Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 3rd, 2006, 09:19 AM
paperinik3's Avatar
paperinik3 paperinik3 is offline
Regular Poster
 
Join Date: Aug 2003
Posts: 90
Default at every boot rundll32.exe wants...

At every boot rundll32.exe wants the privilege to install hooks.
Should I give in ?
  #2  
Old February 3rd, 2006, 10:34 AM
tonyjl's Avatar
tonyjl tonyjl is offline
Frequent Poster
 
Join Date: May 2004
Posts: 287
Default Re: at every boot rundll32.exe wants...

What does the command line say? Is it from a trusted app?
__________________
Best Regards,
TonyJL

I am prepared to meet my Maker. Whether my Maker is prepared for the great ordeal of meeting me is another matter.
Sir Winston Churchill, on the eve of his 75th birthday
British politician (1874 - 1965)
  #3  
Old February 3rd, 2006, 12:14 PM
paperinik3's Avatar
paperinik3 paperinik3 is offline
Regular Poster
 
Join Date: Aug 2003
Posts: 90
Default Re: at every boot rundll32.exe wants...

thank you tonyjl, in the protection tab it says only: "c:\winnt\system32".
  #4  
Old February 3rd, 2006, 04:52 PM
tonyjl's Avatar
tonyjl tonyjl is offline
Frequent Poster
 
Join Date: May 2004
Posts: 287
Default Re: at every boot rundll32.exe wants...

Quote:
Originally Posted by paperinik3
thank you tonyjl, in the protection tab it says only: "c:\winnt\system32".

That just says where rundll32 is located.

I mean,when you get the alerts,(the actual pop-up) click on 'more info',it should give more details about what is using rundll32 to install hooks:-app path and name,cmd line etc. Next time you get the alert,jot down the info given and then post back.
__________________
Best Regards,
TonyJL

I am prepared to meet my Maker. Whether my Maker is prepared for the great ordeal of meeting me is another matter.
Sir Winston Churchill, on the eve of his 75th birthday
British politician (1874 - 1965)
  #5  
Old February 4th, 2006, 04:24 AM
paperinik3's Avatar
paperinik3 paperinik3 is offline
Regular Poster
 
Join Date: Aug 2003
Posts: 90
Default Re: at every boot rundll32.exe wants...

This is very curious...So: I have rebooted, got the alert "at 10.08.04 rundll.exe was blocked from creating a global GetMessage hook", went to the logs and - surprise! there was no trace of this block. All the other blocks were logged (I have, for instance, put a block on mobsync.exe) but not only did I not find the rundll32.exe block but THERE IS NO ENTRY at all between 10.08.01 and 10.08.09 !
What does this mean ?
Hopeful regards
  #6  
Old February 4th, 2006, 04:37 AM
SpikeyB SpikeyB is offline
Frequent Poster
 
Join Date: Mar 2005
Posts: 464
Default Re: at every boot rundll32.exe wants...

I would run HijackThis and take a look at the O4 entries to see if that gave any clues as to what wanted to run rundll32.exe. An example is given in the log here: http://forums.techguy.org/security/435855-hjt-log.html (check out the 1st and 3rd O4 entries).

You can probably get the same info from using msconfig and the startup tab but the msconfig window makes viewing the details difficult.

Last edited by SpikeyB : February 4th, 2006 at 04:45 AM.
  #7  
Old February 4th, 2006, 05:34 AM
paperinik3's Avatar
paperinik3 paperinik3 is offline
Regular Poster
 
Join Date: Aug 2003
Posts: 90
Default Re: at every boot rundll32.exe wants...

Hijackthis tells me that the only application which wants to run rundll32.exe at startup is Start Pwr Monitor which is " IBM'S PROPRIETARY "battery maximizer" and power monitoring software for laptops" - so , my machine being an IBM Thinkpad, I suppose it's allright to let it run.
Thank you very much for your help SpikeyB.

BUT - WHY IS THIS EVENT NEVER LOGGED
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > ProcessGuard « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:18 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums