彻底解决Chrome浏览器劫持后显示“由贵单位管理(Managed by your organization)” 的解决办法

article/2025/8/8 9:54:03

声明:
Declaration:

由于网络中的病毒virus/malware等存在随时变异或者对应多种感染方式等情况,本文所针对的处理方法仅针对本次样本负责,个人如有误操作,后果自负。如需帮助,可以关注我的公众号(我在全球村)然后回复关键词:”加微信“ 获取我的微信号,或通过文末二维码添加messager联系我!

Because the virus/malware in the network is mutated at any time or corresponds to multiple infection methods, the processing method targeted in this paper is only responsible for this sample. If the individual has misoperation, the consequences are at your own risk. If you need help, you can follow my public account (MyGlobalVillage) and then reply to the keyword: "Add WeChat" to get my WeChat ID, or contact me via the messager QR code at the end of the post!

现象
Phenomenon:

最近协助移除恶意插件时,遇到一些网友反馈移除清理不干净的情况,并说右键菜单或者Chrome浏览器出现了“由贵单位管理(Managed by your organization)“的选项,感觉是莫名其妙,而且清理后,主页没有被自动恢复,哎,看来生产恶意软件的人又开始利用浏览器的漏洞了!经过一天的折腾捣鼓,终于搞清楚了来由和解决方法,现写出来留给需要的人尝试!

When assisting in the removal of malicious plug-ins recently, I encountered some netizens' feedback that the removal and cleaning was not clean, and said that the "Managed by your organization" option appeared in the right-click menu or Chrome browser. And after cleaning, the homepage was not automatically restored. Hey, it seems that the people who produced the malware started to use the browser's loopholes again! After a day of tossing, I finally figured out the reason and solution, and now write it down for those who need it!

很多谷歌浏览器用户发现设置选项多了一个提示由贵单位管理,论坛上有很多人反馈,并且寻求移除的方法。

Many Google Chrome users find that the setting option has an additional reminder managed by your organization, and many people on the forum have feedback and seek ways to remove it.

如何确定自己的电脑有没有发生类似的情况呢?

How can I determine if something similar has happened to my computer?

其实很简单,一个是看Chrome 右上角菜单选项中是否有该选项.

It ’s actually very simple, one is to see if it is available in the menu option in the upper right corner of Chrome.

或者浏览器中输入:chrome://management/

Or enter in your browser: chrome: // management /

被接管时是:

When it taken over:

未被接管时是:

When not taken over:

 

分析
Analysis:

如果是企业用户遇到这个通知可能还能理解但不少个人用户也遇到这种情况,使用的并非谷歌浏览器企业版。同时遇到这个问题的不仅仅是国内网友而是全球网友都遇到了,谷歌官方已经发布声明解释(见下文 “Managed by your organization” messages)。

If this notice is encountered by business users, it may be understood, but many individual users also encounter this situation, not using Google Chrome Enterprise Edition. At the same time, not only domestic netizens but global netizens who encountered this problem encountered Google ’s official statement statement (see “Managed by your organization” messages below).

先来看看谷歌对该功能的官方定义:

Let's take a look at Google's official definition of this feature:

对与公司电脑来说,如果你们公司部署了策略,比如添加了一些重要的内网站点到书签里。那么不要试图取消,应该公私分明。

对于家庭或个人电脑,第三方软件却将这个功能乱用,设置企业策略应用到了个人的电脑,导致浏览器显示:“浏览器有所属组织管理”。

绝大多数情况下,这些策略是安全的,比如一个第三方软件是不需要使用企业策略的,但是有些第三方软件可能有特殊目的所以会添加企业策略。例如诸如LastPass这类密码管理器可能就会触发这类策略,导致用户在浏览器里看到由贵单位管理相关字样。

同时有些第三方软件没有明说目的但也会使用企业策略,而且恰好这种情况被恶意劫持类软件看上了,简直是如虎添翼,让人删直呼删不掉,移除不掉,包含很多昂贵的杀毒软件也没能清理掉,有试过的同学应该都知道。

谷歌浏览器打开Chrome://policy,你会看到哪些策略在Chrome里被启用了。比如你的密码管理扩展或者其他被信任的程序启用的策略。

For corporate computers, if your company has a strategy in place, such as adding some important intranet sites to bookmarks. Then don't try to cancel it. It should be clearly public and private.

For home or personal computers, third-party software uses this function arbitrarily, setting corporate policies to personal computers, causing the browser to display: "The browser is managed by its organization."

In most cases, these policies are secure. For example, a third-party software does not need to use enterprise policies, but some third-party software may have special purposes and therefore add enterprise policies. For example, password managers such as LastPass may trigger this type of policy, causing users to see related words managed by your organization in the browser.

At the same time, some third-party software does not have a clear purpose but also uses corporate policies, and this happens to be seen by malicious hijacking software. It is really powerful, making it impossible to remove, not to remove, including many expensive The anti-virus software has not been cleaned up. Students who have tried it should know it.

Open Chrome: // policy in Google Chrome and you will see which policies are enabled in Chrome. Such as your password management extension or other policies enabled by trusted programs.

其中一个网友同学的策略如下:

The strategy of one of the netizens is as follows:

导出来的json文件类似如下:

The exported json file is similar to the following:

{"chromeMetadata": {"OS": "macOS 版本 10.13.6(版号 17G11023)","application": "Google Chrome","revision": "fcea73228632975e052eb90fcf6cd1752d3b42b4-refs/branch-heads/3987@{#974}","version": "80.0.3987.132 (正式版本) (64 位)"},"chromePolicies": {"DefaultSearchProviderEnabled": {"level": "recommended","scope": "machine","source": "platform","value": true},"DefaultSearchProviderName": {"level": "recommended","scope": "machine","source": "platform","value": "SearchMine"},"DefaultSearchProviderNewTabURL": {"level": "recommended","scope": "machine","source": "platform","value": "https://www.searchmine.net/search/?asset=hp&wtguid=59730897629213944&wtmacid=692cb6d70138b337cc4092a0d10777eb&wtsrc=8291&wtdt=031420&wtbr=1&wtpl=10.13.6.0&v=6.0"},"DefaultSearchProviderSearchURL": {"level": "recommended","scope": "machine","source": "platform","value": "https://www.searchmine.net/search/?asset=ds&wtguid=59730897629213944&wtmacid=692cb6d70138b337cc4092a0d10777eb&wtsrc=8291&wtdt=031420&wtbr=1&wtpl=10.13.6.0&v=6.0&q={searchTerms}"},"HomepageIsNewTabPage": {"level": "recommended","scope": "machine","source": "platform","value": true},"HomepageLocation": {"level": "recommended","scope": "machine","source": "platform","value": "https://www.searchmine.net/search/?asset=hp&wtguid=59730897629213944&wtmacid=692cb6d70138b337cc4092a0d10777eb&wtsrc=8291&wtdt=031420&wtbr=1&wtpl=10.13.6.0&v=6.0"},"NewTabPageLocation": {"level": "recommended","scope": "machine","source": "platform","value": "https://www.searchmine.net/search/?asset=hp&wtguid=59730897629213944&wtmacid=692cb6d70138b337cc4092a0d10777eb&wtsrc=8291&wtdt=031420&wtbr=1&wtpl=10.13.6.0&v=6.0"}},"extensionPolicies": {"kbfnbcaeplbcioakkpcpgfkobkghlhen": {}}
}

我们可以看到其中某几个字段很显然已经被曾经安装的插件修改了,但是用户又无法通过其展示的页面和选项进行修改删除,这样的结果就是即使你移除了本地和浏览器的插件,但是这个配置仍会生效,依然没有释放你的主页和后续新窗口的默认搜索引擎!

 

处理方法:
Approach:

好了,下面来讨论移除方法(针对Mac OS):

We can see that some of these fields have obviously been modified by the plug-ins that have been installed, but users cannot modify and delete the pages and options displayed by them. The result is that even if you remove the local and browser plug-ins , But this configuration will still take effect, the default search engine for your homepage and subsequent new windows is still not released!

