Multiple dllhost.exe, msiexec.exe and cmd.exe

Eric Jones

New Member
Thread author
Aug 12, 2015
10
I've attached both scan logs from FRST.
 

Attachments

  • Addition_8-12-2015_1215.txt
    29.8 KB · Views: 2
  • FRST_8-12-2015_1215.txt
    19.3 KB · Views: 2

Eric Jones

New Member
Thread author
Aug 12, 2015
10
Also, this PC is a company machine and thus has some software that may be unrecognized compared to a typical "home" computer. I'm pretty knowledgeable about what that Company software is, so I'll let you know if something I'm asked to remove is necessary to the operations of this computer.
 

Eric Jones

New Member
Thread author
Aug 12, 2015
10
@TwinHeadedEagle: no matter how I word a message in PM it give me:

Your content can not be submitted. This is likely because your content is spam-like or contains inappropriate elements. Please change your content or try again later. If you still have problems, please contact an administrator.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
51a5bf3d99e8a-ComboFixlogo16.png
Scan with ComboFix

This is a very powerful tool that should be used only if advised by Malware Analyst.
Do not run ComboFix on your own!


Referring to this instruction, please download ComboFix by sUBs and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a5bf3d99e8a-ComboFixlogo16.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Accept the disclaimer and agree if prompted to install Recovery Console.
  • Do not take any actions while ComboFix goes through your System - it may cause it to stall!
  • This scan may take some time!
  • When finished - it will display a logfile (located also on your main drive, usually C:\ComboFix.txt).

Include that log in your next reply.
icon_idea.gif
If you'll encounter any issues with internet connection after running ComboFix, please visit this link.
icon_idea.gif
If an error about operation on the key marked for deletion will appear after running the tool, please reboot your machine.
 

Eric Jones

New Member
Thread author
Aug 12, 2015
10
Is it better to run Combofix in Safe Mode, or should I just run it from a normal windows session?
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Let's use FRST again:

FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 

Eric Jones

New Member
Thread author
Aug 12, 2015
10
Here are the requested logs.
 

Attachments

  • Addition_08-13-15_1554.txt
    27.7 KB · Views: 1
  • FRST_08-13-15_1554.txt
    20.8 KB · Views: 1

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
2eyjdoj.png
Check Disk
  • Press the
    WindowsKey.png
    + R on your keyboard at the same time. Type cmd and click OK.
  • Copy/Enter the command below and press Enter:
  • Code:
    chkdsk C: /r
  • You should get a message to schedule Check Disk at next system restart. Please type Y and press Enter.
  • All you should do now is to restart your PC and let the Check Disk process finish uninterrupted.
Check Disk report:
  • Press the
    WindowsKey.png
    + R on your keyboard at the same time. Type eventvwr and click OK.
  • In the left panel, expand Windows Logs and then click on Application.
  • Now, on the right side, click on Filter Current Log.
  • Under Event Sources, check only Wininit and click OK.
  • Now you'll be presented with one or multiple Wininit logs.
  • Click on an entry corresponding to the date and time of the disk check.
  • On the top main menu, click Action > Copy > Copy Details as Text.
  • Paste the contents into your next reply.
 

Eric Jones

New Member
Thread author
Aug 12, 2015
10
I am unable to do the last part about copying data from the Event Viewer. There doesn't appear to be any events tied to a chkdsk either upon scanning through the list. Maybe XP doesn't do that part? Regardless, when it did the check disk, it said disk was clean on the window that ran. Also, after the reboot, the system is running much better and i'm not seeing the rogue processes!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top