Computing.Net > Forums > Security and Virus > Rundll32.exe .. Problem .. Help Nee

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Rundll32.exe .. Problem .. Help Nee

Reply to Message Icon

Name: virtualarun
Date: September 18, 2006 at 09:48:25 Pacific
OS: Win XP
CPU/Ram: 768
Comment:

Im having this Rundllw32.exe file running everytime I boot my PC (Task Manager), inspite of deleting it
and its entries in the Prefetch folder. It just gets regenerating. Im not able to connect
to my LAN as the driver for the ethernet card gets corrupted within minutes I install it.
The file that gets affected/corrupted is slnt.sys. Because of which Im not able to connect
to the internet too. This is not picked up by NAV 2005 or NIS 2005 and even by Zone Alarm.
Can anyone of you let me know what should I do to remove this trojan ?

Thanks
Arun



Sponsored Link
Ads by Google

Response Number 1
Name: Tufenuf
Date: September 18, 2006 at 09:53:44 Pacific
Reply:

Arun, Follow the Removal Instructions under the "Solution" tab at the link below.

http://www.trendmicro.com/vinfo/vir...

Tufenuf


0

Response Number 2
Name: virtualarun
Date: September 18, 2006 at 10:03:41 Pacific
Reply:

Tufe, I actually did try removing the registry entry mentioned in that article, but in vain. It just pops out again. It slows my net cnnection and ultimately corrupts the slnt.sys file, ensuring the PC is no more in any LAN. Im sure that some backend application makes this to run. Any idea or suggestions regarding this ?

Thanks
Arun


0

Response Number 3
Name: Tufenuf
Date: September 18, 2006 at 10:09:41 Pacific
Reply:

Arun, Are you first bringing up Task Manager (Ctrl/Alt/Del) and ending the process "Rundllw32.exe" then try removing the registry entry and deleting that file? You may also want to disable System Restore then run a virus scan in SAFE mode. If it comes up clean the enable System Restore again.

Tufenuf


0

Response Number 4
Name: virtualarun
Date: September 18, 2006 at 11:01:44 Pacific
Reply:

Tufenuf, I tried doing what you had told. The file was detected and deleted in safe mode. The internet connection was working fine then.
But once i restarted the PC in normal mode and used the net.. thats it .. in the next ten min .. the exe started running again crashing the driver and disconnecting me from the LAN.
I guess this could be resolved only when the source file that repeatedly creates this exe is deleted. Any suggestions ?

Thanks
Arun


0

Response Number 5
Name: Tufenuf
Date: September 18, 2006 at 11:19:20 Pacific
Reply:

Arun, I'd try running the Free Housecall online virus scan at the link below and let if remove or fix everything it finds.

http://housecall.trendmicro.com/

Tufenuf


0

Related Posts

See More



Response Number 6
Name: Tufenuf
Date: September 18, 2006 at 11:33:11 Pacific
Reply:

Arun, Did you turn off Syastem Restore like the Removal Instructions at the link I posted in Response Number 1 stated to do? Many times these culprits hide in the System Restore files and turning it off flushes them out.

Tufenuf


0

Response Number 7
Name: virtualarun
Date: September 19, 2006 at 08:11:49 Pacific
Reply:

Hey Tufe, Sorry for the delay. Finally they are out of my system !

I thought I could share my experience here so that someone might find it useful.

I manually checked in the registry entries after trying everything in vain and I found that in the CURRENT_USERS domain there was an entry for MSIEXEC.exe file. Actually this was the file that ran once I booted the system after connecting the ethernet card. This exe would give rise to the Rundll32.exe and which was causing the damage.

I came to know the relation by giving the following command in the command prompt that showed me all the EXEs that were initiating or using Rundll32.exe.

tasklist /m /fi "IMAGENAME eq rundll32.exe" >C:\rundll32.txt

Then did a full system scan with NAV and it deleted around six files that were affected. Then rebooted it.

Now its working fine .. Anyway thanks for your help..

[Note: Rundll32.exe will not run when the ethernet card is disabled from the system. Once the card is enabled the exe starts running until the driver for the card gets corrupted, disconnecting you from the network.]


Thanks
Arun


0

Response Number 8
Name: Tufenuf
Date: September 19, 2006 at 09:31:10 Pacific
Reply:

Arun, Good job and Thanks for posting back. It will be usefull to others who run into the same problem.

Tufenuf


0

Response Number 9
Name: virtualarun
Date: September 19, 2006 at 09:57:29 Pacific
Reply:

Tufe, I just wanted to add one more detail regarding this problem.
Though the MSIEXEC is the file that initiates this Rundll32.exe, we should not delete MSIEXEC.exe file because its an essential Windows file that actually is used by programs during their startup and during any installation process. Deleting the file file will result in malfunction of the above mentioned jobs. We just need to delete the linkage between MSIEXEC and Rundll32, which are in no way connected.

Tip To Find whether the running Runddll32.exe is a trojan:
As we have a Rundll32.exe that comes with the Windows package, we should not delete it. Basically Rundll32.exe is designed to run in invisible mode (it wont appear in task manager) so if you see a rundll32 running in the task manager then better check for your system compatibility.

Thnx for the suppport mate.

Thanks
Arun


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Rundll32.exe .. Problem .. Help Nee

rundll32.exe problem www.computing.net/answers/security/rundll32exe-problem/13961.html

rundll32.exe problem www.computing.net/answers/security/rundll32exe-problem/25264.html

help please! (rundll32.exe www.computing.net/answers/security/help-please-rundll32exe-/27825.html