30 dllhost.exe*32 COM Surrogate processes

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mattbiel, Feb 21, 2014.

  1. mattbiel

    mattbiel Private E-2

    My computer is infected, I don't know with what. I have (stupidly) tried every tool I could find to scan and remove it. These 30 dllhost processes remain and are slowing my computer down to a crawl. I found a thread on another site that describes my issue exactly, and they used OTL to remove it finally...I don't know how to use that. I am attaching logs of MGtools, TDSSKiller, and Hitman Pro. Malwarebytes, RogueKiller, and MGtools all failed to finish scanning.

    Here is the link to the thread of the other person that had a problem that seems the same as mine if it helps:
    http://www.bleepingcomputer.com/forums/t/514186/30-dllhostexe32-com-surrogate-processes-are-running/
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Logs from Malware Bytes and RogueKiller did not attach. ;)
     
  3. mattbiel

    mattbiel Private E-2

    Thank you for looking at my case! I cannot get a MBAM or RogueKiller scan to complete...are there logs somewhere for them even though they didn't complete?
     
  4. mattbiel

    mattbiel Private E-2

    I was finally able to get MBAM to complete a scan in safe mode. I am attaching the log!

    Still cannot get RogueKiller to complete a scan even in safe mode but I am attaching a screen shot of where it gets stuck.

    Thank you for your help!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete:
    Malware Bytes says you took no action on those items it found, did you do so AFTER attaching the log?



    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  6. mattbiel

    mattbiel Private E-2

    Thank you for your time, Kestrel. I was able to find local help and they resolved the issue with the computer. It's malware free and running great!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it! ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds