Multiple rundll32.exe appearing under processes
Win2K3 Server Std w/SP2 + critical updates from Microsoft as of Feb 15/2009
Server is a member of the local domain and is used only as a file/print server.
About a week now, I've noticed that there are alot of rundll32.exe appearing under the processes tab in task manager. As much as 100 of them. I don't know where they are coming from and was wondering if anyone would know.
I've scanned and rescanned for viruses, worms, trojans and malware but nothing shows up. We have 9 other servers, mixed Win2K3 std and ent and none of them have this issue as well as the 30 pc's.
Having all those rundll32.exe does not seem to affect the performance of the server itself. Still have access to files and printers. and from the server itself, I can browse the internet, connect to other servers and so forth.
Under processes, rundll32.exe displays 00 under CPU and 1688k under Memory Usage.
I ran "tasklist /m /fi "IMAGENAME eq rundll32.exe" >C:\rundll32.txt" and this is what I get for all of them. Only the PID # is different for each one.
Image Name PID Modules
========= ==== ====================================================================================
rundll32.exe 5060 ntdll.dll, kernel32.dll, msvcrt.dll, GDI32.dll, USER32.dll, ADVAPI32.dll, RPCRT4.dll, Secur32.dll, imagehlp.dll, IMM32.DLL
Any help is appreciated.
Thanks.
Stan.
Re: Multiple rundll32.exe appearing under processes
True.
I was anable to see the past context.
That does make a difference. It is just common for some people to get over
excited about seeing rundll32.exe and svchost.exe entries when it is normal
to see them (in normal amounts) so I thought that might be what this was.
Ok.
Very good.
Re: Multiple rundll32.exe appearing under processes
Find out if they only return like that with one particular user profile. I
have had problems like that and solved it be backing up required parts of
the profile (Desktop, My Doc, Favorites, etc). Then delete the
profile,...run the AV to clean up,...log the user in to recreate the
profile,...copy the saved data back to the profile. Then reboot and see if
it comes back again.
Re: Multiple rundll32.exe appearing under processes
I had the same problem. I downloaded and executed the KK tool from http://support.kaspersky.com/faq?cha...&qid=208279973 and the problem was gone. The tool detected the KIDO virus. Hope it helps all.
ps1: my free Avira Antivirus was unable to detect and remove the virus.
ps2: I have Windows Vista Business SP2 installed.
Re: Multiple rundll32.exe appearing under processes
thanks for your support guys.
bit defender is also good at rooting out conficker as well.