Re: Many (runaway?) RunDLL32.exe processes starting - help
From: Help (anonym_at_whoknowswhere.osh)
Date: 08/03/04
- Next message: Alex Nichol: "Re: Some Text is Wrong Size After Reinstall"
- Previous message: S.Sengupta: "Re: Shutdown Error - Explorer.exe not responding"
- In reply to: Malke: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Next in thread: Rock: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Reply: Rock: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Reply: Malke: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Reply: Masta Eda: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Messages sorted by: [ date ] [ thread ]
Date: Tue, 03 Aug 2004 20:32:30 +0100
Hi Malke,
Thanks for the response .. I was deciding to blat and restart as the
fastest way to sort it out...
However, I have a bit more info and another question...
I ran a final virus scan with the system checking absolutely everything
it can and it found a part of the sasser virus. The file cmd.ftp was in
c:\windows\system32
This file is a temporary file used as part of the infecting process with
SASSER-A.
There were no signs of SASSER-A infected files anywhere else.. although
the symptoms are similar.
I did a scan for files that were modified around the same time as
cmd.ftp and found a couple in windows/system32:
cc.exe
msc.cpl
Neither show up in the sophos scan as being infected.
There were other bits such as things in prefetch .. but then the system
adds anything it runs to prefetch so these are presumably a kind of
audit trail of what was run when the infection took place.
I renamed the cc.exe, msc.cpl, and cmd.ftp to different names and
extensions.
The .cpl is a control panel file and would explain why I couldn't open
control panel.
Now, when I reboot, the machine starts up ok .. no extra processes and
seems clean.
My problem is that I don't know what else might have been
corrupted/changed when the infection took place and don't feel 100%
comfortable putting the machine on the network at the moment. (It is
currently standalone and I have been transferring files via a CD).
I assume that one or other of cc.exe, msc.cpl was triggering the
rundll32s and that they were being started by the prefetch (they were in
there from when they had run during the initial infection). I don't
know how realistic that is tho.
Again, any advice appreciated ...
Malke wrote:
> Help wrote:
>
>
>>Hi,
>>
>>I have had a laptop passed back to me by one of my users. After
>>booting up there were getting the RPC error... "Windows must now
>>restart because the RPC service terminated unsuccessfully" - and the
>>countdown.
>>
>>Although the machine is patched, I assumed that a sasser variant had
>>got in...
>>
>>When I got the machine, I booted it up in safe mode and ran a scan and
>>found the RBOT-AM virus on, which I removed. I also ran spybot - S&D
>>and adaware and remove a few bits but nothing dramatic.
>>
>>When I start up in normal mode, a load of rundll32 processes are
>>running .. a couple of hundred .. and they just seem to spawn until
>>there is no VM left and the machine shuts itself down.
>>
>>When I start in Safe Mode, I can use the machine excpet for accessing
>>the control panel. When I try to access the control panel, I get the
>>window up and then the searchlight icon spinning around. If I try to
>>get into task manager, then I see a lot of rundll32 processes again
>>and the machine runs out of VM again.
>>
>>One of the last things the user did before the problem occurred was to
>>install a BTBroadband CD. I uninstalled what I could of it .. mainly
>>an Intel DSL program, but, because I can't get to the control panel, I
>>can't get to Add/Remove programs.
>>
>>If I stop the shutdown with a shutdown -a, I only really delay the
>>inevitable because the machine still runs out of VM.
>>
>>Any help appreciated ...
>>
>>Anyone have any ideas as to why control panel fails in safe mode ?
>>
>>Is there anyway of finding out what might be triggering all the
>>rundlls ? What is the direct command to launch the Add/Remove programs
>>window ?
>>
>
> It sounds like the system is infested with viruses and spyware. At this
> point - particularly if you are a busy sysadmin - the easiest and most
> efficient way is to format and start over.
>
> Malke
- Next message: Alex Nichol: "Re: Some Text is Wrong Size After Reinstall"
- Previous message: S.Sengupta: "Re: Shutdown Error - Explorer.exe not responding"
- In reply to: Malke: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Next in thread: Rock: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Reply: Rock: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Reply: Malke: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Reply: Masta Eda: "Re: Many (runaway?) RunDLL32.exe processes starting - help"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|