Fake COM Surrogate is keeping on coming back.

Ahmed Reda Saied Ahmed Elshazly 0 Reputation points
2025-12-15T15:10:05.54+00:00

Hello everyone
so I had that com surrogate problem where it consumes about 70% from the CPU non stop, also it have a deluding name where the file executing the com surrogate is located at C:\Users\Ahmed\AppData\Roaming\Dll and the file name is dlI.host "the first letter is small L and the third is a capital i" and it is a mining virus, there was a post here that recommended to do some steps in safe and normal mode to make sure it is not coming back but it always comes back, I need your help.

Windows for home | Windows 11 | Security and privacy
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Q&A Assist
    2025-12-15T15:10:19.0933333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    It sounds like you're dealing with a persistent malware issue that disguises itself as a COM Surrogate. Here are some steps you can take to address the problem:

    1. Run a Full Antivirus Scan: Ensure your antivirus software is up to date and perform a full system scan to detect and remove any malicious software.
    2. Use Malware Removal Tools: Consider using specialized malware removal tools like Malwarebytes or Windows Defender Offline to scan and remove stubborn malware.
    3. Check Startup Programs: Use the Task Manager to check for any suspicious programs that start with Windows. Disable any that look unfamiliar or suspicious.
    4. Delete Suspicious Files: Navigate to the directory mentioned (C:\Users\Ahmed\AppData\Roaming\Dll) and manually delete the suspicious file dlI.host. Ensure that you have hidden files visible in your folder options.
    5. Check Registry Entries: Sometimes malware creates registry entries to persist. Use regedit to check for any entries that reference the suspicious file and remove them. Be cautious when editing the registry, as incorrect changes can cause system issues.
    6. Reset Web Browsers: If the malware has affected your web browsers, reset them to their default settings to remove any unwanted extensions or changes.
    7. Reinstall Windows: If the problem persists and you cannot remove the malware, consider backing up your data and performing a clean installation of Windows.
    8. Seek Professional Help: If you are not comfortable performing these steps, consider seeking help from a professional technician.

    Make sure to back up important data before making significant changes to your system.


    References:

    0 comments No comments

  2. DaveM121 815.3K Reputation points Independent Advisor
    2025-12-15T15:42:29.2466667+00:00

    1

    Please provide a screenshot of where you are seeing that COM Surrogate entry listed on your system.

    2

    Click the link below to download a small free utility that does not require installation.

    https://download.sysinternals.com/files/Autoruns.zip

    When the file downloads, unzip it.

    Run Autoruns64 as Administrator

    A

    Select the 'Logon' tab at the top of Autoruns.

    Please provide a screenshot of all entries on that tab.

    B

    Select the 'Scheduled Tasks' tab at the top of Autoruns.

    Please provide a screenshot of all entries on that tab.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.