rundll32.exe

G

Guest

Hello All
Have a ibm laptop that is having some cpu resource probs.
The process rundll32.exe is using 100% cpu which is causing the system to
grind to a halt. I have scaned the system for virsus with a current virus
scanner and checked for some of the signs of virius's. Any idea's? It seems
there is a legit app that is using rundll32, something to do with wireless
networking. It doesn't use cpu at 100% all the time. Any idea's?

Regards
Michael
 
S

S.Sengupta

Scan your system with latest adaware/spybot,search and destroy/CWShredder.
Run the all the latest versions in safe mode.
regards,
ssg MS-MVP
 
G

Guest

I have tried this, but nothing was detected.
I have disable the wireless networking and will see what that does.
I'm curious to see why this occurs.
Any other suggestions?

Regards
Michael
 
R

Rock

mickygee said:
Hello All
Have a ibm laptop that is having some cpu resource probs.
The process rundll32.exe is using 100% cpu which is causing the system to
grind to a halt. I have scaned the system for virsus with a current virus
scanner and checked for some of the signs of virius's. Any idea's? It seems
there is a legit app that is using rundll32, something to do with wireless
networking. It doesn't use cpu at 100% all the time. Any idea's?

Regards
Michael

It takes more than just one AV program to keep a system clean of all the
nasties floating around out there. Run these programs to check for
spyware/malware. After installing update them, then boot into safe mode
and run them. You should update and run them weekly.

Cwshredder
http://www.intermute.com/spysubtract/cwshredder_download.html

Ad-aware SE
http://www.lavasoftusa.com

Spybot Search and Destroy
http://www.safer-networking.org

Bazooka Adware and Spyware Scanner
http://download.com.com/3000-2144-10247783.html

Pest Patrol Free Pest Scanner
http://www.pestscan.com/ScanOrTrial.asp

If you’re still having problems after running these then run HijackThis
and post the log to one of the specialty forums, _NOT_ this one.

HijackThis
http://www.majorgeeks.com/download.php?det=3155

Forums to Interpret HijackThis Logs:

http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/

After your system is clean use these programs to help keep it clean:

Spywareblaster
www.javacoolsoftware.com/sbdownload.html

Spywareguard
http://www.javacoolsoftware.com/sgdownload.html

IE-SPYAD
http://www.staff.uiuc.edu/~ehowes/resource.htm

For viruses, start with Trend Micro’s Sysclean. Download it and the
signature file. Turn off system restore, boot into safe mode and run
sysclean. Boot back into normal mode and run a full AV scan with your
normal AV program. Then turn system restore back on.

Trend Micro Sysclean
http://www.trendmicro.com/download/dcs.asp

Trend Micro Signature File
http://www.trendmicro.com/download/pattern.asp

You should also regularly run at least two of these online scans in
addition to your regular up to date AV program:

Online and Downloadable Virus Scanning:

Panda ActiveScan
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Bit Defender Online Virus Scan:
http://www.bitdefender.com/scan/license.php

Symantec Online Virus and Security Scan:
http://security.symantec.com/ssc/home.asp

TrendMicro:
http://housecall.trendmicro.com/housecall/start_corp.asp

McAfee Online Virus Scan:
http://www.mcafee.com/myapps/mfs/default.asp

RAV AntiVirus - Scan Online
http://www.ravantivirus.com/scan/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/

[Note: Stinger looks only for a limited number of specific viruses.
It’s not intended for full strength virus scanning and removal, but it
can help eliminate enough threats to allow you to install and scan with
a full featured AV program.]

If none of this works try some clean boot troubleshooting:
How to Troubleshoot By Using the Msconfig Utility in Windows XP
http://support.microsoft.com/?id=310560

How to perform advanced clean-boot troubleshooting in Windows XP
http://support.microsoft.com/?id=316434
 
R

Ramesh [MVP]

G

Guest

I too have an ibm laptop that was being consumed by rundll32.exe. The
solution for me was to run msconfig and turn off the one startup item that
contained rundll32 in the command. For me this was the power monitor utility
(pwrmonit). Since I did this two weeks ago, I have had no problems. Of
course, I don't have the power monitor, but this is a small price to pay.

Note that this did not involve searching and destroying any spyware or other
malicious software. I did not have to download any third party software of
unknown origin. The responses to similar rundll32 questions on this
discussion group have tended to focus on malicious software. Some responses
by MS-MVPs have included statements that rundll32 is itself spyware and
should be removed when at the same time the MS KnowledgeBase says that
rundll32 is a key Microsoft utility. I am puzzled.

Johnny1045
 
M

Malke

johnny1045 said:
I too have an ibm laptop that was being consumed by rundll32.exe.
The solution for me was to run msconfig and turn off the one startup
item that
contained rundll32 in the command. For me this was the power monitor
utility
(pwrmonit). Since I did this two weeks ago, I have had no problems.
Of course, I don't have the power monitor, but this is a small price
to pay.

Note that this did not involve searching and destroying any spyware or
other
malicious software. I did not have to download any third party
software of
unknown origin. The responses to similar rundll32 questions on this
discussion group have tended to focus on malicious software. Some
responses by MS-MVPs have included statements that rundll32 is itself
spyware and should be removed when at the same time the MS
KnowledgeBase says that
rundll32 is a key Microsoft utility. I am puzzled.

Johnny1045

Rundll32.exe is a legitimate Windows file. However, it is often used by
malware and will not normally be running at startup. You will see it
when something like Control Panel is open, but it will not be a startup
process all by itself. Hence the suggestion to posters with this file
at startup to scan for malware. And here are malware removal
instructions. All tools used should be updated and all scans should be
done in Safe Mode:

1) Scan in Safe Mode with current version (not earlier than 2003)
antivirus using updated definitions.

2) Remove spyware with Spybot Search & Destroy and Ad-aware. These
programs are free, so use them both since they complement each other.
There is a new version of CWShredder from Intermute. I would not
install the other Intermute programs, however. Alternately, there are
CoolWebSearch malware removal steps at SilentRunners.

Be sure to update these programs before running, and it is a good idea
to do virus/spyware scans in Safe Mode. Make sure you are able to see
all hidden files and extensions (View tab in Folder Options).

HijackThis is an excellent tool to discover and disable hijackers, but
it requires expert skill. See below for HijackThis links. A combination
of HijackThis and About:Buster works well in removing the About:Blank
homepage hijacker. Again, this is an expert tool and novices should get
help with it.

3) If you are running Windows ME or XP, you should disable/enable System
Restore because malware will be in the Restore Points. With ME, you
must disable System Restore completely. With XP, you can delete all but
the most recent (presumably clean) System Restore point from the More
Options section of Disk Cleanup (Run>cleanmgr).

4) Make sure you've visited Windows Update and applied all security
patches. Do not install driver updates from Windows Update.

5) Run a firewall.

Links to help with malware:

Software/Methods:
http://www.safer-networking.org - Spybot Search & Destroy
http://www.lavasoftusa.com - Ad-aware
http://www.majorgeeks.com - good download site
http://www.intermute.com/spysubtract/cwshredder_download.html
http://www.silentrunners.org/sr_cwsremoval.html. - SilentRunners

HijackThis:
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/
http://www.spywareinfo.com/forums/

General:
http://forum.aumha.org/ - look under "Security" for various forums
http://rgharper.mvps.org/cleanit.htm
http://mvps.org/winhelp2002/unwanted.htm
http://www.aumha.org/a/parasite.htm - The Parasite Fight
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Malke
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top