Welcome, Guest. Please login or register.
December 09, 2009, 08:08:14 PM

Login with username, password and session length

341319 Posts
37724 Topics
85651 Members

Latest Member: colin8605

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Defense+ Help
| | | | |-+  Defense+ Alerts: rundll32.exe is trying to execute different dll, exe files
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Defense+ Alerts: rundll32.exe is trying to execute different dll, exe files  (Read 4680 times)
Jags_FL
Newbie
*
Offline Offline

Posts: 5


« on: May 27, 2009, 11:03:03 PM »

On a fresh installation of Windows 7 RC I'm keep getting these Defense+ alerts that rundll32.exe is trying to execute one or another dll / exe files ONLY when the PC is idle.

Whenever I return to the PC after being away for 15/20 minutes, I see these alerts and each time rundll32.exe is trying execute different files. I've ran Avira (installed), Kaspersky, F-secure (both online) and Malwarebytes' Anti-Malware, many times and they've found nothing so far.

32-bit CIS Ver: 3.9.95478.509 (installed in Vista compatibility mode)

Many thanks in advance, any help is highly appreciated.
Logged
napsterz
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 394


Machinez Rule The World...And I Rule The Machinez


WWW
« Reply #1 on: May 27, 2009, 11:55:36 PM »

The First File Is A Part of Microsoft Visual Studio .NET And No Idea About The Second One. However Both The File's Seem's To Be Suspicious. I Would Suugest You To Submit The File For Analysis.

More Information On How To Submit A Suspicious File
Logged

In Life We All Have An Unspeakable Secret, An Irreversible Regret, An Unreachable Dream And Unforgettable Love...!!!
Jags_FL
Newbie
*
Offline Offline

Posts: 5


« Reply #2 on: May 28, 2009, 12:29:11 AM »

[at] napsterz

Many thanks for the reply.

My main concern is the behavior of rundll32.exe, why it tries to execute any file in first place (is this normal ?) and more importantly why only when the PC is idle ? (the alert never pops up when I'm using the PC)

About submitting the file: As each time the PC is idle for 15/20 minutes rundll32.exe tries to execute different .dll / .exe files so how many should i submit ?

Thanks again.
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1558


The only thing i ask for are eggs.


WWW
« Reply #3 on: May 28, 2009, 12:39:19 AM »

it maybe for the screensaver! just saying not sure
Logged

What you see isn’t what you always get!
napsterz
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 394


Machinez Rule The World...And I Rule The Machinez


WWW
« Reply #4 on: May 28, 2009, 12:50:23 AM »

Hope You Know That Rundll32.exe Is Responsible For Running DLLs and Placing Its Libraries In The Memory.
So Rundll32.exe Executing A DLL File Is Normal. However The Issue Here Is Why Its Happening During/After The Idle Time. So We Can Conclude What's Happening Only By Recognizing The Properties Of The DLL File Executed By Rundll32.exe. Either Its A Kind Of Malicious File Try To Load Or A Genuine Windows Process Trying To Load.
Logged

In Life We All Have An Unspeakable Secret, An Irreversible Regret, An Unreachable Dream And Unforgettable Love...!!!
SiberLynx
Comodo's Hero
*****
Offline Offline

Posts: 662



« Reply #5 on: May 28, 2009, 12:59:41 AM »

Hi Jags_FL,

Definitely if you are not sure - you have to check with Comodo as napsterz suggested

Microsoft.stdformat.dll is a part of Microsoft .Net Framework (see assembly directory)
C:\WINDOWS\assembly\GAS\Microsoft.StdFormat\
This is highly protected directory so you cannot access and get files from there except special “command line way”  Wink

QtCore4.dll is part of C++ application development framework

Basically it belongs to Trolltech but you may find names like Nokia Corporation and/or its subsidiary(-ies) for example under Properties.

This is actually a library for building graphical user interfaces.
Therefore  you can have the file in question supplied by many companies as a part of their Software
There are GNU and comerciall versions You can read here
http://doc.trolltech.com/4.1/index.html

I have 5 instances if the said DLL. Belonging to LightScribe; LMMS audio sequencer; Stellarium (astronomy software), etc. Keep in mind that you may have different versions of QtCore4.dll belonging to each Software

My regards
Logged

admin; XP Pro, SP3 (32); CIS 3.13.121240.574 (firewall only; Proactive with Defense+); Vengine 2.7.0.33 ; AVG free; Mamutu Behavioural Blocker
Jags_FL
Newbie
*
Offline Offline

Posts: 5


« Reply #6 on: May 28, 2009, 01:10:38 AM »

napsterz, SiberLynx thanks guys...

The screensaver is set at 40 min and turn display off is at 45 minutes but this rundll32.exe alerts I get anywhere between around 15/20 min.

Here are some of the file names rundll32.exe tries to execute:
Microsoft.stdformat.dll, QtCore4.dll, QtNetwork4.dll, jpeg62.dll, sqlceca30.dll, CamMenuPlayer.exe, CamRecorder.exe (TechSmith Camtasia files) and many others I wasn't able to get name of.

Sometimes when I return to the PC and tries to take a screenshot (or try to write down the name of the file) Defense+ alert just disappears.

I'm going to submit the files (that I know of, mentioned above) to avlab [at] Comodo through the email.

Thanks a lott.
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2730


Follow the White Rabbit...


« Reply #7 on: June 04, 2009, 07:34:05 PM »

I have noticed that, every morning, my D+ logs are full of entries related to rundll32.exe. It seems to happen particularly if there has been some system change or new software installation. It is curious, I wonder if it's a Windows 7 thing...

I know this is not a malware/spyware/virus/add your own definition here... as it also occurs after a clean installation of Win 7 (from Microsoft not a torrent) and CIS. It looks like rundll32.exe is just catching up with 'changes' when system activity is low.

Here is a 'sample' of my log from last night.





Logged

"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."

Forum Policy
Quill
Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2730


Follow the White Rabbit...


« Reply #8 on: June 21, 2009, 08:02:15 PM »

I want to revisit this as it's becoming a bit of a pain.

I get this every night, as soon as the system has been idle for a period of time. There are no tasks scheduled, no scans, defrags etc. This problem only happens on the Windows 7 PC. I have never seen anything like this on the XP PC. On occasion I wake to find CIS has crashed.

This problem is not a malware issue (maybe move this topic...), as it happens on a clean install of 7100, which came from MS.

So the question is, what the heck is rundll32 doing with all these processes/applications, and why are they appearing in the D+ log?
 
Attached another copy from last night.

sample:
Code:

Sun Jun 21 2:04:15 AM
C:\Windows\System32\rundll32.exe
Create Process, Execute Image
C:\Program Files\ATI\CIM\Bin\ATISetup.exe


Sun Jun 21 2:06:16 AM
C:\Windows\System32\rundll32.exe
Create Process, Execute Image
C:\Program Files\ATI\CIM\Bin\Setup.exe


Sun Jun 21 2:08:16 AM
C:\Windows\System32\rundll32.exe
Create Process, Execute Image
C:\Program Files\Microsoft Silverlight\2.0.40115.0\zh-Hant\system.resources.dll


Sun Jun 21 2:10:15 AM
C:\Windows\System32\rundll32.exe
Create Process, Execute Image
C:\Program Files\Microsoft Silverlight\2.0.40115.0\de\mscorrc.dll
 

« Last Edit: June 23, 2009, 06:16:04 AM by Toggie » Logged

"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."

Forum Policy
wj32
Comodo Loves me
****
Offline Offline

Posts: 122



WWW
« Reply #9 on: June 23, 2009, 05:54:54 AM »

Unless ATISetup.exe and Setup.exe export any functions, rundll32 can't do anything with them. Similarly, I have Silverlight installed and I don't even have the 2.0.40115.0 folder in Microsoft Silverlight. System.Resources.dll is a .NET assembly anyway and doesn't export any native functions, so it can't be run by rundll32 either.

There may be a malware infection...

Code:

Sun Jun 21 2:04:15 AM
C:\Windows\System32\rundll32.exe
Create Process, Execute Image
C:\Program Files\ATI\CIM\Bin\ATISetup.exe


Sun Jun 21 2:06:16 AM
C:\Windows\System32\rundll32.exe
Create Process, Execute Image
C:\Program Files\ATI\CIM\Bin\Setup.exe


Sun Jun 21 2:08:16 AM
C:\Windows\System32\rundll32.exe
Create Process, Execute Image
C:\Program Files\Microsoft Silverlight\2.0.40115.0\zh-Hant\system.resources.dll


Sun Jun 21 2:10:15 AM
C:\Windows\System32\rundll32.exe
Create Process, Execute Image
C:\Program Files\Microsoft Silverlight\2.0.40115.0\de\mscorrc.dll
 


[/quote]
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2730


Follow the White Rabbit...


« Reply #10 on: June 23, 2009, 06:14:45 AM »

Thanks!

Quote
There may be a malware infection...

There is not. Please read my post and please see the attached.
Logged

"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."

Forum Policy
Logos
Guest
« Reply #11 on: August 04, 2009, 12:45:50 PM »

yeah just got this a few minutes ago for the first time, in Win7/7100 as well. Haven't got a clue what this is about. I had an alert for most of those events in the pic and blocked (without remembering), just in case, although I don't think either that any malware is involved.

« Last Edit: August 04, 2009, 12:48:28 PM by Logos » Logged
Ieke
Newbie
*
Offline Offline

Posts: 3


« Reply #12 on: September 13, 2009, 09:12:12 AM »

I'm having the same problem on my laptop and desktop. I'm running Windows 7 64 RTM on both. The thing I can't figure out is it doesn't happen all the time. If I reboot the problem goes away, it normally happens after the PC has been on for awhile and NOT in use. Why is it trying to run freaky things, its trying to open crysis.exe, ati apps, everything, and why does it only do it after the PC has been idle? Finally why does a reboot termporarily fix it?

Thank you
Logged
Scam
Newbie
*
Offline Offline

Posts: 7


« Reply #13 on: September 21, 2009, 05:14:24 AM »

The same issue on Windows 7 (32bit). Fresh installation no viruses/trojans.  Seems that it is Comodo Defense+ issue. As it officially does not support Windows 7 we just should wait I think. Smiley
Logged
troubada
Newbie
*
Offline Offline

Posts: 6


« Reply #14 on: October 01, 2009, 07:40:33 AM »

I am having this issue as well with Windows 7 32-bit Final/updated. It does happen when I'm away from the PC about 15 minutes, and my screensaver had come on the times that it happened. Mine says something about rundll32.exe trying to execute http_...

When I just checked my Defense+ events in COMODO, it became clear that in my case this is caused by VLC Media Player and also by Microsoft Games for Windows LIVE:

Quote
C:\Windows\System32\rundll32.exe   Create Process, Execute Image   C:\Program Files\VideoLAN\VLC\http\requests\browse.xml

Quote
C:\Windows\System32\rundll32.exe   Create Process, Execute Image   C:\Program Files\Microsoft Games for Windows - LIVE\Client\Help\Http_error_es-es.htm

Logged
Tags: Defense+  rundll32.exe  dll  exe 
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.045 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com