Help! com surrogate virus :(

blythepotter

New Member
Thread author
Oct 22, 2014
3
workstation has been displaying pop-ups saying "Your current security settings do not allow this file to be downloaded". Hundreds and hundreds of times an hour. com surrogate and multiple Dllhosts.exe processes running in the task manager. FRST.txt and Additional.txt have been attached, any help is appreciated :)
 

Attachments

  • Addition.txt
    24.6 KB · Views: 109
  • FRST.txt
    23.7 KB · Views: 50

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


I am not sure I can help you, because this is not home edition windows, but let's try. Currently I do not see signs of infection here.



FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.




RogueKiller.png
Scan with RogueKiller

Please download RogueKiller and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
  • Right-click on
    RogueKiller.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the pre-scan will be done. It shouldn't take more than 2-3 minutes.
  • Accept the Terms of use.
  • When the Scan button becomes available, please click it. RogueKiller will start a full scan.
  • Let this process run uninterrupted!.
  • When finished, a Report button will become available. Click it. You will be presented with a logfile.
Please include the content of this logfile in your next reply.
 

Attachments

  • fixlist.txt
    1.6 KB · Views: 44

blythepotter

New Member
Thread author
Oct 22, 2014
3
Thank you for getting back to me so quickly! Sorry I didn't get back yesterday I was out of town getting my car fixed in Redmond. I am currently running the scan tools and will report back asap :)
 

blythepotter

New Member
Thread author
Oct 22, 2014
3
Well, this workstation is still infected after hours of trying to clear this malware/virus :( I re-ran the FARBAR scan under the infected user's profile this time. I'm thinking they will have different results. I will have to come in this weekend and work some overtime to get this resolved. I would just reformat the c:\ drive but we dont have access to some important Certs installed. Please take a look at these NEW scan results and let me know what the next step is. Thanks TwinHeadedEagle :)
 

Attachments

  • Addition.txt
    21.6 KB · Views: 59
  • FRST.txt
    22.1 KB · Views: 119

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top