Computing.Net > Forums > Security and Virus > Rundll32 is 100%... Is it a virus?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Rundll32 is 100%... Is it a virus?

Reply to Message Icon

Name: mant
Date: June 17, 2007 at 19:22:39 Pacific
OS: Windows XP Pro
CPU/Ram: Pentium M/512
Product: IBM Thinkpad
Comment:

I have noticed lately that my computer gets slow and I can hear it running a program, yet I know I didn't open anything. When I check the task panel it says my comp. is at 100% and it is always the rundll32 which I have no idea what this is. I try and closing all processes, the rundll32, lowering its priority, and nothing works to slow it. Can anyone give me advice on what maybe wrong and how to fix it? I did run a complete scan on my norton and found one worm that said was low priority called an egather and couldn't remove it. I also did a full scan with Adaware as well.

Thank you for your help.



Sponsored Link
Ads by Google

Response Number 1
Name: jboy
Date: June 17, 2007 at 23:42:06 Pacific
Reply:

Rundll32.exe is (or can be) a legitimate Windows process, depending on its location - however, even the bona fide version can be used to launch undesirable processes.

"... found one worm"

Are you certain of that? The presence of a worm indicates a compromised system - if that is indeed an accurate statement, since eGather could be a legitimate app from IBM/Lenovo and might only represent a security exploit - which can be addressed by an update from IBM

Censorship is the tool of those who have the need to hide actualities from themselves and others. Their fear is only their inability to face what is real.


0

Response Number 2
Name: mant
Date: June 18, 2007 at 12:30:18 Pacific
Reply:

Thanks for the information about eGather. You are probably correct because when I go to the Norton site and type this in, it directs me to the IBM site for a download. Unfortunately the page doesn't exist but I am assuming it isn't a high priority.

Anyway, do you know why this Rundll32 is always at 100% and slowing me down? I don't have a lot of stuff on my laptop so if I needed to reload Windows I could but I prefer not too.

Thanks in advance for the help!


0

Response Number 3
Name: jboy
Date: June 18, 2007 at 15:27:52 Pacific
Reply:

It seems likely, given there isn't much else applicable under that name - - although I'm unsure why you'd referred to it as a 'worm', a rather specific term (and hardly a 'low priority')

Anyways... investigate(!) Use msconfig to examine your startups, or Hijackthis, which should give you a pretty clear picture - - just look for instances of rundll32.exe - it should be followed by parameters which will identify what's actually being launched

It follows this format, and you might try the command prompt technique there to determine the culprit

Censorship is the tool of those who have the need to hide actualities from themselves and others. Their fear is only their inability to face what is real.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Something slowing my pc..... Can't Boot Windows, I get...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Rundll32 is 100%... Is it a virus?

is it a virus? www.computing.net/answers/security/is-it-a-virus/3211.html

hd failure...is it a virus????? www.computing.net/answers/security/hd-failureis-it-a-virus/4350.html

start-up page virus....is it a virus?? www.computing.net/answers/security/startup-page-virusis-it-a-virus/138.html