.dllhost COM surrogate running multiple instances

Status
Not open for further replies.

fangshway

New Member
Thread author
Aug 27, 2014
9
I've been browsing the other threads of those with the same issue as mine but I'm not sure if i should just follow the same directions. Can anyone either help me solve this or direct me to the right thread to follow instructions?
 

Attachments

  • Addition.txt
    45.1 KB · Views: 151
  • AdwCleaner[S0].txt
    8.2 KB · Views: 125
  • FRST.txt
    46.4 KB · Views: 133
  • Rkill.txt
    2.2 KB · Views: 59

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
51a5bf3d99e8a-ComboFixlogo16.png
Scan with ComboFix

This is a very powerful tool that should be used only if advised by Malware Analyst.
Do not run ComboFix on your own!


Referring to this instruction, please download ComboFix by sUBs and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a5bf3d99e8a-ComboFixlogo16.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Accept the disclaimer and agree if prompted to install Recovery Console.
  • Do not take any actions while ComboFix goes through your System - it may cause it to stall!
  • This scan may take some time!
  • When finished - it will display a logfile (located also on your main drive, usually C:\ComboFix.txt).

Include that log in your next reply.
icon_idea.gif
If you'll encounter any issues with internet connection after running ComboFix, please visit this link.
icon_idea.gif
If an error about operation on the key marked for deletion will appear after running the tool, please reboot your machine.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Very good, we're making some progress :)


FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 

fangshway

New Member
Thread author
Aug 27, 2014
9
everything seems to be working fine since i ran combofix, however when i open chrome i still get three windows that open to alternate search engines that i never chose to use
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.




Tell me how is your PC now?
 

Attachments

  • fixlist.txt
    1.8 KB · Views: 120
Last edited:

fangshway

New Member
Thread author
Aug 27, 2014
9
i have the fixlist.txt on my desktop along with my FRST and i ran it as administrator but it crashes after about 30 seconds. i was running other programs at the same time though let me try it without.
 

fangshway

New Member
Thread author
Aug 27, 2014
9
yeah still the same issue, heres the log from the windows crash report:

Problem Event Name: APPCRASH
Application Name: FRST64.exe
Application Version: 30.8.2014.0
Application Timestamp: 54018bca
Fault Module Name: ntdll.dll
Fault Module Version: 6.1.7600.16559
Fault Module Timestamp: 4ba9b802
Exception Code: c00000fd
Exception Offset: 00000000000536ac
OS Version: 6.1.7600.2.0.0.768.3
Locale ID: 1033
Additional Information 1: c97e
Additional Information 2: c97eac62f095f40edf8b6dab370bb979
Additional Information 3: dd13
Additional Information 4: dd139bda81a8a2271f18926f634b393a

Read our privacy statement online:
http://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0409

If the online privacy statement is not available, please read our privacy statement offline:
C:\Windows\system32\en-US\erofflps.txt
 

fangshway

New Member
Thread author
Aug 27, 2014
9
about 30 seconds after i press fix, i should restart my comp and try again, i forgot to do that.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Let's try with another tool:



51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a612a8b27e2-Zoek.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    Code:
    createsrpoint;
    autoclean;
    chrdefaults;
    emptyalltemp;
    ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to me or any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top