Link to home
Start Free TrialLog in
Avatar of rajuvegesna
rajuvegesna

asked on

rundll32.exe problem

Hello,

I have a problem when i shutdown my laptop, rundll32.exe is not closing, i have to close it manually.. Whats the use of this rundll.exe. How can achieve the problem. Also when i goto controlpanel/software for uninstallating any programs nothing displays there.. Is there any like between this and rundll32.exe

can i get any help..
I am using Windows XP Home Edition
i dont want to repair with cd, its my last option!!

thankyou..

Avatar of Aristiana
Aristiana

What applications are you running prior to shutting down your system?

I've found that some applications do not properly shutdown the RUNDLL32 file. Which then causes you to have shut down problems.
A temporary work around is to do the following prior to shutting down:

CTL ATL DEL
Click Task Manager
Click the Processes Tab
Click on RunDll32
Click End Task.
Keep doing that until the RUNDLL32 file ends.
Avatar of rajuvegesna

ASKER

Hello  Aristiana,

I will check with windows xp cd.

Hello  gemarti,

your solution works, but its not the right way.. because when i restart my system rundll32.exe starts again, so same problem occures..
every time i cant click endtask before shutdown..




can i know whats the use of this rundll32.exe?

thankyou..


ASKER CERTIFIED SOLUTION
Avatar of gemarti
gemarti
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
hello,

now it was good,

bridge.dll is making shutdown problem for rundll32.exe..

even before i found this bridge.dll through Norton scanning, this bridge.dll is in c:/windows/download internet files. When i try to delete this i didnt found the file even in safe mode.. how can i find this file and delete..

thankyou..
as i asked before " Also when i goto controlpanel/software for uninstallating any programs nothing displays there (it strucks).". Now the problems was solved. Sometime it shows problem but when i close it and open again there is no problem..have u any idea..this is due to rundll32.exe.

thankyou..
Glad I could help.

Thank you.
I suggest that you download and run at least two of these applications to clean up your system. You've probably got lots of spyware on your machine. Since the bridge.dll file was in your temporary internet folders this is a high probablity.

Spyware/Adware removal tools:
------------------------------

SpyBot-S&D : http://www.webattack.com/download/dlspybot.shtml 

Ad-aware : http://www.webattack.com/download/dladaware.shtml 

Trojan Remover :http://www.simplysup.com/

HijackThis : http://www.webattack.com/download/dlhijackthis.shtml 

KL-Detector  :http://www.webattack.com/download/dlkldetector.shtml

X-Cleaner Free  :http://www.webattack.com/download/dlxcleaner.shtml

SpywareBlaster  :http://www.webattack.com/download/dlspywareblaster.shtml

SpywareGuard :http://www.webattack.com/download/dlspywareguard.shtml

SpySites  :http://www.webattack.com/download/dlspysites.shtml

Keylogger Hunter :http://www.webattack.com/download/dlklhunter.shtml

Spycop: http://www.spycop.com/

Goodbye Spy http://www.topshareware.com/GoodBye-Spy-download-2012.htm
Thanx for the links. I have at present ad-aware6 in my system, once i have problems with SpyBot, it took my windows dll files also (crazy)..

i will download Hijack This..

ciao
Hello,

This is my scan file from Hijack This, Can you help me which should i fix.

Logfile of HijackThis v1.97.7
Scan saved at 10:30:32, on 29.02.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\stopzilla\szntsvc.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\mysql\bin\mysqld.exe
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\Programme\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Programme\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\slserv.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\khooker.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Program Files\stopzilla\Stopzilla.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\rnathchk.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programme\Yahoo!\Messenger\YPager.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Programme\HijackThis.exe
C:\Programme\HijackThis.exe
C:\Programme\Messenger\msmsgs.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar2.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\StopzillaBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O3 - Toolbar: Yahoo! Assistent - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Programme\Gemeinsame Dateien\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Msgchm] C:\WINDOWS\System32\MSGCHM.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~2\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Unldr16] c:\windows\system32\unldr16.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\stopzilla\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Lnbu] C:\Dokumente und Einstellungen\Raju\Anwendungsdaten\oroe.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://c:\programme\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\programme\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\programme\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Si&milar Pages - res://c:\programme\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programme\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/InstallFiles/SIFiles/lpxlive/HS_live.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.5.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Assistent) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F0230524-9D39-4E84-8452-41C592961EA7} (Installer Class) - http://www.4wav.com/Config.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/crack.CAB

thanx a lot!!
Well I don't normally use Hijack this but upon scanning your list it looks like:

