Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > rundll32 & adware

Reply
Thread Tools

rundll32 & adware

 
 
winged
Guest
Posts: n/a
 
      12-10-2004

You have any nfo on the animal you mentioned? I can't find mention (by
that name) on the web. Kinda curious about how new stuff works. Where
in the hive does it embed?
Winged

David H. Lipman wrote:
> McAfee sent me an EXTRA.DAT today for this Adware object, presently identified as
> "Adware-adwr" and will be included in next week's release of v4413 DAT files.
>
> Dave
>
>
>
>
> "Jim Watt" <_way> wrote in message
> news:...
> | I have a couple of machines that pop up IE with adverts from nowhere;
> |
> | There is nothing suspicious run from the registry etc, and spybot
> | finds nothing.
> |
> | There is a process running with rundll32 shown, but no idea what
> | DLL its running.
> |
> | Any suggestions on how to exorcise this ill ?
> |
> | OS is windows/98
> | --
> | Jim Watt
> | http://www.gibnet.com
>
>

 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a
 
      12-10-2004
Winged:

I didn't load the DLL on a test PC, I just provided it to McAfee. They indicated it looked
like a "Look2me" adware component and would require the /program switch be used with the
Command Line Scanner or the Program check box checked in the >v7.x VirusScan.

What do you use at your locale ?

The MIS/IS group around me use Norton. However, I use McAfee and my success rate and
prevention blows away those that use NAV.
One "QHosts-1" Trojan infection, in over 10 years, on a notebook from someone who would not
practice Safe Hex. On the other side of that T1 I mentioned to you know whom, I had a
satellite office. While the contractor was infected with the Lovsan/Blaster running rampant
on their LAN, McAfee blocked infection of the BLASTER.EXE file and none of my platforms were
affected more than being shut down. That is until I pushed via my Kixtart Login Script the
(first in a series of) patch for the RPC/DCOM Buffer Overflow vulnerability. I considered
my satellite LAN a good neighbourhood in a slum. The contractors subnets were a bad
influence on my LAN

Dave



"winged" <> wrote in message news:cpb94u$...
|
| You have any nfo on the animal you mentioned? I can't find mention (by
| that name) on the web. Kinda curious about how new stuff works. Where
| in the hive does it embed?
| Winged
|
| David H. Lipman wrote:
| > McAfee sent me an EXTRA.DAT today for this Adware object, presently identified as
| > "Adware-adwr" and will be included in next week's release of v4413 DAT files.
| >
| > Dave
| >
| >
| >
| >
| > "Jim Watt" <_way> wrote in message
| > news:...
| > | I have a couple of machines that pop up IE with adverts from nowhere;
| > |
| > | There is nothing suspicious run from the registry etc, and spybot
| > | finds nothing.
| > |
| > | There is a process running with rundll32 shown, but no idea what
| > | DLL its running.
| > |
| > | Any suggestions on how to exorcise this ill ?
| > |
| > | OS is windows/98
| > | --
| > | Jim Watt
| > | http://www.gibnet.com
| >
| >


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RUNDLL32.EXE --tomcat-- Computer Support 7 04-26-2004 04:03 PM
Rundll32 run-time error '53' Ian H Computer Support 7 01-07-2004 12:28 AM
rundll32.exe sabine Computer Support 8 09-29-2003 04:29 PM
Re: A Big trojan problem (irc.flood.??) and rundll32.exe connecting to internet Timo aka Sul Computer Support 0 07-31-2003 07:58 PM
rundll32 Illegal operation error Fred Erfmann Computer Support 0 06-25-2003 02:27 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57