Defense+ Alerts: rundll32.exe is trying to execute different dll, exe files

Hey Matty, thanks man. Worked fine, no more ■■■■■■■■ alerts over here :P0l

many thanks for supplying a answer to this problem guys…it’s been annoying me for weeks.
I assume it’s a windows 7 only problem?

thanks again.

Mike.

Hey, I tried the Task Scheduler thing. I still receive D+ rundll.exe alerts.

I’m running Windows 7 Pro x64.

Help would be appreciated.

On windows 7 RC rundll.exe appears to be aroblem.
it tries to execute many dlls,exe on its own,

one example is here i tried to execute one exe on win 7 rc, which failed as it was written for earlier version however when i checked the d+ logs , i found that rundll has tried to execute it even after 3 days.

surprised i blocked that file using comodo

Nevermind, everything seems to be fine now, after what Matty suggested. I guess a reboot was needed.

I experience this too once every few days. The problem is described like it is in http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/d19fc800-4f76-4353-88d3-d2cc6674ac21

Many random files are trying to be executed by rundll32.exe such as (but not limited to) .bmp, .bnk, and .dll files.

I end up having to click Block in Comodo about 30 times. I reset my Comodo config about 2 or 3 weeks ago and used Training Mode for a few hours while executing different programs. Prior to resetting the config, I never saw this issue. I had to reset my config because my Defense+ group policies disappeared.

The Comodo rundll32.exe alerts were driving me nuts…
Running malware/spyware scanners etc. will not resolve this problem as the cause is with Microsoft Windows 7 collecting customer data:
I found this resolution on an Everybody Geek Blog:

"Why do you get these warnings?
Whenever your computer is idle, Windows 7 collects program telemetry information that is used for the Microsoft Customer Experience Improvement Program, if opted-in.
This information is collected, even if you selected not to participate in the Microsoft Customer Experience Improvement Program. The information is simply not used.

How do I fix this?
Stopping these warnings about rundll32.exe to pop up is very easy. All you have to do is disable the scheduled task that is responsible for collecting program telemetry information.

Open the Task Scheduler
• Click the Start button and enter ‘Task Scheduler’ in the search box
• Click ‘Task Scheduler’
or
• Open Start => Control Panel
• Select ‘System and Security’
• Under Administrative Tools, select ‘Schedule Tasks’
Disable the scheduled task
• In the Task Scheduler, navigate to: Task Scheduler Library => Microsoft => Windows => Application Experience
• You should see two scheduled tasks: AitAgent and ProgramDataUpdater
• Right click ‘ProgramDataUpdater’ and select ‘disable’
• Reboot your computer
That’s all. No more Defense+ warnings about rundll32.exe trying to execute different dll files.
Posted by Everybody Geek"

My pc is now free of these rundll32.exe alerts
Many thanks to Everybody Geek

Hi bukarr ,

The advice about “Application Experience” was (is) somewhere in this forum as well.

At the same time, I never ever had this problem since installing Comodo’s Firewall only (with Defense+ Proactive Mode ) on win 7 x64.

The “Application Experience” was definitely disabled as many other silly MS scheduled tasks & dumb-unneeded services … but that was done “just because”
That is necessary by itself :wink: No connection to the “rundll-alerts”. I never had that problem ??? 88)

Running Firewall only v3.14 on XP and on win 7 Hope Premium x64

Cheers!

A couple of days after I reset my Comodo config and before upgrading to Comodo v4.0 Firewall, I exported my v3.x settings to a file.

I uninstalled 3.x and then installed 4.0 firewall (I use a separate antivirus).
In 4.0 I imported my 3.x settings.

I’ve been using 4.0 for about 3 or 4 weeks and haven’t had the annoying alerts so far about rundll32.exe.

Hi selflove,

Thanks for reply.

I don’t think that updating to v4 is a cure.
As I pointed that issue does not occure for many configurations whether it is XP ot win 7 32/ x64 bit
and I was using Comodo’s Firewall only starting from version “zero” ;D
I am currently using V3.14 on XP and win 7 x64 and it is the last version I will ever use
… no such problem with rundll

So that’s has nothing to do with v4 upgrade if mean that v4 “will fix” this particular issue

Cheers!