Specialty Forums
Security and Virus
General Hardware
CPUs/Overclocking
Networking
Digital Photo/Video
Office Software
PC Gaming
Console Gaming
Programming
Database
Web Development
Digital Home

General Forums
Windows XP
Windows Vista
Windows 95/98
Windows Me
Windows NT
Windows 2000
Win Server 2008
Win Server 2003
Windows 3.1
Linux
PDAs
BeOS
Novell Netware
OpenVMS
Solaris
Disk Op. System
Unix
Mac
OS/2

Drivers
Driver Scan
Driver Forum

Software
Automatic Updates

BIOS Updates

My Computing.Net

Solution Center

Free IT eBook

Howtos

Site Search

Message Find

RSS Feeds

Install Guides

Data Recovery

About

Home
Reply to Message Icon Go to Main Page Icon

Rundll32 exe overwrite?

Original Message
Name: sonofagun
Date: July 21, 2005 at 05:52:52 Pacific
Subject: Rundll32 exe overwrite?
OS: WinMe
CPU/Ram: AMD Duron 1200MHz, 128RAM
Comment:
Futher to my posting "Installing wingdings and symbols" I found a problem when trying to follow suggestions to load the character map in Add/Remove Programs - Windows Setup, i.e. an error message "Rundll32 has caused an error in Setupx.dll"
After much searching the web it appears this is a pretty common problem possible caused by a worm or trojan, the MS executable is replaced by a bogus one causing all sorts of problems such as working the processor at 100% and/or screwing up the Control Panel.
Sure enough when I checked my Rundll32.exe I found it was installed on 8 June 05! (my copy of WinMe was in fact installed 2 years ago)
OK then, can somebody tell me if I can simply take a copy of Rundll32 off my WinMe istallation disc an overwite the infected executable?


Report Offensive Message For Removal


Response Number 1
Name: Janset
Date: July 21, 2005 at 20:52:54 Pacific
Subject: Rundll32 exe overwrite?
Reply: (edit)
Hi sonofagun.

The recent date on your rundll32.exe does not necessarily follow that it is corrupted.

It is not unusual to have files updated and replaced by windows when you add amendments from the Windows download center, rundll32.exe is no exception.

I checked it out on my XP which is running like a Swiss watch and found that I have the 2 original versions with differing dates and 2 amended versions of that file.

If you are concerned about the fact that you may have picked up a worm, do a full anti spyware check and a complete AV check whilst you PC is in Safe mode...does a more thorough job.

I do not know how stable you OS it at this moment, if it was otherwise O.K. then I would turn off the Restore option when doing the checks and after they are completed re-engage your Restore function.

Note: When you turn off your Restore function, you loose all your restore points.

The reasoning behind turning off the Restore system is that if you have a gremlin in the works, that too gets saved in you restore folder/files and the next time you resort to that particular restored point, you let the genie out of the bottle again.

Regards

Thinking hurts my head


Report Offensive Follow Up For Removal

Response Number 2
Name: sonofagun
Date: July 22, 2005 at 22:56:31 Pacific
Subject: Rundll32 exe overwrite?
Reply: (edit)
Thanks for the reply Janset.
The evidence for thinking my Rundll32 may be infected came from doing a web search using the error message "Rundll32 has caused an error in SETUPX.DLL" which pops up when trying to open Windows Setup in Add/Remove Programs. Clearly there is something amiss as this section won't open and by all accounts this is, or can be, caused by Rundll32exe being infected/corrupted.
Further, it appears that AVs, Norton in my case, will not detect the infection because the AV sees the exe as the original MS one, nevertheless I did a full-blown updated Norton check in Safe Mode as you suggested but found nothing - indicating either that it isn't infected, or it is and Norton didn't find it??!! If it is not, why do I get the error message and why won't Windows Setup open?
My OS appears to be stable but it is inexplicably slow sometimes and occasionally almost freezes when using some applications.
I've run Ad-Aware SE Pro and Spybot S&D but both come up clean. (strangely just had a 10 second freeze when writing the last sentence!!)
Btw, what is the size of your Rundll32, mine is 24k - seems quite small for an exe.



Report Offensive Follow Up For Removal




Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Rundll32 exe overwrite?

Comments:

 
  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 


Data Recovery Software




which laptop?

XP Installed to G?

exessive internet traffic

ZoneAlarm Question. Blocked Connect

Windows Live Messenger Problem


The information on Computing.Net is the opinions of its users. Such opinions may not be accurate and they are to be used at your own risk. Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE

All content ©1996-2007 Computing.Net, LLC