What's the suspicious Rundll32.exe process?
What's the suspicious Rundll32.exe process?: "o know the module which is executed by Rundll32, proceed further. Without any third-party tools, here is a neat way to track down what the Rundll32 is executing. Open a Command Prompt window and type the following command:
tasklist /m /fi 'IMAGENAME eq rundll32.exe' >C:\rundll32.txt
rundll32-2.JPG (35490 bytes)Now, open the file C:\rundll32.txt file and identify the 'odd' modules. (filter out the system files and dependencies used by Rundll32.exe. The odd one (in this example) is the timedate.cpl file. Yes. I had the Date/Time dialog open and this is what Rundll32.ex"
0 Comments:
Post a Comment
<< Home