- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic to the Top
- Bookmark
- Subscribe
- Printer Friendly Page
NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-16-2008 12:04 PM
I use NAV2008 on an HP Desktop running Windows Vista Home premium with Vista Service pack 1. All my updates ar current
I will be getting NIS 2009 in the next month or so, so I know the outgoing firewall will show me what programs are running
I notice that when I run a quick scan or a full system scan, I get MANY instances of An instance of "C:\Program Files\Norton AntiVirus\Navw32.exe" is preparing to access the Internet. I have checked the dll files in the My Norton Antivirus file and do see many dll application extensions. Not sure what they all mean, but they are digitally signed by Symantec. All my scans show only tracking cookies, no other infections. I have also run SpyBot and windows defender and none show any type of infection. When I pull up the windows task manager., it shows onlt 2 rundll.exe on, even when running the scan
My questions:
1.Should there be 11 instances where a dll files needs to access the internet for the scan to work?
2. I notice that there are 4-5 instances and then less than 1 second another 4-5 instances
3. Could this just be a logging clitch?
4. From your knowledge, does this appear to be some type of infection?
my activity logs shows the following:
9/15/08 11:11:05 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:05 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:04 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:04 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:04 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:04 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:03 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:03 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:03 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:03 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:03 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:11:02 pm An instance of "C:\Windows\System32\rundll32.exe" is preparing to access the Internet.
9/15/08 11:10:56 pm An instance of "C:\Program Files\Norton AntiVirus\Navw32.exe" is preparing to access the Internet.
Re: NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-16-2008 04:17 PM
Hi
Have you used something like the program "Hijackthis" to see if more than one Rundll32.exe is running, and more that one registry value?? don't tick any entry in Hijackthis until you know.
Sometimes Viruses / Malware create their own non-legit file of the same name (whether Rundll32.exe, Winlogon.exe etc) in an attempt to hide themself. Or hide behind the process and attempt to launch it's own code.
Quads
Re: NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-16-2008 04:35 PM
Re: NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-16-2008 05:05 PM
The file "Rundll32.exe" is used to run dll's as an application. I just can't think of a reason why it would continually try and access the internet on that regualr a basis for a legitimate process.
There are a couple of nasties that try and attempt to terminate Antivirus software.
If you use Hijackthis, I am willing to see the log if you like to see if any entries like F0 - system.ini: Shell=Explorer.exe, F1 - win.ini: or "F2 - REG:system.ini:Rundll32.exe..............." and so on.
and any other nasties in the log.
You can private message me the log if you like,
Quads
Re: NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-16-2008 05:19 PM
If it is a type of infection (unknown at this point) it doesn't mean that it should affect LU as it depends on what is going on and what is trying to be done.
Like infections affect Windows in different ways , more serverly or not, and so is sometimes easily noticed. Or sometimes uses the PC's resources, but somtimes works really quietly.
Re: NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-18-2008 04:33 PM
sorry all I should correct things
I'm talking about Navw32.exe and rundll32.exe I suspect if I had nav32.exe and or rundll.exe that might be cause for alarm.
But the Navw32.exe is digitally signed by symantec
Re: NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-18-2008 06:23 PM
Hi,
The "rundll32.exe" to me more of a concern the way it is trying to access the internet, when clean systems generally down have that.
Th name "rundll32.exe" can remain the same, but certian viruses and trojans use the file (modified or not) to try and access the net, and/or in the process attempt to shut down security software, or disable silently in an attempt to give free internet access.
"rundll32.exe" is a legitimate file and process and is used by legitimate programs (dll's). People making viruses also realise this and can create a program to modify or use "rundll32.exe" to run the dll the viral program (or trojan). Or create it's own file like for instance,
--------------------------------------------------
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
--------------------------------------------------
In this case is the "Lovegate" Virus.
I can't remember in Vista but in XP there could (or should) be a backup version of "rundll32.exe" in the "dllcache". (a hdden folder).
This is in case of the original file being modified, corrupted etc. by an infection. the file can be replaced with a clean version.
I can't think of any reason why "rundll32.exe" would continually want to access the internet if for legitimate reasons. like you showed in your first post.
more info for you.
Regards
Quads
Re: NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-19-2008 04:04 PM
Re: NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-19-2008 08:01 PM
Hi NY1986,
I think that Quads made you a great offer to help you run and check a Hijack log about the multiple rundll's.
I'd take him up on that!
Best Wishes.
Phil_D
NIS 2010 • 360 v4 • Ghost 15.0
XP SP3 • Vista SP2 • Windows 7 Professional x64
Re: NAV32.exe and dll issue with more specific informatio n
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Notify Moderator
09-20-2008 06:20 AM
I appreciate all the help. I can tell you that my file
rundll32.exe shows no modifications. It is as it was when it came from the store
