Computing.Net > Forums > Security and Virus > EXE question: is it legitimate?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

EXE question: is it legitimate?

Reply to Message Icon

Name: Laogeodritt
Date: August 17, 2004 at 19:50:59 Pacific
OS: Windows XP Home
CPU/Ram: Pentium 4 2.54 GHz; 256 M
Comment:

I was recently using Windows NT backup I installed from the Value_Add folder, and my McAfee product (Firewall, I think, but I have the Internet Security Suite) said that it blocked an exe from accessing the internet at C:\Windows\system32\dllhost.exe. Is this a false alarm, and is this program legitimate? Or is it a threat?

Here's some more information:

It's listed in McAfee firewall as "COM Surrogate" and a trojan. It had suggested I do a system virus scan, and I did, but there weren't any virus' found (and my VirusScan also searches for Trojans and some Spyware). It was in memory when I ran the scan, but it isn't at startup. If anyone needs the HijackThis log to help me, I can do so. Please respond.

Laogeodritt



Sponsored Link
Ads by Google

Response Number 1
Name: Laogeodritt
Date: August 17, 2004 at 20:52:37 Pacific
Reply:

I forgot to say I also have this "hidden" file (though my settings say to unhide hidden files) called "thumbs.db" or something similar in some of my folders. Also, my AntiVirus Activesheild just detected something in my Temporary internet files about a URL-related Exploit (can't remember name). I'm really worried. Help, please.

Laogeodritt


0

Response Number 2
Name: darkfriend
Date: August 17, 2004 at 21:02:15 Pacific
Reply:

They are probably unrelated but who knows. I have the file dllhost.exe in that folder it was created 8.23.01 with a size of 5.00kB. The date on yours may be slightly different with XP Home, but shouldn't be yesterday's date. That file runs alot of legit stuff and should be fine. Maybe just the fact that it's trying to access the internet flags McAfee. Who knows why half the stoopid MS programz try to get on the net.

There are always some BS files in Temporary Internet Files trying to hijack your browser settings, just delete them all and be done with it. Get Adaware SE and Spybot 1.3.
-DF


0

Response Number 3
Name: Laogeodritt
Date: August 17, 2004 at 21:12:58 Pacific
Reply:

I would like a bit of clarification on your post, and some new questions.

1) So, you're saying that it is a legit program? So how come it's considered malicious with McAfee?

2) Should I leave it blocked in the firewall (so it doesn't have access to 'net?)

3) So the temp internet files issue is common and won't do damage, with my AntiVirus program?

4)What are "BS" files?

5) The "thumbs.db" files thing hasn't been answered.


Thank you very much for your help. I agree that many MS/Windows programs try to access the internet (and don't even trigger the password box to use it). Should I allow these programs access to the internet?

Laogeodritt


0

Response Number 4
Name: www
Date: August 17, 2004 at 21:39:46 Pacific
Reply:

thumbs.db is a valid windows file.
What is Thumbs.db?


0

Response Number 5
Name: Laogeodritt
Date: August 17, 2004 at 21:45:22 Pacific
Reply:

So its the thumbnail cache! Anyway, here are the questions I still have unanswered that I still wish to know the answer to.

1) So, you're saying that it is a legit program? So how come it's considered malicious with McAfee? (dllhost.exe)

2) Should I leave it blocked in the firewall (so it doesn't have access to 'net?) (see 1)

4)What are "BS" files?

Laogeodritt


0

Related Posts

See More



Response Number 6
Name: Wombat
Date: August 17, 2004 at 21:54:48 Pacific
Reply:

BS Files are Bull sh*t files...

Iligitimi non carborundum est


0

Response Number 7
Name: Laogeodritt
Date: August 17, 2004 at 22:08:47 Pacific
Reply:

Ohh...

Well, thanks...

Laogeodritt


0

Response Number 8
Name: darkfriend
Date: August 17, 2004 at 22:21:46 Pacific
Reply:

Any new program trying to access the net is flagged by Firewalls. Most just don't give enough info why it is bad or not.

For the most part my philosophy is if its trying to get out let it go. If its trying to get in the firewall will block it. So always allow is my philosophy. I don't care what programs go out on the net and infect others. I just don't want it to come back. The firewall blocks all incoming. Just let it go.

Delete ALL your Temporary Internet Files. That's where most of the virus and trojans hang out at.
-DF


0

Response Number 9
Name: I ll Try
Date: August 17, 2004 at 22:44:58 Pacific
Reply:

Laogeodritt,

1.) You said,
"C:\Windows\system32\dllhost.exe"
If you had said this,
C:\Windows\System32\Wins\Dllhost.exe
(welchia & msblast)

That's one of the reasons, probably, why it got flagged. And also, why it said what it did ("trojan"), in the firewall.
Who knows ;-)
Just a little info.

2.) Your call, on that one. Someone (credibile), will/should advise you.

Darkfriend,

So, you wouldn't care, if something was sending out all your private info? Nevermind, people with your attitude, is why there is so much BS!

RRRRR
Later,
I'll Try


0

Response Number 10
Name: FBI Agent
Date: August 18, 2004 at 11:15:20 Pacific
Reply:

yeah, so many BS files, you know, those bullsh!t files. you could try an online virus scan

FBI Agent

AIM: EliteAssassin187


0

Response Number 11
Name: Laogeodritt
Date: August 18, 2004 at 12:07:04 Pacific
Reply:

darkfriend,

I have my firewall set to ask me if I want to block it or grant it access (along with the Firewall's advice), but this one was blocked automatically.

Laogeodritt


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: EXE question: is it legitimate?

svchost.exe what is it www.computing.net/answers/security/svchostexe-what-is-it/4410.html

jdbgmgr.exe what is it? www.computing.net/answers/security/jdbgmgrexe-what-is-it/3655.html

trickler_3210.exe WHAT is it ???? www.computing.net/answers/security/trickler3210exe-what-is-it-/2432.html