Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Rundll32.exe using 99% of my CPU - is it a virus?
   
BullGuard Antivirus Forum > Virus > Virus Questions > Rundll32.exe using 99% of my CPU - is it a virus?  
Forum Quick Jump
 
New Topic Post reply to : Rundll32.exe using 99% of my CPU - is it a virus? Printable version of : Rundll32.exe using 99% of my CPU - is it a virus?
[ << Previous Thread | Next Thread >> ]

StevieD
New Member


Date Joined Aug 2005
Total Posts : 10
 
   Posted 8-28-2005 3:11 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
I noticed my pc slowing down but running hard and when I checked the task manager processes, I found rundll32.exe running at full CPU (99) and I could not end the process unless I shut the machine down.  Now when I start up I to remove 2 instances of rundll32.exe while they are at CPU 0.  Now and then if I dont keep checking, rundll32.exe will resurface and start running at CPU 99.  Is this a virus and can it be removed?
Thanks
Back to Top
 

StevieD
New Member


Date Joined Aug 2005
Total Posts : 10
 
   Posted 9-5-2005 4:24 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
126 views buy no replies. This suggests to me that no one has seen this before and its likely not a virus? Any comments
Back to Top
 

Emilio (SVK)
Forum Moderator




Date Joined Jan 2005
Total Posts : 1876
 
   Posted 9-5-2005 11:08 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
Hi StevieD

Description:
rundll32.exe is a process which executes DLL's an places their libraries into the memory, so they can be used more efficiently by applications.This program is important for the stable and secure running of your computer and should not be terminated.

original location of this file is C:\Windows\System32

If you have installed service pack also here you will find him:
C:\Windows\ServicePackFiles\i386
C:\$NtServicePackUninstall$\


In other cases is it a virus.

Best solution will be if you will send log from Hijackthis.

>click here for download HijackThis<
Put HJT in a permanent folder. Here's how to make the folder:
Click My Computer, then C:\
In the menu bar, File->New->Folder.
That will create a folder named New Folder, which you can rename to "HJT" . Now you have C:\HJT\ folder. Put your HijackThis.exe there, and double click to run it.
Push - Do a systemscan and save a logfile - button
and Highlight the Entire Log by pressing Ctrl+A and Copy it. Post whole log here...

Please don´t run Hijackthis from Temp folder or Desktop!!!Pernament folder is recomended for backup file from Hijackthis!!!


Emilio25

>Hijackthis<>Maxthon<>FireFox<

Back to Top
 

StevieD
New Member


Date Joined Aug 2005
Total Posts : 10
 
   Posted 9-8-2005 5:14 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
 
here it is
 
 
Logfile of HijackThis v1.99.1
Scan saved at 11:57:37 AM, on 08/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
C:\Program Files\Microsoft Office\OFFICE11\MSTORDB.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\HJT\hijackthis.exe
C:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://ca.search.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login?.src=ym&.v=0&.u=8tht8n91fg8n4&.last=&promo=&.intl=us&.bypass=&.partner=&pkg=&stepid=&.done=http%3A//mail.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ca.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://ca.search.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://ca.search.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login?.src=ym&.v=0&.u=8tht8n91fg8n4&.last=&promo=&.intl=us&.bypass=&.partner=&pkg=&stepid=&.done=http%3A//mail.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://ca.search.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://ca.search.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [UStorage] c:\program files\u-storage tools2.0\ustorage.exe sys_auto_run C:\Program Files\U-Storage Tools2.0
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} (IASRunner Class) - https://www.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4534/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = creditron.com
O17 - HKLM\Software\..\Telephony: DomainName = creditron.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = creditron.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = creditron.com
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
 
Back to Top
 

Steve Fox
Junior Member




Date Joined Sep 2005
Total Posts : 66
 
   Posted 9-8-2005 10:05 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
Hi,

You should analyze "C:\Program Files\Microsoft Office\OFFICE11\MSTORDB.EX here


Enabling Show All Files


• On Windows 2000 and XP

1. Open Windows Explorer. Right-click Start then click Explore.
2. On the Tools menu, click Folder Options.
3. Click the View tab.
4. Select Show hidden files and folders, then click OK.
5. Uncheck the Hide protected operating system files check box (if found).
6. Click Yes when prompted.
7. Uncheck the Hide file extension for known file types check box.
8. Click OK.



1. Start/Find
2. In the Named input box, type:

rundll32.exe

If one finds here it is not a virus: C:\WINDOWS\System32\rundll32.exe

Bye
Back to Top
 

StevieD
New Member


Date Joined Aug 2005
Total Posts : 10
 
   Posted 9-9-2005 3:31 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
Hi Steve Fox
I did the search for rundll.exe as suggested and I get
rundll32.exe in folder C:\WINDOWS\system32   
per your note.  I also get
rundll32.exe in folder C:\WINDOWS\ServicePackFiles\i386
And I get 10 instances of
RUNDLL32.EXE-11E559B7.pf in folder C:WINDOWS\Prefetch
each with a different string in place of the 11E559B7
When I search rundll32 i also get
RUNDLL32.EX_  in folder C:\I386
??
I'll try looking at MSTORDB.EX as well.
Thanks
Back to Top
 

Steve Fox
Junior Member




Date Joined Sep 2005
Total Posts : 66
 
   Posted 9-9-2005 6:09 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
You can delete the folder: C:\WINDOWS\ServicePackFiles\i386
MSTORDB.EXE using 99% CPU
Do you have the latest service pak for office 2003? the Mstordb file is updated in that service pak and may solve the problem
Back to Top
 

StevieD
New Member


Date Joined Aug 2005
Total Posts : 10
 
   Posted 9-11-2005 5:25 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
Just to be sure,
I checked MSTORDB.EX at Virus Total as suggested and it was clean.
I do require the lastest service pack for office 2003.
Should I delete the folder: C:\WINDOWS\ServicePackFiles\i386 before or after updating the service pack for office 2003?
Or, do I still need to delete it if I update the service pack?

Thanks for your help.
Back to Top
 

StevieD
New Member


Date Joined Aug 2005
Total Posts : 10
 
   Posted 9-20-2005 6:21 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
I did the latest service pack for office 2003 and the problem occured again.
Before I delete folder C:\WINDOWS\ServicePackFiles\i386, any comments about what the risks are?
Back to Top
 

StevieD
New Member


Date Joined Aug 2005
Total Posts : 10
 
   Posted 9-21-2005 4:15 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
FYI, I found this posting on bullguard from several months ago. They linked this problem to an IBM Thinkpad battery mgt program. I will try it out.


http://www.bullguard.com/forum/10/Symptoms--Rundll32exe-99-CPU-U_5593.html

toaster
Date Joined Jan 2005
Total Posts : 1
Posted 1/5/2005 5:46 PM (GMT +2)
I had the same CPU usage problem with rundll32 on my T41 and XP SP2.
pwrmonit.dll is part of the power management utilities for IBM Thinkpads.
Updating to version 1.37a seemed to solve the issue:
http://www-307.ibm.com/pc/support/site.wss/document.do?lndocid=MIGR-44226
Back to Top
 

acurila
New Member


Date Joined Sep 2005
Total Posts : 2
 
   Posted 9-27-2005 12:09 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
Heya,
Let me start by appologize for my english, this is not my native language.
 
Wel lfor your problem, it just come from the monitoring of your battery with the IBM software (the green % dispay in the taskbar)
Start Regedit and there : "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
You should errase the line which contain something like that "RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor"
 
And then the monitoring will not be load and your cpu will thank's to that :x
 
bye bye
Back to Top
 

StevieD
New Member


Date Joined Aug 2005
Total Posts : 10
 
   Posted 9-28-2005 6:33 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
acurila,
Thank you for your help. Since updating to 1.37 per the previous posting, I have not had the problem.
I am especially relieved that it was not a virus problem after all as my next step was to format the PC.

If the problem re appears I will try your approach.

I take it you had the same problem?

Cheers
Back to Top
 

acurila
New Member


Date Joined Sep 2005
Total Posts : 2
 
   Posted 9-28-2005 10:28 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
I had the same pb with all my IBM T41p...
But I using this tips since 1 year now...so I dont know if the pb is fixed by any new IBM softs cos each format I'm doing the tips ^^

Bye bye
Back to Top
 

BaIT ltd
New Member


Date Joined Oct 2005
Total Posts : 1
 
   Posted 10-10-2005 2:10 (GMT +1)    Quote: Rundll32.exe using 99% of my CPU - is it a virus?Alert an admin about: Rundll32.exe using 99% of my CPU - is it a virus?
I have same problem but probably with nvidia drivers.

I'll try this regedit think and post resaults
Back to Top
 
New Topic Post reply to : Rundll32.exe using 99% of my CPU - is it a virus? Printable version of : Rundll32.exe using 99% of my CPU - is it a virus?
 
Forum Information
Currently it is Friday, January 09, 2009 3:15 AM (GMT +1)
There are a total of 65.964 posts in 16.185 threads.
In the last 3 days there were 23 new threads and 96 reply posts. View Active Threads
Who's Online
This forum has 27795 registered members. Please welcome our newest member, rey_rebs.
60 Guest(s), 1 Registered Member(s) are currently online.  Details
Derrack
5 Latest Threads
Getting taken by multiple bad guys (5)09-01-2009 02:07:14 (Derrack)
Denial of Service Attack (6)09-01-2009 02:07:01 (elledelle)
Contacted CiD spyware/virus (2)09-01-2009 02:05:39 (oblomurg)
Vbs malware gen in phone memory card.. please help (1)09-01-2009 01:20:25 (bindujagarla)
Random pop-ups (0)09-01-2009 00:10:41 (yogendra)