Well, let's discuss the removal method (for Mac OS):

1)首先,你得关闭Chrome的云同步和退出当前登录账号,防止修改和移除的数据被自动同步回来;

退出方法:

First of all, you have to turn off Chrome ’s cloud sync and log out of the current login account to prevent the modified and removed data from being automatically synced back;

Exit method:

您可以从Chrome退出Google帐户。
1.在计算机上,打开Chrome。
2.在右上角,单击“配置文件退出”。
如果您打开了同步功能,则可以将其关闭。这也将使您退出Gmail等Google帐户服务。
1.在计算机上,打开Chrome。
2.单击右上角的“配置文件同步到[电子邮件]”。
3.在“人员”下,单击“关闭”,然后单击“关闭”。
注意:如果您在Chrome中打开了同步功能,并退出了Gmail之类的Google服务,那么您也将退出Chrome。这将暂停同步,直到您使用同一帐户重新登录。
关闭Chrome登录

通过Gmail之类的服务登录Google帐户后,您将自动登录Chrome。如果您不想登录Chrome或打开同步功能,则可以更改设置。
1.在计算机上,打开Chrome。
2.单击右上角的“其他设置”。
3.在“隐私和安全性”下,关闭“允许Chrome登录”。
    *如果您在Chrome中打开了同步功能,则关闭此设置也会关闭同步功能。

You can sign out of your Google Account from Chrome.

  1. On your computer, open Chrome.

  2. At the top right, click Profile   Sign out.

If you have sync turned on, you can turn it off. This will also sign you out of your Google Account services, like Gmail.

  1. On your computer, open Chrome.

  2. At the top right, click Profile   Syncing to [email].

  3. Under "People," click Turn off  Turn off.

Note: If you turned sync on in Chrome and sign out of a Google service, like Gmail, you'll also be signed out of Chrome. This will pause sync until you sign back in with the same account.

Turn off Chrome sign-in

When you sign in to your Google Account, through a service like Gmail, you’ll be automatically signed in to Chrome. If you don’t want to ever sign in to Chrome or turn sync on, you can change your settings.

  1. On your computer, open Chrome.

  2. At the top right, click More   Settings.

  3. Under "Privacy and security," turn off Allow Chrome sign-in.                                                                                           If you turned sync on in Chrome, turning off this setting will also turn off sync.

2)关闭浏览器,通过系统给的接口,移除相关profile配置

Close the browser and remove the related profile configuration through the interface provided by the system

/usr/bin/profiles -D -f

3)关闭浏览器,通过Chrome的接口,移除相关配置:

Close the browser and remove the related configuration through the interface of Chrome:

sudo defaults delete com.google.Chrome HomepageIsNewTabPage
sudo defaults delete com.google.Chrome NewTabPageLocation
sudo defaults delete com.google.Chrome HomepageLocation
sudo defaults delete com.google.Chrome DefaultSearchProviderEnabled
sudo defaults delete com.google.Chrome DefaultSearchProviderSearchURL
sudo defaults delete com.google.Chrome DefaultSearchProviderNewTabURL
sudo defaults delete com.google.Chrome DefaultSearchProviderName

4,这样之后,再重启电脑,重置浏览器,一般都能解决上述问题了啦!解决后的chrome://policy/ 显示的干干干净,如下:

After that, restarting the computer and resetting the browser can usually solve the above problems! The resolved chrome: // policy / is displayed as follows:

通过上述方法一般都能解决删除恶意软件之后,Chrome主页不能被重置的问题,感兴趣的可以试试哈!

The above method can generally solve the problem that the Chrome home page cannot be reset after removing the malware. Those who are interested can try it!

顺便说下Windows的解决办法:

下载后管理员权限运行

https://download.csdn.net/download/julius_lee/12253192

或者通过删除注册表进行移除;

1.在浏览器访问这个:Chrome://policy,会看到政策名为EnabledPlugins

2.按win+R:输入:%systemroot%\syswow64\regedit,跳转到注册表编辑器

3.按Ctrl+F,查找政策名为EnabledPlugins的目录,然后右键删除

4.重启Chrome,由贵单位管理消失

By the way Windows solutions:

Run with administrator rights after download

https://download.csdn.net/download/julius_lee/12253192

Or remove it by deleting the registry;

1. Visit this in your browser: Chrome: // policy, you will see the policy named EnabledPlugins

2. Press win + R: Enter:% systemroot% \ syswow64 \ regedit, jump to the registry editor

3. Press Ctrl + F, find the directory named EnabledPlugins, and right-click to delete

4.Restart Chrome, disappeared by your organization management

 

忠告:
Advice:

1,苹果电脑要更新和下载软件尽量去App Store,其他浏览器突然弹出的说电脑有问题或者软件需要更新,都尽量不要点!!!!

2,电脑设置中安全设置,选项选择只安装认证过的软件!!!

3,要使用破解版软件,就必须做好被安装广告和恶意插件的心理准备!

1, Apple computer to update and download software as far as possible to the App Store, other browsers suddenly pop up saying that the computer has a problem or the software needs to be updated, try not to point! ! ! !

2, the security settings in the computer settings, the option to choose only installed certified software! ! !

3. To use the cracked version of software, you must be mentally prepared to install advertisements and malicious plug-ins!

 

如果觉得本文对你有帮助,那就赞一个或者评论一个吧,您的支持是我继续前进的动力!

If this article is helpful to you, please click like or comment on it. Your support is my motivation to move forward!

 

 

 

 

 

 

 


http://chatgpt.dhexx.cn/article/T9nXYTJ7.shtml

相关文章

Python sklearn学习之数据预处理——非线性转换

Python sklearn学习之数据预处理——非线性转换 文章目录 Python sklearn学习之数据预处理——非线性转换1. 两种常见的非线性转换1.1 分位数转换1.2 幂变换 2. sklearn中非线性变换的实现2.1 映射到均匀分布2.1.1QuantileTransformer类 2.2 映射到高斯分布2.2.1 Yeo-Johnson t…

javaScript学习笔记【尚硅谷】

javaScript学习笔记【尚硅谷】 这是我在看尚硅谷的前端大神超哥视频时,所记录的笔记! 文章目录 javaScript学习笔记【尚硅谷】[TOC](文章目录)1、javaScript基本知识1.2、JS编写位置1.3、JS基本语法1.4、变量与字面量1.5、标识符1.6、数据类型1.6.1、Nu…

机器学习流程及详细内容(1)

一般流程:数据收集、整理→数据预处理与特征工程(数据清理、集成、规约、变换、特征提取、筛选)→模型的选择与建立→模型的评估与优化。 数据收集 既可以使用公开的数据集,也可通过爬虫、购买或者实时数据的方式自己收集。 UC…

机器学习(Machine Learning)与深度学习(Deep Learning)资料汇总

《Brief History of Machine Learning》 介绍:这是一篇介绍机器学习历史的文章,介绍很全面,从感知机、神经网络、决策树、SVM、Adaboost到随机森林、Deep Learning. 《Deep Learning in Neural Networks: An Overview》 介绍:这是瑞士人工智能实验室Jurg…

Flutter 学习

Flutter 学习 参照:https://book.flutterchina.club/ 参照:https://flutter.cn/docs/development/platform-integration/platform-channels?tabtype-mappings-java-tab 目前进度:https://book.flutterchina.club/chapter9/animated_widgets…

原生开发如何学习 Flutter | 谷歌社区说

Hello 大家好,我是《Flutter 开发实战详解》的作者,Github GSY 系列开源项目的负责人郭树煜,目前开源的 gsy_github_app_flutter 以 13k 的 star 在中文总榜的 dart 排行上暂处第一名。 数据来源: https://github.com/GrowingGit/…

【CVRP】基于matlab遗传算法求解带容量的车辆路径规划问题【含Matlab源码 162期】

⛄一、VRP简介 车辆路径问题(VRP)最早是由 Dantzig 和 Ramser 于1959年首次提出,它是指一定数量的客户,各自有不同数量的货物需求,配送中心向客户提供货物,由一个车队负责分送货物,组织适当的行…

matlab解决LRP类型的多配送中心路径优化问题

** 问题描述 ** 有关多配送中心的选址-路径优化问题,一般是通过基于区域内的客户需要求,对配送中心进行合理的选址以及配送中心的车辆调度以及路径优化。在给出的配送中心候选点位置已知,需要在给出的这些位置中,通过与顾客需求…

<代码分享> 一种无人机配合卡车配送的车辆路径规划模型

本文为本人博客《一种无人机配合卡车配送的车辆路径规划模型》的代码分享。 由于近期此文的关注者较多,代码分享较为不便,因此决定专门写一篇博客以提供源码。 感谢各位博友关注,本人能力有限,如有错误,还请及时批评指…

(附源码)springboot车辆管理系统 毕业设计031034

车辆管理系统的设计与实现 摘 要 科技进步的飞速发展引起人们日常生活的巨大变化,电子信息技术的飞速发展使得电子信息技术的各个领域的应用水平得到普及和应用。信息时代的到来已成为不可阻挡的时尚潮流,人类发展的历史正进入一个新时代。在现实运用中&…

QT+SQL Server实现车辆管理系统 -代码具体实现

QTSQL Server 实现车辆管理系统 -代码具体实现 1.摘要2.整体框架3.具体代码实现3.1 连接数据库3.2 登录操作3.3 申请账户3.4 添加车辆信息3.5 查询车辆信息3.6删除车辆信息3.7修改车辆信息3.8 添加司机信息 4.总结5.资源下载链接 1.摘要 前面一篇文章简要介绍了车辆管理系统的…

如何使用低代码进行车队管理?

处理任何业务都具有挑战性,但车队管理无疑是所有业务中的佼佼者。无论是司机短缺、环境问题、国际法规还是行业不稳定,车队经理都必须面对这一切。除此之外,还有数字化和路线优化的概念。数字化转型车队管理业务意味着消除挑战,拥…

车辆自然驾驶轨迹数据集/交通流数据介绍

文章目录 NGSIMNGSIM 概览快速路车道选择算法Interstate 80 Freeway 数据集Lankershim Boulevard 数据集US highway101数据集动态交通分配DTACORSIM Argoverse Motion Forecasting DatasetAIMSUNHighDITS DataHub 美国智能交通数据库Data.govPeMSPortland Oregon Region data英…

3D车辆检测AP评价指标代码的理解

课题研究的是单目3D车辆的识别,采用的目标检测网络是SMOKE,为了可以更好的定量评测训练模型的性能,需要使用到合理的评测指标,目前比较流行的评测指标是得到多组precision和recall值画出PR曲线,然后计算PR曲线下的面积…

根据车辆型号自动生成车辆编号

开发工具与关键技术:Visual Studio 2015 linq 正则 作者:孙水兵 撰写时间:2019年6月26一、 功能 根据不同的类型的车辆型号,生成以车辆型号开头的车辆编号。 二、 达到的效果 用户选择了车辆型号之后,将对应的车辆编…

【路径规划】基于遗传算法求解多车多类型车辆的车辆路径优化问题附matlab代码

1 内容介绍 多车辆多路线的交通路线优化涉及到排序问题,是一个N-P难题,高效精确的算法存在的可能性不大.提出了基于遗传算法的求解方法,给出了实例来证明如何利用遗传算法解决多车辆多路线的优化问题.结果证明,一般情况下利用遗传算法对于多车辆多路线的行车路线优化能得到一组…

机动车登记信息代码

原链接:机动车登记信息代 搜索结果本栏目用于收集和整理行业相关标准,如机械行业,化工行业等。http://www.gb99.cn/e/search/result/?searchid76243针对其中第七项车辆信息牌照代码如下:

利用低代码平台进行车辆管理,为交通行业添砖加瓦

概要:本文介绍了交通行业车辆管理的重要性,并详细阐述了基于低代码平台设计的车辆管理系统的优势。通过快速开发、易于维护、增加灵活性、提高数据可靠性、降低成本以及实时监控等多个方面,这种车辆管理系统可以帮助企业提高效率和降低成本&a…

(c++课程设计)简单车辆管理系统(有五种类型的车辆)代码+报告

关于这个课程设计 ,差点没把我头发愁没。 好了其实本质还是东拼西凑,编程能力没怎么长进,花里胡哨的东西却学了不少(不是) 万恶的学院,虽然要求三人一组,但是却分一二三类,三个人代…

什么是车辆识别代码(VIN)

车辆识别代码(VIN),VIN是英文Vehicle Identification Number(车辆识别码)的缩写。因为ASE标准规定:VIN码由17位字符组成,所以俗称十七位码。正确解读VIN码,对于我们正确地识别车型,以致进行正确地诊断和维修都是十分重要的。车辆识别代码根据国家车辆管理标准确定,包…