Strage alerts when browsing web-pages

I have installed Comodo a couple of days ago, but I am having some troubles.

After surfing a while (giving both WebWasher and Internet Explorer “Allow”) I suddenly get a new request for Internet access from sevarel programs (among them “trillian” ICQ/MSN agent, WebWasher ad-filter and Avast! web-scanner). I can see why the two latter has to do with Internet Explorer, but not what IE used Trillian for. And why do I get this alarming message in the lower part of the alert:

“C:\Program Files\Internet Explorer\iexplore.exe has loaded C:\WINDOWS\SYSTEM32\shell32.dll into c:\program files\Trillian\trillian.exe using a global hook which could be used by keyloggers to steal private information.” (the message is equal for “wwasher.exe” and “ashWebSv.exe”, same warning about “iexplore.exe” and “shell32.dll”, but shouldn’t they be “safe” applications).

Also got some similar message involving “expolrer.exe” and "iexplore.exe when surfing on some newspaper web-site :frowning:

Ohhh BTW: If I deny these request all h**l is loose. Then I’m no longer able to access any web-pages using any browsers. Even if all applications still have “allow” inside Comodo. Have to restart the system to get things back to working again (ok, actually it works if I stop the “application monitor”, but that is not really a safe and good solution :slight_smile:

This is getting very annoying. Anyone know what is happening (I’m almost ready to go back to ZA now :slight_smile:

Here are some messages from the log if that can say anything that will give a solution:

Date/Time :2006-10-13 00:05:43
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (trillian.exe)
Application: c:\program files\Trillian\trillian.exe
Parent: C:\Program Files\Oppstart\Oppstart.exe
Protocol: TCP Out
Destination: 207.46.106.41:1863
Details: C:\Program Files\Internet Explorer\iexplore.exe has loaded C:\WINDOWS\SYSTEM32\shell32.dll into c:\program files\Trillian\trillian.exe using a global hook which could be used by keyloggers to steal private information.

Date/Time :2006-10-13 00:06:45
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (wwasher.exe)
Application: C:\Program Files\WebWasher\wwasher.exe
Parent: C:\WINDOWS\explorer.exeProtocol: UDP Out
Destination: 129.240.2.3:dns(53)
Details: C:\Program Files\Internet Explorer\iexplore.exe has loaded C:\WINDOWS\SYSTEM32\shell32.dll into C:\Program Files\WebWasher\wwasher.exe using a global hook which could be used by keyloggers to steal private information.

Date/Time :2006-10-13 00:06:46
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (ashWebSv.exe)
Application: C:\Program Files\Alwil avast!\ashWebSv.exe
Parent: C:\WINDOWS\SYSTEM32\services.exe
Protocol: TCP Out
Destination: 195.92.253.137:http(80)
Details: C:\Program Files\Internet Explorer\iexplore.exe has loaded C:\WINDOWS\SYSTEM32\shell32.dll into C:\Program Files\Alwil avast!\ashWebSv.exe using a global hook which could be used by keyloggers to steal private information.

Date/Time :2006-10-13 00:07:01
Severity :High
Reporter :Application Monitor
Description: Application Access Denied (wwasher.exe:129.240.2.3:dns(53))
Application: C:\Program Files\WebWasher\wwasher.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: UDP Out
Destination: 129.240.2.3:dns(53)

Date/Time :2006-10-13 00:07:04
Severity :High
Reporter :Application Monitor
Description: Application Access Denied (ashWebSv.exe:195.92.253.137:http(80))
Application: C:\Program Files\Alwil avast!\ashWebSv.exe
Parent: C:\WINDOWS\SYSTEM32\services.exe
Protocol: TCP Out
Destination: 195.92.253.137:http(80)

Very strange. When working in MS Access I now got the same type of alert about “MSaccess.exe” trying to use “Agent.exe” (my e-mail) program to gain access to the Internet. What is this? Access shouldn’t even need Internet Access, and why should it mess with Agent’s memory :frowning:

All these alerts are on nice clean programs (have run a virus scan). Why are they fired then?