Computing.Net > Forums > Security and Virus > Strange connection of rundll32.exe

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Strange connection of rundll32.exe

Reply to Message Icon

Name: shahramsh
Date: February 4, 2006 at 13:42:59 Pacific
OS: XP pro Sp2
CPU/Ram: p4 3.2 gh
Comment:

Today I started my computer, it connected to internet,
and without opening any program my rundll32.exe started to request internet access,

The strange thing about it is the remote addresses that it requested to access

here is the pic from my firewall:
http://img139.imageshack.us/img139/5030/p017kk.jpg

and the IP 64.233.183.147, refers too google
meaning it wants to connect to google, while I have nothing from google installed, not even their google bar.

the other IPies are for two other companies:
68.142.194.21
212.58.224.116

http://img145.imageshack.us/img145/6512/p035at.jpg


and these are the processes under which rundll is started:
http://img490.imageshack.us/img490/8627/p027xe.jpg

I have Norton System Works 2006, Update to the latest definition, and non of my antiadware/spyware programs shows anything suspicious,


What could this be???????????????



Sponsored Link
Ads by Google

Response Number 1
Name: Johnw
Date: February 5, 2006 at 04:10:07 Pacific
Reply:

Here are a few tools that dig deeper than most.
My SpyCatcher thoughts.
What it does, after the search, it offers choices of what to do with files found, which can be a bit daunting.
All these choices, like > Ask, can ( after research or your own knowledge of what you have installed ) be changed. In the Status window, the Protection ( in the middle of the page ) section, click on the files found.
It also finds uninstall exe's, which I change to > Allow.
SpyCatcher Express

http://www.tenebril.com/consumer/spyware/spycatcher-express.php

* Allows novice PC users to remove aggressive spyware
* Stops next-generation, mutating spyware
* Blocks reinstallation of aggressive spyware
* Removes spyware safely and automatically
* Database receives 6 million spyware submissions per day
=============================================
RegAuditor

http://www.nsauditor.com/freeware/index.html


http://www.sixfiles.com/dbase/fr-network-internet/anti-spam-virus-spy-tools

Registry Auditor gives you a quick look at the Adware, malware and spyware installed on your computer including parasites and trojans. Registry Auditor tells you by colored icons ( green icon - safe, yellow icon - unknown, red icon - harmful ) whether specific Objects are known to be safe or harmful, also the program searches the registry for entries including filenames that aren't present on and allows you to delete unwanted registry entries. The tool is designed with a user-friendly interface and is easy to use. Windows NT/2K/XP/2003
===================================

RemoveIT Pro
http://www.incodesolutions.com/
http://www.incodesolutions.com/removeit.htm
Clean your computer from Viruses & Worms, Adwares & Spywares. Full log file about active processes, startup files, worms & viruses. Database updation every day. Remove many viruses that other popular antivirus software cannot discover.
Note: Free for non commercial use.


0

Response Number 2
Name: shahramsh
Date: February 6, 2006 at 04:06:06 Pacific
Reply:

thanx for ur program introduction,

I figured it through other ways,

Rundll32.exe was running msfeeds.dll from IE7 to get the RSS feeds and so was the connection requests.


0

Response Number 3
Name: Johnw
Date: February 6, 2006 at 04:15:06 Pacific
Reply:

Well done shahramsh


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Strange connection of rundll32.exe

rundll32.exe virus or bug www.computing.net/answers/security/rundll32exe-virus-or-bug/9156.html

rundll32.exe missing, no windows cd www.computing.net/answers/security/rundll32exe-missing-no-windows-cd/25680.html

Rundll32.exe .. Problem .. Help Nee www.computing.net/answers/security/rundll32exe-problem-help-nee/19480.html