Thread: COM Surrogate (dllhost.exe) trying to do weird things to ZA

    riceorony

    Default COM Surrogate (dllhost.exe) trying to do weird things to ZA

    

    COM Surrogate (dllhost.exe) was trying to communicate with (FileWrite) all of the files in the ZA folder in the Programs Folder (I think that's what ZLDir stands for?)

    What could attribute this occurrence? This is the first time I'm seeing this under the OSFirewall tab of my logs. Is it possibly attributed to me performing an online scan using Panda's activescan 2.0?

    All of the occurences were blocked by OSFirewall, but then mysteriously ZA-ISS 7.1 closed and my computer became unusable so I had to do a hard-shut down and restart.


    Operating System:
    Windows Vista Ultimate
    Software Version:
    7.1 (Vista)
    Product Name:
    ZoneAlarm Internet Security Suite

    Re: COM Surrogate (dllhost.exe) trying to do weird things to ZA

    
    

    It is part of the ZA self protection alerting you.
    Really harmless by itself.
    If you happen to see something like 21OOPX43QR.exe doing these attempts or perhaps svchost.exe (coming from the %WINDOWS% and not the %WINDOWS%system32) or perhaps explorer.exe (coming from the %WINDOWS%system32 and not the %WINDOWS% ), then there is a malware attacking the ZA.
    Otherwise, it is ignoreable.

    Doing an online scan (which uses activeX and the COM server components) would need to use the dllhost.exe, as it is com and activeX related.
    The ZA saw the dllhost.exe as a parent process in the online scanner attempts to open the ZA files.

    You could open the Options (in the right click of the dllhost.exe in the ZA program listing) and check the first two items and apply/ok to reduce the "noise" of the alerts.

    Open the OSFWRULES.XML with the notepad.exe and take a look at the self protection for the ZA and the protection the ZA is providing for Windows against malware.
    All kinds of registry, file, internet explorer protection is shown and described.
    This is all part of the OSFirewall protection of the ZA.
    {if you understand the .xml and windows and the ZA you could selectively edit and do a custom congifuration of the osfwrules.xml}

    
    

    

