The Digital Surgery (computer questions/problems here)

Technology, computers, internet, websites, mobiles, cameras, audio and video.
SPONSORS: Hua Hin Web Design
Post Reply
User avatar
buksida
Moderator
Moderator
Posts: 23982
Joined: Tue Dec 31, 2002 12:25 pm
Location: south of sanity

Post by buksida »

rundll32.exe is a standard Windows file, perfectly safe.
Who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed? - Hunter S Thompson
Guess
Deceased
Deceased
Posts: 3470
Joined: Fri Jul 22, 2005 3:01 pm
Location: BangSaphan. Laurasia. Sub thumb

Post by Guess »

Roel wrote: Anyone any ideas?

Image
Yes there are viruses that disguise themselves as rundll sometimes misspelling it. Try these below. There are often programs available for free that check your copies of rundll32.exe and remove the problem. uUst stopping the task that you suspect is dodgy will do noting. These type of viruses are elf duplicating.

Try
http://recherche21.wordpress.com/2008/0 ... ndll32exe/
and
http://www.techsupportforum.com/securit ... virus.html

for information

and http://www.f-secure.com for a possible solution. Do a google search for rundll32.exe virus and youi get a list of forums that have discussions on the problems that you can get with rundll.
[color=blue][size=134]Care in the community success story.[/size][/color]
User avatar
buksida
Moderator
Moderator
Posts: 23982
Joined: Tue Dec 31, 2002 12:25 pm
Location: south of sanity

Post by buksida »

Most Windows system files can be used and disguised by viruses, if it has been scanned with three different programs and come up clean then I would imagine it is - if you're really paranoid then try this: http://housecall.trendmicro.com/

Most if not all XP machines have rundll32.exe running safely in the processes list but yes, it is good to be aware of the nasties that lurk out there.
Who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed? - Hunter S Thompson
User avatar
Roel
Guru
Guru
Posts: 975
Joined: Tue Jun 26, 2007 10:21 am
Location: Phuket

Post by Roel »

Thank you very much for the insight gentlemen Guess and Buksida. I will investigate and report back. By the way I am running Vista, not XP, but I assume that should not make any difference.
We are all living in 'the good old days' of the future.
User avatar
Roel
Guru
Guru
Posts: 975
Joined: Tue Jun 26, 2007 10:21 am
Location: Phuket

Post by Roel »

Time for a first evaluation.

Khun Guess, your first link gives a solution offered by an expert. Detailed but rather complicated instructions (for me, surely not for you gentlemen). But then I have to mess around with my rundll32.exe file. So I put that option in the fridge for now. At the end there are responses from other nerds what makes it for a layman like myself not much clearer rather quite the opposite. Especially when the nerds disagree with each other. Interesting observation however from this link is the following:

Image

And here is a shot of my rundll32.exe icon

Image

Conclusion: If this is not an attempt by nerds to wind up ordinary people then it does not look good.

The second link is too much of professional computer abracadabra for me. Might also be outdated. It is from 2003.

F-secure can only be downloaded via IE. Not an insurmountable problem but I have to register and will receive my download link per email. Therefore I skipped that one and went to Trend Micro as suggested by Khun Buksida. After a pretty long time of downloading and unzipping it told me it cannot install unless I un-install my AVG Paid first. Something I do not want to do.

So I browsed a little bit more but I can really not find a suitable solution. (That is why I put it on HHAD in the first place hoping there would be people with personal expertise regarding this specific problem).

Forums discussing the rundll32.exe virus subject or either too specialistic for me or too simple eg. just offering yet another link to yet another anti-virus program. I ran into neuber.com and its free Registry Scan is supposed to get rid of all known rundll32.exe problems. I downloaded that one but when I try to run it it says:

Image

Any further suggestions are most welcome!
We are all living in 'the good old days' of the future.
User avatar
buksida
Moderator
Moderator
Posts: 23982
Joined: Tue Dec 31, 2002 12:25 pm
Location: south of sanity

Post by buksida »

Is the computer behaving as if it has got a virus, any of the symptoms below??

1) Erratic/slow network/internet activity (network connection icon permanently illuminated)
2) Strange popup windows
3) Slow or erratic operation (opening programs etc)
4) Critical processes not functioning (such as regedit or msconfig)
5) Virus alerts from your scanners

If not then I'd say its a case of paranoia as the file itself is perfectly safe under normal circumstances.

Don't download or run anything that you're not familiar with - half the time these 'solutions', 'spyware removers' and 'free virus tools' are the virus!
Who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed? - Hunter S Thompson
User avatar
Roel
Guru
Guru
Posts: 975
Joined: Tue Jun 26, 2007 10:21 am
Location: Phuket

Post by Roel »

Well, actually no problems at all. I am more worried that my computer is a zombie, used by bad people to spam or worse store illegal stuff with remote control.

Anyway, the rundll32.exe icon looks like a sheet of paper with dog-ear on other computers so I assume that was a wind-up.

I will leave it for now and if something suspicious comes up I will give notice. Thanks for your help and especially your patience both Khun Guess and Khun Buksida.
We are all living in 'the good old days' of the future.
Norseman
Rock Star
Rock Star
Posts: 4665
Joined: Tue May 10, 2005 12:13 pm
Location: Hua Hin

Post by Norseman »

You can of course rename the file to, for instance, rundll32x.exe and see what will happen.
If everything works ok then don't do anything else.
Just remember that the original rundll32.exe file in the c:/windows/system32/ rundll32.exe, which is a 32,5 KB sized file, should not be touched.
Otherwise you will not be able to upload / start windows.
Be very careful with this file.
It is a driver file for a lot of other programs as well, snd can be found in other directories. (Service pack and upgrading directories).
I intend to live forever - so far so good.
User avatar
richard
Deceased
Deceased
Posts: 8780
Joined: Tue Feb 18, 2003 1:59 pm
Location: Wherever I am today

Post by richard »

How can I paste from a work doc into a thread on the forum? It has pics embedded but they do not paste
RICHARD OF LOXLEY

It’s none of my business what people say and think of me. I am what I am and do what I do. I expect nothing and accept everything. It makes life so much easier.
User avatar
buksida
Moderator
Moderator
Posts: 23982
Joined: Tue Dec 31, 2002 12:25 pm
Location: south of sanity

Post by buksida »

richard wrote:How can I paste from a work doc into a thread on the forum? It has pics embedded but they do not paste
You can't, you need to upload the pictures separately or link to them from an external image hosting site.
Who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed? - Hunter S Thompson
BaaBaa.
Addict
Addict
Posts: 8620
Joined: Wed Aug 23, 2006 5:41 pm
Location: leuk lap

Post by BaaBaa. »

Did you ever get round to looking at embedding videos Buks?
User avatar
buksida
Moderator
Moderator
Posts: 23982
Joined: Tue Dec 31, 2002 12:25 pm
Location: south of sanity

Post by buksida »

Try this, I believe the changes have been made to the backend:

http://www.freewebspace.net/forums/show ... ?t=2194119
Who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed? - Hunter S Thompson
BaaBaa.
Addict
Addict
Posts: 8620
Joined: Wed Aug 23, 2006 5:41 pm
Location: leuk lap

Post by BaaBaa. »

buksida wrote:Try this, I believe the changes have been made to the backend:

http://www.freewebspace.net/forums/show ... ?t=2194119
Google translate doesn't seem to work on that site Buks! :P
User avatar
Spitfire
Addict
Addict
Posts: 5248
Joined: Thu Apr 10, 2008 1:17 pm
Location: Thailand

Post by Spitfire »

Does anyone know much about "crapware", ie how to find out how much might be on your computer, recommendations on how to get rid of it, and what effects other than slowness it might have. I'm under the impression that it's stuff like "Yahoo toolbar" etc that sneaks it's way onto you computer when you install other software and the like. Is this true or does it cover a lot more stuff? Sometimes my set-up seems slow and am tryiny to find out what it is, not a virus so thought this could be the culprit.

:cheers: for any suggestions.
PET
Legend
Legend
Posts: 2219
Joined: Mon Jun 25, 2007 4:24 pm
Location: Hua Hin

Clean - up computer start up etc

Post by PET »

I took my computer to Khun Martin at the DIGITAL SURGERY ( as advertised here ) at their North Hua HIn branch and in 24 hours they cleaned the whole thing up.

I did not have any virus problems but the computer now runs at least 50% faster and I am very pleased. It was also at a very reasonable cost.

I strongly suggest you go there as it will solve many problems for you.
Post Reply