Please Help: COM Surrogate dllhost.exe *32

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Code:
CloseProcesses:
CustomCLSID: HKU\S-1-5-21-1218409403-638510066-2772475861-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1218409403-638510066-2772475861-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
C:\Users\Main Account\13-9_win7_win8_64_dd_ccc_whql.exe
EmptyTemp:
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.
 
Sorry about the late response. I had to work a 12 hour shift. :( Looks as if Com surrogate is not longer in my task manager.....
 

Attachments

Just turned my PC on for the first time since i resposted, went to search something real quick on IE. Then it popped up saying "Internet Explorer has stopped working". But it was still working. Opened task manager, and dlllhost.exe *32 COM Surrogate is back. Here is the FRST I just ran.
 

Attachments

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Code:
Start
CustomCLSID: HKU\S-1-5-21-1218409403-638510066-2772475861-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
HKU\S-1-5-21-1218409403-638510066-2772475861-1000\...\MountPoints2: F - F:\Autoplay.exe -auto
HKU\S-1-5-21-1218409403-638510066-2772475861-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
EptyTemp:
End
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.
 
This time the fix was literally instantly. I have my old frst files in a FOLDER thats on my desktop and the new frst with the new fixlist on the actual desktop with FRST64 also on my destop when I fixed it. Does that matter? After I did this, still shows COM surrogate running in my task manager.
 

Attachments

Scan with Combofix:
  • Please download ComboFix by sUBs and save it to your Desktop.
    You may read how Combofix works here.
  • Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
    If you are unsure how to do this please read this or this Instruction.
  • Run ComboFix. Click on I Agree! & follow the prompts.
    Note: If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart your computer.
  • When finished, it will produce a report for you. Please attach log reports (ComboFix.txt) back to topic.
    (typical log location: C:\ComboFix.txt )
 
I ran it again and the COM Surrogate is now gone from my task manager. Here is the new fixlog. Should I still use combofix?
 

Attachments

The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
checkmark.png
Remove disinfection tools
checkmark.png
Create registry backup
checkmark.png
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
 
Do I do anything else, like a certain scan? I'm just afraid it will popup in a day or so like it did last time... Nevermind, saw you just posted. ok, one moment
 
Ok. Thank you very much. I was actually uninstalling some programs right now and while some were uninstalling, I clicked on the task manager screen real quick and I saw ONE dllhost.exe *32 COM surrogate but the instant I clicked the task manager window and noticed it, it went away. Hasn't popped up yet. Maybe because I was uninstalling a "Microsoft Corporation" MSX something program I never remember installing a month ago and It popped up for a quick second because it was uninstalling. I don't know. But I don't see anything now. I will holler if it pops up tomorrow. I appreciate all your help. You have some beers coming your way :P