Link to home
Start Free TrialLog in
Avatar of technolutions
technolutionsFlag for South Africa

asked on

rundll32.exe

If I open the task manager on the Win2k3 box with Exch2k7 there are 128 processes of rundll32.exe.  What is the problem or what is causing this.
Avatar of flaphead_com
flaphead_com
Flag of United Kingdom of Great Britain and Northern Ireland image

k drop to powershell and run
get-process rundl32.exe

I will show u what modules are running.  Also task manager shows you the User Name .. Is it the same for al l instances?
I don't believe powershell or that command will work with Windows 2003.  The powershell is a feature of server 2008.
Process Explorer (from sysinternals) should show you what you are looking for.  Be aware though, most of the problems associated with that many instances of rundll32.exe signal an infection.  Verify again that all of the Windows updates are installed, patches applied and your AV is up to date.  May not hurt to use a product like Malware Bytes as a compliment to your existing AV.

Process explorer -> http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx 
ASKER CERTIFIED SOLUTION
Avatar of flaphead_com
flaphead_com
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial