My Windows 7 machine became infected with a Powershell virus/malware unless I am mistaken. Running processes showed about 8 or 9 dllhost.exe *32 Com Surrogate processes running at once. CPU resources were almost at 100 percent and the hardrive fan were running very loud. Also, continuous IE activity was showing each time I deleted files even though I was not using the internet. Also, multiple intrusion attempts were then being blocked due to my machine being a slave to the malicious sites it was seeking out on its own unless I am mistaken. It also appeared that the IE security settings were automatically changed.
I read the other thread from a subscriber who posted wtih a similar problem. I do not believe this to be a PUA installed with other software. This seems to be a much more serious issue. This malware is taking control of IE and searching out malicious sites were intrusions followed. This is just my opinion though, as I am not an expert.
I did a lot of research on the net regarding others who have had this problem. It seemed that the virus was isolated to the user profile I was using. No mattter how many scans I did, my machine always came back clean. I created new profiles and ultimately deleted the infected profiles. It appears that the malicious activity does not exist on the new profiles. I used backup data and restored it to the new profiles. I'm hoping this solution is permanent, but I will be watching in case anything malicious wakes.
My quesiton is why was this malware not detected? I'm not sure if it is a variant of a Powershell or other signature. I know that it is mimicking a windows file that is necessary, but isn't there a way for this to be detected somehow? Even if there is not a signature to recognize this, I was hoping that the behavior of this malware would be deteced with the 0 day functionality.
I've never seen anything like this before and my goal is to protect against this type of thing in the future. Any thoughts, advice, or perspectives would be appreciated.
dllhost.exe / Com Surrogate malware not detected
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.