Multiple dllhost.exe/Com Surrogate processes running

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tesher07, Nov 5, 2014.

  1. tesher07

    tesher07 Private E-2

    In the past week my computer has BSOD'ed three times and at some point I noticed numerous instances of dllhost.exe/Com Surrogate processes running in the task manager its self. I am unsure if this is relevant to any virus, but my computer has been locking up very frequently when Firefox is the only program running. Below are the logs from the scans.
     

    Attached Files:

    Last edited: Nov 5, 2014
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  3. tesher07

    tesher07 Private E-2

    Added the FRST files requested.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it seems you have confused things because you ran Combofix on your own before posting here. You should never run ComboFix on your own. Thus your logs do not show signs of multiple dllhost.exe processes running. Nor does an active Poweliks infection show completely and it is what would cause this problem.

    But I do see some issues to address so we will take care of them but before we can get started, the first issue that MUST be address is that you are running multiple antivirus programs! You have Eset's NOD and also Microsoft Antimalware aka Microsoft Security Essentials installed and running. You need to uninstall one of these right now and then reboot. Then rerun the scan with FRST I requested and attach new logs.

    Then we will be able to continue on with other items I observed. Also
    please answer this question, "Are you really still having issues with multiple dllhost.exe processes running?" It does not look like it.
     
    Last edited: Nov 6, 2014
  5. tesher07

    tesher07 Private E-2

    I don't notice any new issues with the processes running, but they were occurring the day I posted the issue.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but you posted here on the basis of not having run ComboFix. Since you did, you had already changed the status of your PC. Thus the Title of your thread was actually no longer correct. ;)

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download this >> View attachment fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    How are things working now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds