DLLHost.exe (Com Surrogate) Bitcoin Miner Keeps Coming Back After Removal

Status
Not open for further replies.

ShadowSlim69

New Member
Mar 6, 2021
2
Yesterday I noticed that Com Surrogate was using a lot of resources, so I scanned with Malwarebytes Rootkit Remover and that picked up in the folder Appdata/Roaming/DLL had 2 files that were related to bitcoin mining, after using the tool to remove them they came back after reboot, I did notice however just before they appeared in the folder, there was a 7 Zip folder called VS_Files.7s that I presume extracted and put the 2 files into the DLL folder.

I did have some software that might have caused this that has been since removed, I have also done the farbar recovery scan and attached the files below.

Thank You
 

Attachments

  • Capture.PNG
    Capture.PNG
    9.9 KB · Views: 14
  • Addition.txt
    29.4 KB · Views: 11
  • FRST.txt
    60 KB · Views: 23

nasdaq

Moderator
Verified
Staff member
Nov 5, 2019
598
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.

Is the problem solved?
 

Attachments

  • fixlist.txt
    901 bytes · Views: 35
  • Thanks
Reactions: ShadowSlim69

ShadowSlim69

New Member
Mar 6, 2021
2
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.

Is the problem solved?

As of right now the files haven't come back even after a few reboots so the issue seems to have resolved thank you
 

Attachments

  • Fixlog.txt
    4.2 KB · Views: 12
Status
Not open for further replies.
Top