Solved What is rundll32.exe?

yankleber

IT Dinosaur
Member
VIP
Local time
2:25 AM
Messages
212
Location
Home
Is it normal to have around 30 copies of rundll32.exe running at the same time?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Professional 64bit
CPU
Intel i5-3330
Motherboard
GigaByte B75M-D3H
Memory
8GB
Graphics Card(s)
Onboard
Sound Card
Behringer UCA222
Monitor(s) Displays
Samsung 22.5"
Screen Resolution
1920x1080
Hard Drives
SSD Kingston 120GB
HDD Samsung 320GB
Internet Speed
1M
Antivirus
ZoneAlarm FW + AV Free
Browser
Chrome
Sometimes. Viruses have been known to use rundll32.exe To check, run malwarebytes


Having multiple instances of rundll32 running at the same time is not very suspicious by itself.


rundll32 is a part of Windows used to invoke functions in dll's that are explicitly meant to be called by them (meaning that you can run them from a command line/command line script, or from an executable without linking against the dll that the required function is contained in). For a mor in-depth explanation, see the MS Knowledge Base.
Also look here for a description of how you can adjust the table in your task manager to see the entire command line, and so which functions are actually being run by your rundll32. This will also tell you which rundll32.exe is being run (if one of them is in a strange folder, say C:\Program Files\whatever\rundll32.exe, that would likely be a problem. Both instances should have the same path (this may be different on 64bit systems which may have a separate 32bit version, I'm not sure about that).
The article that you link to is not good advice imho. While a changing symbol for rundll32 is a sign that tells you something is wrong, it is by no means certain that a modification of it would show up in this way!

In terms of advice: First check the file paths of the running rundll32, then check which dll's/functions they are running. If you still have original recovery media (if not, you might be able to get some from your hardware vendor), recover your system from there instead of the hdd image if you're concerned about that.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP Desktop & Compaq Laptop
OS
Win 10 x64, Linux Lite, Win 7 x64, BlackArch, & Kali
Hard Drives
Samsung 850 Pro 256Gb,
Hitachi HDD 1Tb,
Crucial MX SSD 250Gb
Segate 3Tb USB 3.0 Ext. Backup HDD
Internet Speed
150Mbps dn, 20Mbps up
Antivirus
Avast Free, Malwarebytes Anti-Exploit & Anti-Ransomware
Browser
Firefox, Chrome, Opera, & VPN
Thank you! I was imagining it because I never had seen it before and my computer was super slow. In the meantime rebooted my computer and it became normal again.

Then I saw your message and installed Malwarebytes but it didn't find anything. Anyway, checking TM the rundll32 files aren't there anymore (because the reboot for sure). I will keep an eye on it.

Thanks again!

:-)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Professional 64bit
CPU
Intel i5-3330
Motherboard
GigaByte B75M-D3H
Memory
8GB
Graphics Card(s)
Onboard
Sound Card
Behringer UCA222
Monitor(s) Displays
Samsung 22.5"
Screen Resolution
1920x1080
Hard Drives
SSD Kingston 120GB
HDD Samsung 320GB
Internet Speed
1M
Antivirus
ZoneAlarm FW + AV Free
Browser
Chrome
Never hurts to run a malware scan. Malwarebytes is one of the best free or real-time premium.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP Desktop & Compaq Laptop
OS
Win 10 x64, Linux Lite, Win 7 x64, BlackArch, & Kali
Hard Drives
Samsung 850 Pro 256Gb,
Hitachi HDD 1Tb,
Crucial MX SSD 250Gb
Segate 3Tb USB 3.0 Ext. Backup HDD
Internet Speed
150Mbps dn, 20Mbps up
Antivirus
Avast Free, Malwarebytes Anti-Exploit & Anti-Ransomware
Browser
Firefox, Chrome, Opera, & VPN
Back
Top