HELP REQUEST: dllhost.exe COM Surrogate Trojan

A26B

New Member
Thread author
Nov 6, 2014
11
Assistance requested. Topic says it all. Thanks in advance.
 

Attachments

  • Addition.txt
    33.1 KB · Views: 70
  • FRST.txt
    56.7 KB · Views: 110

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
Hi.


FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.






Download ESET Poweliks Cleaner
http://download.eset.com/special/ESETPoweliksCleaner.exe

When the download is complete, navigate to your Desktop, double-click ESETPoweliksCleaner.exe.
Read the terms of the End-user license agreement and click Agree if you agree to them.

The tool will run automatically. If the cleaner finds a Poweliks infection, press the Y key on your keyboard to remove it.

If Poweliks was detected "Win32/Poweliks was successfully removed from your system" will be displayed.
Press any key to exit the tool.

After removing an infection we highly recommend that you restart your computer. The infection should now be removed and you should be able to access the web content that was being blocked.
 

Attachments

  • Fixlist.txt
    312 bytes · Views: 61

A26B

New Member
Thread author
Nov 6, 2014
11
No option to select Administrator
Ran "Fix"
No Fixlog generated
Both attached logs are in the same location (desktop)
 

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
Both files, FRST (tool) and fixlist.txt have to be in the same location or the fix will not work!

Double click the FRTS and click Fix



edit

You have downloaded fixlist
 
Last edited:

A26B

New Member
Thread author
Nov 6, 2014
11
FRST & Addition were the only files generated from Scan and they are in the same directory.
 

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
You have downloaded fixlist?
 

Attachments

  • 2014-11-06_175223.jpg
    2014-11-06_175223.jpg
    110.2 KB · Views: 77

A26B

New Member
Thread author
Nov 6, 2014
11
Sorry, I am not seeing a fixlist download link, only a reference to it with FRST
 

A26B

New Member
Thread author
Nov 6, 2014
11
Still in progress, sorry for my confusion, I thought fixlist would be generated by FRST. My bad...
 

A26B

New Member
Thread author
Nov 6, 2014
11
Fix completed. "Fixlog.txt saved. Should I restart now as advised?
 

Attachments

  • Fixlog.txt
    1.1 KB · Views: 47

A26B

New Member
Thread author
Nov 6, 2014
11
fine for now. I could end the trojan COM Surogates process proliferation and it would lay low for awhile then come back. SO it may take a day for me to be comfortable with it actually being gone. FWIW, I did notice that when it first became visible on Task Manager, it initiated with 8460K memory & spread from there with increasing amounts of memory consumption. I could end the process on the first one and kill them all. Sort of like an upside down pyramid.
 

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
You are happy, poweliks is backdoor, was not long in system.



Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the
    51a5ce45263de-delfix.png
    icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run and wait until the tool completes his work.
  • All tools we used should be gone. Tool will create an report for you (C:\DelFix.txt)
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
 

A26B

New Member
Thread author
Nov 6, 2014
11
Looks like I sent you 3 donations of $40 ea. PayPal indicated error 2X. Must be the gods telling me it was worth it!! Thank you!!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top