Return Styles: Pseud0ch, Terminal, Valhalla, NES, Geocities, Blue Moon. Entire thread

rundll32.exe in task manager process list

Name: Anonymous 2007-11-10 13:52

This is suspicious.  I don't remember "rundll32.exe" running in the process list last week, but it seems to be automatic now.

It's suspicious because, just like svchost, malicious processes can hide behind the names of these otherwise ordinary system processes.

How do I find out which dll is running under this process?  The only results I can find on google point to programs that exist on XP Pro and not XP Home (gee thanks Microshit).

Also, I've already scanned my entire system thoroughly with AVG, AVG Anti-Spyware, Ad-Aware, and Spybot Search & Destroy.  None of them have turned up any threats found.  So after scanning it with that many anti-malware programs, is it safe to assume that this isn't malicious?

In msconfig I do see a couple of rundll32.exe entries that launch nvidia's programs for my graphics card, one of which is the tray (which I don't see in the desktop's tray icon bar).  But I'm pretty sure a week ago, these were still there, and I didn't see "rundll32.exe" in the process list anyway.  Maybe I just didn't notice.

Name: Anonymous 2007-11-10 21:42

i have to manually end process it cause it slows my comp like fuck

Name: Anonymous 2007-11-10 21:46

Rundll32 is used to launch Nvidia utilites; it is not suspicious, you just didn't notice it.

If it's slowing down your computer then you should consider just disabling them on start up with msconfig; as do you really use your nvidia utilites much? I don't.

Name: Anonymous 2007-11-11 5:57

>So after scanning it with that many anti-malware programs, is it safe to assume that this isn't malicious?

No because you likely ran those scanners from the same operating system. A better approach would be to boot a "known to be clean" system, such as a linux live CD and use that to scan your system. That way malware has a harder time masking itself from the scanners.

Knoppicillin comes with several scanners and an online update function but it's German. Maybe you can find something similar.

Name: Anonymous 2007-11-11 7:30

>>4
Rootkits aren't likely to show up in process lists, so that's probably overkill.
Not to mention that scanning for Windows malware from a Linux live CD isn't likely to get results in the first place.

Name: Anonymous 2007-11-11 8:00


Newer Posts
Don't change these.
Name: Email:
Entire Thread Thread List