Dozens of dllhost tasks, but only for one user

Discussion in 'Malware Help (A Specialist Will Reply)' started by boweasel, Feb 15, 2014.

  1. boweasel

    boweasel Private E-2

    Several days ago my Dell Inspiron laptop (Windows XP Pro SP3) shut down after I clicked on a webpage link. When it restarted it seemed sluggish, so I opened taskmgr to find about 20 instances of dllhost.exe running under my user name. I could delete them, but after I'd gotten them whittled down to a few, they'd come roaring back. I rebooted, but saw no change.

    I then rebooted using another administrator account. No dllhost files. I ran a quick Malwarebytes scan. It found nothing. A full Malwarebytes scan. Nothing. A full MSE scan. TDSSKiller, AdwCleaner, JRT, ESET, SuperAntiSpyware, RogueKiller, MBar, Rkill. All either found nothing or just trivialities which I removed. Nothing made any difference - logging in as my primary user opens a heap of dllhost processes - all using between 4 and 12 MB. Logging in as another Administrator does not initiate any dllhost tasks. SFC /scannow finds no integrity violations.

    I downloaded and ran a tool called Emsisoft. It down 13 pieces of malware - Backdoor trojans and others - I can't find a log for it. But it changed nothing.

    Starting the laptop in any safe mode always gives me a non-specific BSOD. I can run a system restore to the day before the incident, but it always gives me the restore failure message upon restart.

    I have downloaded and run process monitor, but I fail to see how it can help with debugging.

    I downloaded, renamed, and ran ComboFix after disabling MSE's real time protection. It went through all the opening stuff - scan times for badly infected machines, etc., but it would never initiate. I left it on overnight and in the morning it still had not started stage one. The other 'curiousity' is that whenever I attempt to run ComboFix, although it doesn't start, when I finally end it I has lost my wireless connection, making my Default Gateway blank. I have to reboot the laptop to get a valid gateway value.

    I used Hitman Pro on this laptop about a year ago and cannot get it to remove anything, telling me that the license has expired.
    I'm about out of tools and ideas...
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. boweasel

    boweasel Private E-2

    Tell me specifically what you want me to do because if you reread my post I fail to see anything from the READ & RUN ME FIRST link that I haven't done. I didn't attach logs because RogueKiller, Malwarebytes, TDSSKiller all came out clean.

    The one other thing is that the ESET tool that I'd originally run from a desktop icon was actually called ESET Sirefef Cleaner, something that only checks for the specific Sirefef infection. Since then I have run the ESET Online Scanner, the results of which are included as an attachment. Although it found and removed a number of objects it failed to change the basic behavior - I boot the laptop, click on my user name, and after the desktop displays I open taskmgr and go to Processes. All looks good for about a minute, then I get a single dllhost.exe at the top of the list. About 3 seconds later I have 20 or more dllhost tasks. This does not happen with the other Administrative user.

    I've also included thr latest RogueKiller log, and will reun MalwareBytes and attach it's log a little later.
     

    Attached Files:

  4. boweasel

    boweasel Private E-2

    Attached are two Malwarebytes logs - one from a few days ago, the other from earlier today.
     

    Attached Files:

  5. boweasel

    boweasel Private E-2

    Don't these facts indicate the presence of malware?
    • I cannot boot the laptop in safe mode without getting a BSOD
    • I cannot perform a system restore
    • ComboFix will not start
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not neccessarily. I still would like you to run MGTools and get me that log. (C:\MGLogs.zip).
     
  7. boweasel

    boweasel Private E-2

    The MGTools log. Curious that when I searched for it, the computer found a single instance on the desktop, and over 2 dozen on the root drive. All had the same size, date and time stamp. Once I ended the search and explored the C:\ drive, there was but one instance.
     

    Attached Files:

  8. boweasel

    boweasel Private E-2

    I don't know if you're still out there TimW, and I have no idea how to interpret that MGTools log.... but whatever it did.... IT WORKED!.

    All those other tools I used, and the one I didn't use, the one I never heard of, did the trick.

    If you could tell me what it did I'd appreciate it. Was it a virus? Something else?

    Thanks again.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly, I don't know what was causing it, but good to know it is fixed.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds