Friday, December 22, 2006

What's the suspicious Rundll32.exe process?

What's the suspicious Rundll32.exe process?: "o know the module which is executed by Rundll32, proceed further. Without any third-party tools, here is a neat way to track down what the Rundll32 is executing. Open a Command Prompt window and type the following command:

tasklist /m /fi 'IMAGENAME eq rundll32.exe' >C:\rundll32.txt

rundll32-2.JPG (35490 bytes)Now, open the file C:\rundll32.txt file and identify the 'odd' modules. (filter out the system files and dependencies used by Rundll32.exe. The odd one (in this example) is the timedate.cpl file. Yes. I had the Date/Time dialog open and this is what Rundll32.ex"

0 Comments:

Post a Comment

<< Home