This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

dllhost.exe com surrogate [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My wife's computer has been infected with this virus. Her computer began slowing down dramatically starting a week ago. Looking at Task Manager, we found the culprit was using a lot of her memory. After "Ending Process" the memory use of Windows Explorer as recorded in Task Manager began to increase rapidly. I have done the scan with aswMBR and Farbar as instructed, and attach the logs here: 

 

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-08-21 09:17:59
—————————–
09:17:59.949    OS Version: Windows x64 6.1.7601 Service Pack 1
09:17:59.949    Number of processors: 2 586 0x3A09
09:17:59.951    ComputerName: SILJA-PC  UserName: Silja
09:22:00.518    Initialize success
09:22:11.406    VM: initialized successfully
09:22:11.406    VM: Intel CPU supported 
09:22:28.172    VM: disk I/O iaStorA.sys
09:22:40.833    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\000000c4
09:22:40.911    Disk 0 Vendor: ATA_____ 3M__ Size: 476940MB BusType: 11
09:22:42.533    Disk 0 MBR read successfully
09:22:42.533    Disk 0 MBR scan
09:22:42.533    Disk 0 Windows VISTA default MBR code
09:22:42.611    Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS         1500 MB offset 2048
09:22:42.705    Disk 0 default boot code
09:22:42.798    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       464823 MB offset 3074048
09:22:42.892    Disk 0 Partition 3 00     17 Hidd HPFS/NTFS NTFS        10616 MB offset 955031552
09:22:44.062    Disk 0 scanning C:\windows\system32\drivers
09:23:20.531    Service scanning
09:23:28.830    Service BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\BASHDefs\20140110.001\BHDrvx64.sys **LOCKED** 5
09:23:31.155    Service ccSet_NIS C:\windows\system32\drivers\NISx64\1406000.01B\ccSetx64.sys **LOCKED** 5
09:23:39.483    Service eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys **LOCKED** 5
09:23:40.200    Service EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys **LOCKED** 5
09:23:46.235    Service IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\IPSDefs\20150512.001\IDSvia64.sys **LOCKED** 5
09:24:04.424    Service NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20140115.032\ENG64.SYS **LOCKED** 5
09:24:05.298    Service NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20140115.032\EX64.SYS **LOCKED** 5
09:24:46.297    Service SRTSPX C:\windows\system32\drivers\NISx64\1406000.01B\SRTSPX64.SYS **LOCKED** 5
09:24:48.652    Service SymDS C:\windows\system32\drivers\NISx64\1406000.01B\SYMDS64.SYS **LOCKED** 5
09:24:49.385    Service SymEvent C:\windows\system32\Drivers\SYMEVENT64x86.SYS **LOCKED** 5
09:24:49.666    Service SymIRON C:\windows\system32\drivers\NISx64\1406000.01B\Ironx64.SYS **LOCKED** 5
09:24:49.822    Service SymNetS C:\windows\System32\Drivers\NISx64\1406000.01B\SYMNETS.SYS **LOCKED** 5
09:25:01.257    Modules scanning
09:25:01.304    Disk 0 trace - called modules:
09:25:01.319    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys storport.sys hal.dll iaStorA.sys 
09:25:01.335    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006557060]
09:25:01.335    3 CLASSPNP.SYS[fffff88001cf243f] -> nt!IofCallDriver -> [0xfffffa8006556aa0]
09:25:01.335    5 iaStorF.sys[fffff880019f0a2c] -> nt!IofCallDriver -> \Device\000000c4[0xfffffa80060189c0]
09:25:01.351    Disk 0 statistics 110202/0/0 @ 1.59 MB/s
09:25:01.351    Scan finished successfully
09:27:04.289    Disk 0 MBR has been saved successfully to "C:\Users\Silja\Desktop\MBR.dat"
09:27:04.289    The log file has been saved successfully to "C:\Users\Silja\Desktop\aswMBR.txt"
 
FARBAR

Addition.txt available at pastebin.com/EKm4Sg1d

FRST.txt:


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:14-08-2015 01
Ran by [removed] (administrator) on SILJA-PC (17-08-2015 05:14:07)
Running from C:\Users\[removed]\Desktop
[removed]

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days.

:)


Hello there, Gered

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

Sorry for the late response. Do you still require assistance?

—————————————————————————————————

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI