Friday, July 31, 2009

Help me, how do I delete this file 12/8/2007 10:36:52 AM Running process C:\WINDOWS\System32\Rundll32.e...

12/8/2007 10:36:52 AM Running process C:\WINDOWS\System32\Rundll32.exe: detected modification of riskware 'Hidden data sending'.





Im using Kaspersky

Help me, how do I delete this file 12/8/2007 10:36:52 AM Running process C:\WINDOWS\System32\Rundll32.e...
It's probably a false positive, but Kaspersky is pretty good at what it does, so it may be true. Go here: http://www.spywareinfo.com/~merijn/winfi... and download a new copy of rundll.exe (be sure to get the one for your version of Windows), and let Kaspersky delete your old copy. Then replace it with the new copy, it goes in C:\WINDOWS\system32.





If you're unable to delete the old rundll.exe, use Unlocker: http://ccollomb.free.fr/unlocker/ but install Unlocker before you try to delete the old file and then replace it with the new one IMMEDIATELY.
Reply:It's a vulnerable component..


rundll32.exe is a process which executes DLL's and places their libraries into the memory, so they can be used more efficiently by applications. This program is important for the stable and secure running of your computer and should not be terminated.





Note: rundll32.exe is a process registered as a backdoor vulnerability which may be installed for malicious purposes by an attacker allowing access to your computer from remote locations, stealing passwords, Internet banking and personal data. This process is a security risk and should be removed from your system.





Note: rundll32.exe could also be a process which belongs to the . This program is a non-essential process, but should not be terminated unless suspected to be causing problems.





This program is part of Windows, used to run program code in DLL files as if it were an actual program. However, many viruses also use this name or similar names such as 'rundII32' (uppercase i appears the same as lowercase L in many fonts). It's also commonly used by spyware to launch its own code.





If it's infected, scan it..and remove it,.if it just altered, don't remove it.


No comments:

Post a Comment