Google Chrome crash warnings but it is not installed.

pjhersom

Estimable
Dec 20, 2014
4
0
4,510
I have been getting a Google Chrome "crashed" or "Aw Shucks" message but I do not have Chrome installed. When I CTRL-ALT-DEL and bring up my Windows Task Manager I see multiple of processes with variable CPU and Memory (Private Working Set) readings, example shown below.

vzssqsmwxk.exe *32 <username> 01 114,560 K Google Chrome

I did a complete scan with Norton Antivirus and It didn't trigger a virus/malware response. I checked with the Google Chrome support site, but they only reference issues with installing Chrome and I don't want to install Chrome and it has never been installed on this system.

This started today and to be sure I de-installed the only software that I have installed on this system in the last week (CoffeeCup HTML Writer) and rebooted the system, but that did not resolve the issue.

My OS is Windows 7 Professional SP1.
 

pjhersom

Estimable
Dec 20, 2014
4
0
4,510
Thanks for the tip, MalwareBytes found an issue and quarantined it. Will monitor for 24 hours and make sure it's resolved.

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 12/20/2014
Scan Time: 5:41:24 PM
Logfile:
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2014.12.20.07
Rootkit Database: v2014.12.14.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User:

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 323930
Time Elapsed: 3 min, 35 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 3
IPH.Trojan.Clicker.W7, C:\Users\...\AppData\Local\Programs\ENXEFFPNDT.DLL, Delete-on-Reboot, [a07702636a12b77fe1f8d52bd62a857b],
IPH.Trojan.Clicker.W7, C:\Users\...\AppData\Local\Programs\ENXEFFPNDT.DLL, Delete-on-Reboot, [a07702636a12b77fe1f8d52bd62a857b],
IPH.Trojan.Clicker.W7, C:\Users\...\AppData\Local\Programs\ENXEFFPNDT.DLL, Delete-on-Reboot, [a07702636a12b77fe1f8d52bd62a857b],

Registry Keys: 0
(No malicious items detected)

Registry Values: 1
IPH.Trojan.Clicker.W7, HKU\S-1-5-21-2196557683-2761650257-1052596965-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|enxeffpndt, regsvr32.exe /s "C:\Users\...\AppData\Local\Programs\enxeffpndt.dll", Quarantined, [a07702636a12b77fe1f8d52bd62a857b]

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
IPH.Trojan.Clicker.W7, C:\Users\...\AppData\Local\Programs\ENXEFFPNDT.DLL, Delete-on-Reboot, [a07702636a12b77fe1f8d52bd62a857b],

Physical Sectors: 0
(No malicious items detected)


(end)