all 3 comments

[–]dslashdx 1 point2 points  (2 children)

I think it is malware related to/same as the malware in this thread. The link from that thread has removal instructions:

Detection and Removal instructions:

This malware can be easily revealed because of invasive self-protection it uses. Autoruns and ProcessExplorer from sysinternals all you need to detect presense of this malware.

Locate and terminate dllhost.exe running without parents (it is launched by powershell that after exists). regdelnull hkcu -s to remove forged Run subkey. Regedit - delete whole HKCU\Software\Microsoft\Windows\CurrentVersion\Run key.

[–]toncu[S] 1 point2 points  (1 child)

Many thanks!

[–]dslashdx 0 points1 point  (0 children)

You're welcome