BetaONE will rise again!


Reply
  #1  
Old 2nd Oct 05, 08:16 PM
rikytik's Avatar
rikytik rikytik is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: Canada
Posts: 1,051
rikytik is an unknown quantity at this point
rundll.exe a worm in XP?
My firewall (ZAP) identified runndll.exe as a virus. Doing a Google search I learned that rundll.exe is not part of Win XP, as it was with win 98 and Me.

This dll was running on my isntallation and I killed it. So far nothing noticed. I also note that rundll32 is running on another pc, but not on my laptop--all running WinXP.

Anybody run into this? Any ideas? MS's web site explains the use of this dll, but doesn't talk about misuse by spyware, at least that I noted in a quick look.

The following is from one of the Google sites I found.

Process File:

rundll.exe

Process Name:

Microsoft RunDLL




Description:

rundll.exe is a Windows System process belonging to the Windows 95, 98 and ME range of Microsoft Windows products. This is an important system process and should not be terminated.

NOTE: rundll.exe can also be the LOXOSCAM and Backdoor.SchoolBus.B trojans depending on Operating System and file path; this is always a virus on Windows XP and 2000 operating systems however. Both are a backdoor Trojan that allow hackers to gain access to the computer. These program is a registered security risk and should be removed immediately. If found on your system make sure that you have downloaded the latest update for your antivirus application. Please consult the file path to distinguish between this and the system process.
Reply With Quote
  #2  
Old 3rd Oct 05, 02:23 AM
Dudelive Dudelive is offline
Senior Member
 
Join Date: Oct 2001
Location: USA
Posts: 603
Dudelive is an unknown quantity at this point
Just be sure that you are looking at the rundll and not rundll32.

http://support.microsoft.com/kb/q164787/

This will help explain it.

Thanks
Dudelive
__________________
Be careful what you ask for, because you might just get it.
Reply With Quote
  #3  
Old 3rd Oct 05, 09:17 AM
rikytik's Avatar
rikytik rikytik is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: Canada
Posts: 1,051
rikytik is an unknown quantity at this point
Yep, Dudelive, I saw that. What I am scratching my head about is that ZAP asked permission to stop or allow rundll.exe from running and identified it as passibly a dangerous virus. I blocked it and then did a file search on the pc in question. the program was not found.

Then on another machine, I went thorugh the same, porcedure, uninstalling NAV, then installing ZAP. No call for rundll, but I noted that rundll32 was one of the processes running on this second machine.

The first machine has an older installation and has seen a lot of software installed/uninstalled over the past year or more, although it gets a registry cleaner, spyware checker, etc., run on it many times a month.

NOD32 hasn't identified any of this stuff (newly installed as a trial) So, I'm still wondering what program is trying to start rundll and why.
Reply With Quote
  #4  
Old 3rd Oct 05, 11:45 PM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
For winxp rundll32.dll is safe. For instance you might see it opening device manager.

Anything else is not safe.

So if anything else delete it. Back it up just in case I suppose.
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #5  
Old 6th Oct 05, 12:40 AM
rikytik's Avatar
rikytik rikytik is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: Canada
Posts: 1,051
rikytik is an unknown quantity at this point
btw, I dumped ZAP and NOD and am trying BitDefender 9 and the whole issue seems to have disappeared into the woodwork. Really strange how ZAP kept asking to run rundll.exe as a program monitoring mouse and keyboard activity. Still not sure why this was happening, nor why other firewalls didn't pick up the same activity.

Could be pc operators are from Mars and PC's are from Venus.
Reply With Quote
  #6  
Old 6th Oct 05, 03:26 AM
Dudelive Dudelive is offline
Senior Member
 
Join Date: Oct 2001
Location: USA
Posts: 603
Dudelive is an unknown quantity at this point
I am running ZAP and kaspersky....and there is not a rundll of any kind asking or running on mine through ZAP.

Thanks
Dudelive
__________________
Be careful what you ask for, because you might just get it.
Reply With Quote
  #7  
Old 8th Oct 05, 12:53 AM
rikytik's Avatar
rikytik rikytik is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: Canada
Posts: 1,051
rikytik is an unknown quantity at this point
I am still scratching my head. This rundll thing only ocurred on my somewhat mature pc that has been on line a lot with all kinds of bad sites, had many trial programs installed and uninstalled. So there could be a residue of many sins on the hd.

I recently tried out a program called White Canyon Secure Clean. Even tho I erase cookies wsith the traditional means, it showed up temp internet files that contained credit card numbers, id's, passwords and stuff that shocked me. Got me into looking at the *.dat files which you can clean, but not the one in the Windows directory (forget the exact name of it right now) But it'll make you paranoic if you keep digging.

My Bitdefender 9 machine is still rolling along fine and I've put Norton 2005 back in this machine.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
XP architectures: grown not given Alpine BetaONE News 0 12th Sep 05 04:03 AM
Microsoft Windows XP x64 RTM NewsBot NeoWin News 0 31st Mar 05 04:30 PM
Microsoft To Force SP2 Update On All XP And XP SP1 NewsBot ieXbeta News 0 22nd Feb 05 05:00 PM
Windows XP "Reduced Media Edition" Revealed NewsBot NeoWin News 0 7th Feb 05 01:00 AM
Windows XP "Reduced Media Edition" Revealed NewsBot NeoWin News 0 7th Feb 05 12:00 AM


All times are GMT +1. The time now is 10:24 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.