Re: RUNDLL32.EXE
From:Date: 07/28/02
- Next message: Stephen Green: "Re: Zone Alarm Settings Help Please!!!"
- Previous message: luis: "Re: Router's Firewall"
- In reply to: Andrew Rossmann: "Re: RUNDLL32.EXE"
- Next in thread: luis: "Re: RUNDLL32.EXE"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Sun, 28 Jul 2002 03:30:52 GMT
Thanks for the reply Andrew... AdAware hasn't been able to detect the
program that is using RUNDLL32.
I found a really cool program that helps you to better manage your running
tasks . Using that program I was able to see that there were multiple
instances of RUNDLL32 running and all of them were accessing my cookies
while also trying to connect to the net... In the meantime my CPU usage was
kept at about 50% by those tasks... Now I am able to kill them in my
sessions but they comeback every time I reboot my computer...
If anybody is interested, the program I am talking about is called "Process
Explorer"and can be found in this page: http://www.sysinternals.com/. I
strongly recommend it... I am sure I am not the only one having this
problem. I just have to keep researching on how to disable whatever is
doing this to my systems.
Regards,
Luis.
"Andrew Rossmann" <andyross@no_junk.worldnet.att.net> wrote in message
news:MPG.17ac6cf52337cd82989d3c@netnews.att.net...
> In article <j1w09.136344$_51.93086@rwcrnsc52.ops.asp.att.net>,
> not@vaila.ble says...
> > I have thousands of entries on my ZAPro log indicating that RUNDLL32.EXE
was
> > trying to connect from my computer... the entries look like this on the
Log
> > file:
> >
> > FWIN,2002/02/09,22:21:18 -5:00 GMT,24.129.2.34:53,66.176.63.8:1184,UDP
> > FWIN,2002/02/09,22:21:24 -5:00 GMT,24.129.2.34:53,66.176.63.8:1187,UDP
> > FWIN,2002/02/09,22:21:44 -5:00 GMT,24.129.2.34:53,66.176.63.8:1190,UDP
> > FWIN,2002/02/09,22:22:53 -5:00 GMT,24.129.2.34:53,66.176.63.8:1204,UDP
> > FWIN,2002/02/09,22:23:44 -5:00 GMT,24.129.2.34:53,66.176.63.8:1206,UDP
> > FWIN,2002/02/09,22:24:15 -5:00 GMT,24.129.2.34:53,66.176.63.8:1218,UDP
> > FWIN,2002/02/09,22:26:24 -5:00 GMT,24.129.2.34:53,66.176.63.8:1235,UDP
> > FWIN,2002/02/09,22:26:24 -5:00 GMT,24.129.2.34:53,66.176.63.8:1237,UDP
> > FWIN,2002/02/09,22:26:24 -5:00 GMT,24.129.2.34:53,66.176.63.8:1238,UDP
> > FWIN,2002/02/09,22:26:28 -5:00 GMT,24.129.2.34:53,66.176.63.8:1249,UDP
> > FWIN,2002/02/09,22:26:35 -5:00 GMT,24.129.2.34:53,66.176.63.8:1253,UDP
> > FWIN,2002/02/09,22:27:14 -5:00 GMT,24.129.2.34:53,66.176.63.8:1288,UDP
> > FWIN,2002/02/09,22:27:33 -5:00 GMT,24.129.2.34:53,66.176.63.8:1310,UDP
> > FWIN,2002/02/09,22:27:35 -5:00 GMT,24.129.2.34:53,66.176.63.8:1312,UDP
> > FWIN,2002/02/09,22:27:37 -5:00 GMT,24.129.2.34:53,66.176.63.8:1315,UDP
> >
> > This started after I noticed that there was a lot of uploading activity
> > going on my computer and I turned the protection up.
> > My Hard drive is constantly making noise as if something is being read
and I
> > get lots of blocked activity... I can see that ICQ has to do with it
but I
> > am also suspecting the possibility of a Trojan. Any help is
appreciated.
>
> RUNDLL32 is just a wrapper for .DLL files to run as programs. The tricky
> part is trying to find out what program is using it.
>
> Download programs like AdAware (www.lavasoft.nu) and similar to search
> for spyware and trojans.
>
> --
> If there is a no_junk in my address, please REMOVE it before replying!
> All junk mail senders will be prosecuted to the fullest extent of the
> law!!
> http://home.att.net/~andyross
- Next message: Stephen Green: "Re: Zone Alarm Settings Help Please!!!"
- Previous message: luis: "Re: Router's Firewall"
- In reply to: Andrew Rossmann: "Re: RUNDLL32.EXE"
- Next in thread: luis: "Re: RUNDLL32.EXE"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]