C:\WINDOWS\System32\khooker.exe

and

O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe


are kind of suspect. I would first back up the registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Then I would delete the
Value: SIS KHooker

Then I would locate c:\WIndows\System32\kHooker.exe KHooker.exe ->KHooker.spy
If your unable to do it while logged on then after making the registry change above reboot your PC and then try renaming KHooker.exe


I will try to do this. Except this everything is in perfect..

thankyou..
NOTE: In the registry you should always export the key you are about to modify before making any changes or deleting. This way if you do something wrong you can bring the unedited key back to the registry.
To Export a Key while in the registry click FILE | Export
Save the [filename].reg to a location on your Hard Drive where you can find it later if you have to.
thankyou for your support....
In my experience, khooker is used by the Sis sound card and is not spyware
khooker is a keylogger isnt it?

Lets hope not, that could be really bad :-O
Nevermind the above I stole this off another board.


"SiS is the manuafacturer of your motherboard or some of the components on it. The KHooker is a keyboard software that can map keys on teh keyboard with special functions. It is not needed and most people won't use it.
ZeroZen was wrong to assume that it is somethign bad. IT ISN'T. removing it may free up some resources on your computer. Pc (PT) Snoop is a driver for a PcTel modem that is in your PC. Crappy modem, ptsnoop hogs many resources on the computer. If you don't use your modem (for instance if you have DSL or a cable modem) then remove the modem and uninstall the drivers."
Hello,

Its bad to know lately, i uninstalled Hijack This. I am using DSL line. I can remove the modem and uninstall the software but when i reinstall can i get KHooker. If not its waste to do so.. In future if i use modem i need the software, can you please give instructions for uninstalling the software.

Thankyou..
You said your on a DSL line, are you using some sort of firewall like Zonealarm from www.zonelabs.com. It's a free and extremely popular and excellent personal firewall.
I discovered that the rundll32.exe error upon shut down is due to spyware that none of the regular spyware scanners remove.  It is called Cool Web Search.  Go to this link to learn about it and get a fix.
http://www.spywareinfo.com/~merijn/cwschronicles.html#cwshredder

The entry in msconfig for this problem was listed as "image" with
"rundll32.exe c:\windows\image.dll,install" as the path.  

Go to this site that has info on startup  items in msconfig to check out the need for other items listed.
http://www.sysinfo.org/startuplist.php
This site is where I found the link for cool web search to remove the spyware.

Hope this saves some of you a lot more time than I spent in tracking this beast down.

Hello dctechgrl,

Thanx for spending time for the search. I am not facing rundll32.exe problem anymore at system shutdown. This problem occures due to bridge.dll at systemstartup.Your link at startuplist helps in future.


give the points to someone then. Looks like gemarti gave you the skinny on blowing out startup data so I would hook him up.

-Bo
Hello bhaggard,

What points?? Have u didnt read the comments, i have given the points long back to gemarti. See the accepted answer.. thankyou..
My sincere apologies. For some reason when I reviewed that question I did not see the huge freaking green bar with the bolded 'Accepted Answer". Again, sorry for the criticism.

-Bo
:O PLEASE HELP! My Desktop is frozen. I can turn on my computer and logon(no problems there) but when the I get to the desktop it is frozen. When I move the mouse over the toolbar, the hour glass shows. Usually w\hen my DSL connects my messanger logs me on. My friends tell me I'm logged on. I have no clue I am because my desktop screen is frozen? What should I do???


Thanks.
Good old RunDll32.exe problem. Windows will not shut down. Various strange problems also have arisen. "Run a Dll as an App has encountered a problem and needs to close" is the message I receive. Detail is "AppName: rundll32.exe  AppVer 5.1.2600.00 ModName 6jo4 sv.dll"

All this is puzzling for an old man. I have used the new verstion of Spybot a couple days ago and this happened. Please help.

Explorer does not find Rundll32.3xe but then I may not know how to search for it.
This issue might be because of spyware: http://www.2-spyware.com/file-rundll32-exe.html