Therefore, you should check the dllhost.exe process on your PC to see if it is a threat. I noticed it when windows power shell started repeated having an illegal operation... Download and run this tool, immediately it will start searching for suspicious programs on your computer and then shows a message how many programs it found. Good luck!  It took me a handful of times going through the process, but it worked.  You have to download RogueKiller and Process Explorer. useful reference

Hope this may help someone else...Best regards,LinI just wanted to say thank you sooo much, Lin. In the Windows/system32 folder I found a file called "winthemes_service.dll" which was proliferating rundll32.exe files. No one is ignored here. How to Get Data Off an Old Hard Drive (Without Putting It in a PC) Nest vs.

As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged I have a widget on windows 7 that shows hard drive and mem usage, this file was using 100% disk and 50/60 memory out of 10 megs. There went 6 hrs of antivirus wont find this because its not a virus. Its creeps the memory up and up until my computer stops working and basically crashes How to move file requesting permission When you have located the file...

This is just another work a round and Quads is right about the log files, ( I know how to read them and what I'm looking for but if your not Dllhost.exe is a trustworthy file from Microsoft. Currently, I have blocked powershell.exe from running (a copy exists in c:\windows\system32\windowspowershell\v1.0 and in c:\windows\syswow64\windowspowershell\v1.0). Case closed...

It's the ones that aren't running under that path that you need to worry about ok so then the one under system32 is not running. C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService It just means that you can safely ignore a rundll from either of those locations. this page Click on Settings > Detection and Protection > Non-Malware Protection > PUP (Potentially Unwanted Program) detections > Make sure it's set to Treat detections as malware Same for PUM (Potentially Unwanted

you will also need to turn all your anit-virus and/or firewalls off because these cleaners will clash with everything.

Follow the instructions that pop up for posting the results. Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process. I had been looking on the internet for hours, trying to figure out what exactly was wrong. Notepad will open with the results.

