successfully wrote VisualElementsManifest.xml to C:\Program Files (x86)\Google\Chrome\Temp\source57768_782\Chrome-bin [0726/093612:VERBOSE1:install_worker.cc(481)] Adding unregistration items for DelegateExecute verb handler in 80000002 [0726/093612:VERBOSE1:install_worker.cc(1354)] Adding registration items for DelegateExecute verb handler. [0726/093612:VERBOSE1:install_worker.cc(1416)] Adding registration items for Active Setup. [0726/093612:VERBOSE1:install_worker.cc(1335)] No DelegateExecute verb handler processing to do for Google Chrome binaries [0726/093612:VERBOSE1:install_worker.cc(1407)] No Active Setup processing to do for system-level Google Chrome binaries [0726/093612:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Temp [0726/093612:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application [0726/093612:VERBOSE1:copy_tree_work_item.cc(95)] Copied source C:\Program Files (x86)\Google\Chrome\Temp\source57768_782\Chrome-bin\chrome.exe to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [0726/093612:VERBOSE1:move_tree_work_item.cc(91)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source57768_782\Chrome-bin\VisualElementsManifest.xml to destination C:\Program Files (x86)\Google\Chrome\Application\VisualElementsManifest.xml

/r/GlobalOffensiveTrade Thread