Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I was recently using Windows NT backup I installed from the Value_Add folder, and my McAfee product (Firewall, I think, but I have the Internet Security Suite) said that it blocked an exe from accessing the internet at C:\Windows\system32\dllhost.exe. Is this a false alarm, and is this program legitimate? Or is it a threat?
Here's some more information:
It's listed in McAfee firewall as "COM Surrogate" and a trojan. It had suggested I do a system virus scan, and I did, but there weren't any virus' found (and my VirusScan also searches for Trojans and some Spyware). It was in memory when I ran the scan, but it isn't at startup. If anyone needs the HijackThis log to help me, I can do so. Please respond.
Laogeodritt

I forgot to say I also have this "hidden" file (though my settings say to unhide hidden files) called "thumbs.db" or something similar in some of my folders. Also, my AntiVirus Activesheild just detected something in my Temporary internet files about a URL-related Exploit (can't remember name). I'm really worried. Help, please.
Laogeodritt

They are probably unrelated but who knows. I have the file dllhost.exe in that folder it was created 8.23.01 with a size of 5.00kB. The date on yours may be slightly different with XP Home, but shouldn't be yesterday's date. That file runs alot of legit stuff and should be fine. Maybe just the fact that it's trying to access the internet flags McAfee. Who knows why half the stoopid MS programz try to get on the net.
There are always some BS files in Temporary Internet Files trying to hijack your browser settings, just delete them all and be done with it. Get Adaware SE and Spybot 1.3.
-DF

I would like a bit of clarification on your post, and some new questions.
1) So, you're saying that it is a legit program? So how come it's considered malicious with McAfee?
2) Should I leave it blocked in the firewall (so it doesn't have access to 'net?)
3) So the temp internet files issue is common and won't do damage, with my AntiVirus program?
4)What are "BS" files?
5) The "thumbs.db" files thing hasn't been answered.
Thank you very much for your help. I agree that many MS/Windows programs try to access the internet (and don't even trigger the password box to use it). Should I allow these programs access to the internet?Laogeodritt

So its the thumbnail cache! Anyway, here are the questions I still have unanswered that I still wish to know the answer to.
1) So, you're saying that it is a legit program? So how come it's considered malicious with McAfee? (dllhost.exe)
2) Should I leave it blocked in the firewall (so it doesn't have access to 'net?) (see 1)
4)What are "BS" files?
Laogeodritt

Any new program trying to access the net is flagged by Firewalls. Most just don't give enough info why it is bad or not.
For the most part my philosophy is if its trying to get out let it go. If its trying to get in the firewall will block it. So always allow is my philosophy. I don't care what programs go out on the net and infect others. I just don't want it to come back. The firewall blocks all incoming. Just let it go.
Delete ALL your Temporary Internet Files. That's where most of the virus and trojans hang out at.
-DF

Laogeodritt,
1.) You said,
"C:\Windows\system32\dllhost.exe"
If you had said this,
C:\Windows\System32\Wins\Dllhost.exe
(welchia & msblast)That's one of the reasons, probably, why it got flagged. And also, why it said what it did ("trojan"), in the firewall.
Who knows ;-)
Just a little info.2.) Your call, on that one. Someone (credibile), will/should advise you.
Darkfriend,
So, you wouldn't care, if something was sending out all your private info? Nevermind, people with your attitude, is why there is so much BS!
RRRRR
Later,
I'll Try

yeah, so many BS files, you know, those bullsh!t files. you could try an online virus scan
FBI Agent
AIM: EliteAssassin187

darkfriend,
I have my firewall set to ask me if I want to block it or grant it access (along with the Firewall's advice), but this one was blocked automatically.
Laogeodritt

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |