catgate Posted June 26, 2004 Report Share Posted June 26, 2004 I have Zonealarm as one of my my guardian angels, and this morning I downloaded and installed the latest update. After doing this I checked which programmes it would allow in/out without question and found that it had rundll32.exe listed as such. I had not put it there, does any one know how it could have got there and why? Quote Link to comment Share on other sites More sharing options...
nellie2 Posted June 26, 2004 Report Share Posted June 26, 2004 explanation of rundll32.exe click here Quote Link to comment Share on other sites More sharing options...
catgate Posted June 26, 2004 Author Report Share Posted June 26, 2004 Thanks for that, nel. I am still a bit puzzled as to how it got fed into my Zonealarm "accept" list . Perhaps it just got fed up of sitting around, waiting for something to do, and decided to get up and have a walk round. Then I have come along and caught it "out of bed" . C'est la vie, as we shall all have to say, come the revolution!! Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted June 27, 2004 Report Share Posted June 27, 2004 rundll will run application extentions. (like options in internet explorer) for some reason, one of them needed to use the internet. you must have let it, because if I remember correctly, zone alarm is picky :) Quote Link to comment Share on other sites More sharing options...
catgate Posted June 27, 2004 Author Report Share Posted June 27, 2004 You are right about Zonealarm being "picky". (So am I , and that is why I like it .) I can only assume that some recently added prog/utility has itself put rundll32 into Zonealarm when I have authorised that prog/utility to 'go online'. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted June 27, 2004 Report Share Posted June 27, 2004 The best thing to do, may be block rundll in zone alarm again, and when it asks to connect back to the internet, see what programs are running and which one is using rundll to connect. It may be a backdoor 'piggybacking' on that file. Just be safe. :D Quote Link to comment Share on other sites More sharing options...
catgate Posted June 27, 2004 Author Report Share Posted June 27, 2004 That is precisely what I have done. I was just curious as to how it got there, because I would have expected anything carrying a piggyback would have been stopped by Zonealarm. Also I run AVG, automatically, every day and would have expected that to have found whatever had managed, by some miracle, to sneak past Zl. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.