rundll32.exe processing srrstr.dll?


  1. Posts : 76
    Windows 7 RTM
       #1

    rundll32.exe processing srrstr.dll?


    Hi everyone. Just a quick question: Is anyone familiar with this phenomenon? I left my computer idle to work in the kitchen for about 25 min, and when I returned I found that rundll32.exe was running and processing something over and over again. I checked Process Explorer, and found it was running something called srrstr.dll - Which apparently came digitally signed from Microsoft (though I guess that's easy to forge). I'm not sure what it was doing, but it chugged away for an additional ten minutes before it closed itself. Very strange.

    Can anyone please advise if this is a nasty? NOD32 and Malwarebytes didn't catch it, if it is. Thank you.
      My Computer


  2. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #2

    Hi, Carbonyl.

    srrstr.dll is part of the System Restore process. If a checkpoint was being created, that period of time is a bit lengthy. You may want to check to see if the time the last checkpoint was created approximately matches the time of your investigation.
      My Computer


  3. Posts : 53,365
    Windows 10 Home x64
       #3

    Carbonyl said:
    Which apparently came digitally signed from Microsoft (though I guess that's easy to forge).
    Maybe Corrine can confirm, but I don't think it is "easily done"...perhaps not impossible, but very complex. A Guy
      My Computer


  4. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #4

    For background on Digital Certificates, see Microsoft KB Article 195724: Description of Digital Certificates

    Note the affected software indicated in this Security Advisory is "none". Microsoft Security Advisory (961509): Research proves feasibility of collision attacks against MD5:

    General Information

    Overview

    Purpose of Advisory: To assist customers in assessing the impact of this research announcement on their current certificate deployments.

    Advisory Status: Issue Confirmed. No Security Update Planned.
    Recommendation: Review the suggested actions and configure as appropriate.
    References Identification:
    Microsoft Knowledge Base Article 961509

    This advisory discusses the following software.
    Affected Software: None.
      My Computer


  5. Posts : 5,056
    Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
       #5

    You can configure when and how often system restore runs, through the Task Scheduler.

    Change How Often System Restore Creates Restore Points in Windows 7 or Vista - How-To Geek
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 02:27.
Find Us