happening on a fresh install windows 7 64bit retail fully patched… installed some new software… when i came back to the machine after several hours had several comodo dialogs waiting for me…
10/29/2009 1:18:52 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.Resources\sv.lproj\SoftwareUpdateLocalized.dll
10/29/2009 1:20:53 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Electronic Arts\Crytek\Crysis\Tools\VistaEssentials.dll
10/29/2009 1:22:54 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Bonjour\ExplorerPlugin.Resources\fi.lproj\ExplorerPluginLocalized.dll
10/29/2009 1:24:56 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Bonjour\ExplorerPlugin.Resources\es.lproj\ExplorerPluginLocalized.dll
10/29/2009 1:26:57 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Steam\bin\SteamService.exe
10/29/2009 1:28:58 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.Resources\de.lproj\SoftwareUpdateLocalized.dll
10/29/2009 1:30:58 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.Resources\it.lproj\SoftwareUpdateLocalized.dll
10/29/2009 1:33:01 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl64.sys
10/29/2009 1:35:01 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\GameSpy\Comrade\156\fr-FR\ComradeLib.resources.dll
10/29/2009 1:37:02 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.Resources\ko.lproj\SoftwareUpdateLocalized.dll
10/29/2009 1:39:03 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Bonjour\ExplorerPlugin.Resources\nl.lproj\ExplorerPluginLocalized.dll
10/29/2009 1:41:04 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Bonjour\ExplorerPlugin.Resources\zh_TW.lproj\ExplorerPluginLocalized.dll
10/29/2009 1:43:05 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AOSUtils.dll
10/29/2009 1:45:07 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Bonjour\ExplorerPlugin.Resources\nb.lproj\ExplorerPluginLocalized.dll
10/29/2009 1:47:08 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Bonjour\ExplorerPlugin.Resources\da.lproj\ExplorerPluginLocalized.dll
10/29/2009 1:49:08 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Bonjour\PrinterWizard.Resources\da.lproj\PrinterWizardLocalized.dll
10/29/2009 1:51:09 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.Resources\nb.lproj\SoftwareUpdateLocalized.dll
10/29/2009 1:53:10 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Bonjour\ExplorerPlugin.Resources\ExplorerPluginResources.dll
10/29/2009 1:55:11 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl64.sys
10/29/2009 1:57:18 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\AirPort\APAgent.exe
10/29/2009 1:59:19 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdateFiles.Resources\de.lproj\SoftwareUpdateFilesLocalized.dll
10/29/2009 2:01:19 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.Resources\ru.lproj\SoftwareUpdateLocalized.dll
10/29/2009 2:03:20 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdateFiles.Resources\zh_CN.lproj\SoftwareUpdateFilesLocalized.dll
10/29/2009 2:05:21 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Steam\Steam.exe
10/29/2009 2:07:23 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdateFiles.Resources\ja.lproj\SoftwareUpdateFilesLocalized.dll
10/29/2009 2:09:23 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdateFiles.Resources\sv.lproj\SoftwareUpdateFilesLocalized.dll
10/29/2009 2:11:25 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Bonjour\ExplorerPlugin.Resources\sv.lproj\ExplorerPluginLocalized.dll
10/29/2009 2:13:25 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Bonjour\ExplorerPlugin.Resources\de.lproj\ExplorerPluginLocalized.dll
10/29/2009 2:15:26 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Apple Software Update\SoftwareUpdateFiles.Resources\fr.lproj\SoftwareUpdateFilesLocalized.dll
10/29/2009 2:17:27 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Bonjour\ExplorerPlugin.Resources\en.lproj\ExplorerPluginLocalized.dll
10/29/2009 2:19:28 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Bonjour\ExplorerPlugin.Resources\fr.lproj\ExplorerPluginLocalized.dll
10/29/2009 2:21:30 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files\Bonjour\ExplorerPlugin.Resources\zh_CN.lproj\ExplorerPluginLocalized.dll
10/29/2009 2:23:30 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Electronic Arts\Crytek\Crysis\Bin32\Benchmark_CPU.bat
10/29/2009 2:25:30 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Electronic Arts\Crytek\Crysis\Bin32\Benchmark_GPU.bat
10/29/2009 2:27:30 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Electronic Arts\Crytek\Crysis\Bin32\Cry3DEngine.dll
10/29/2009 2:29:30 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Electronic Arts\Crytek\Crysis\Bin32\CryAISystem.dll
10/29/2009 2:31:30 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Electronic Arts\Crytek\Crysis\Bin32\CryAction.dll
10/29/2009 2:33:31 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Electronic Arts\Crytek\Crysis\Bin32\CryAnimation.dll
10/29/2009 2:35:31 PM C:\Windows\System32\rundll32.exe Create Process, Execute Image C:\Program Files (x86)\Electronic Arts\Crytek\Crysis\Bin32\CryEntitySystem.dll
… and more and more and more…
pretty much for ever file that was installed…
anyone found a way to keep it from happening? should i report it to comodo?
wonder if it would be possible for comodo to list which process actually called rundll32…