We’re probably getting deep into the confusion of Windows now. Explorer.exe is the Windows shell; the function that provides the file management, desktop, and so on. It’s probably the first place components move around in. It’s also going to the Parent Application of any application you start from a desktop or toolbar shortcut.
What it looks like is that Explorer.exe, as the Windows shell (with dinput.dll integrated) has loaded dinput.dll into Explorer.exe, as the Firefox Parent Application. So, it’s loaded dinput.dll into itself. yeah, I know that sounds confusing. Think of its functions as somewhat compartmentalized, but interconnected. One aspect is operating as the shell, one aspect is the Parent of the browser. The .dll file loads into the shell, which then causes it to be part of the browser. This is all happening as a DNS query is being completed to Cox Communications; presumably then this IP is one of their DNS servers.
I would say this is safe to Allow w/Remember, as you can verify the IP, the function (DNS Query), you know the relationship between Firefox and Explorer.exe, and you know that dinput.dll is a legit file (even if you don’t know why it keeps popping up).
Thanks for the explaination; I’m not going to say I even begin to understand, but I’ll go through what you said and maybe at some point it’ll make sense.
And I have loaded dinput.dll into virusscan.jotti.org and it came out clean. Haven’t done any of the other two actions.
It would be good to submit to Comodo, so they can get it into the safelist (to prevent popups for future users). I’m not sure if you can submit from Component Monitor or not… you can check by right-clicking on the entry and seeing if it gives an option for submitting. I know you can with Application Monitor, but not sure about Component Monitor.
If not, I know you can with CAVS (if you’re using CAVS).
I don’t see a way to submit via component monitor, just add or remove, component monitor also doesn’t list dinput. I’m not running CAVS, so that’s out. Is it possible to submit from a pop-up?
There is that “SEnd to Comodo for Analysis” link, but I’m not sure if that might be for the main app, rather than the component. You can always try and see what it says it’s sending. You can also click that “View Libraries” button to see what’s on that window - there may be more options there, where you could submit.
Just FYI, I’ve only got v3 at the moment, which is vastly different from v2.4; that’s why I dont’ know some of these specifics - they’re not in the top of my head; the rest of it I’ve done from memory.
From what I remember the component was sytem32\dinput with allow/block, but then again when could I ever trust my memories. Alright, I’ll just wait for another one then and go from there if possible.
edit: Alternatively I can just pretty much leave it alone and wait for v3 to finalize, hopefully solving this… issue.
Got it! Go to Security/Tasks/Submit Files to Comodo for Analysis. You can browse to the exact file (yes, probably c:\windows\system32\dinput.dll - you could always do a search for it first, to find the path to navigate) and add it, along with comments, etc.
Update:
Alright I found the actual culprit (I think), video clips (AVI files). Something with the file type video clips triggers dinput.dll to load into the shell, even if I just right click and check properties.
edit: how odd, if I just load media player classic and tell it to open the file, then dinput.dll is not loaded. So, it would appear if I indirectly handle the files nothing happens.
It was nothing impressive, just a bunch of trials. Anyways, I began to realize that after putting stuff in the external and opening them, that I wasn’t getting dins all the time, so I figured something in particular must’ve been triggering the dll injections. I opened up firefox and looked around some AVIs and MKVs I have stashed in there and noticed touching the AVIs triggered the injection. Long story short, I tested AVIs on my primary HD and on DvDs and noticed that in every case, just touching the AVIs directly caused the injection (okay I’m not sure if merely left clicking to select them causes the injection, haven’t tried that yet, nor do I remember if opening a drop down immediately causes a reaction or if I actually have to do something with the file).
Great, that helps; it’ll at least give others an idea of steps to take when experiencing this sort of issue.
I’ll go ahead and mark the topic as Resolved and close it. If you still have questions/issues and need it reopened, just PM a Moderator (please include a link back here) and we’ll be glad to do so.