COM Surrogate multiplies and takes over

Status
Not open for further replies.
Hey, I’m ___ and from
North America
Age group
31 - 40
Last known PC infection
I am joining because my PC is infected
Fav. Web Browser
Internet Explorer
Fav. Mobile OS
Android
Fav. Desktop OS
Windows
Fav. Antivirus
Avast

AaronPalmer

New Member
Thread author
Oct 20, 2014
0
I'm in the IT business, and I've removed a lot of viruses over the years, but this one has me stumped.

I have run Kaspersky virus removal tool from boot up and removed 52 Trojans off my clients PC. I then booted into Safe Mode and ran Malwarebytes Anti-Malware and removed another 9 malicious items as well as a large number of non-malware items. Running them again came up with nothing so I restarted my clients computer and found that the COM Surrogate process is still running in the background and when connected to the internet it multiplies and takes over. If Internet is disconnected it shrinks back down till there are only one or two processes running.

I created a new profile and logged into it to see if the COM Surrogate process would show up there but it doesn't. It is limited to the primary profile.

In the time it took me to write this post, the processes went from 3 in the attached picture to 15 processes. Help would be much appreciated.

Edit: Ran RKill to see if it would see malicious activity running in the background and it found nothing. Document attached.
 

Attachments

  • COM Surrogate.png
    COM Surrogate.png
    2.3 KB · Views: 390
  • FRST.txt
    37.9 KB · Views: 479
  • Addition.txt
    28.2 KB · Views: 424
  • Rkill.txt
    3.3 KB · Views: 367
Last edited:
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top