Skybuck Flying
2015-11-11 02:35:07 UTC
Hello,
I was just running Firefox webbrowser with many tabs open, I closed all of
them.
Then I returned to task manager... first I noticed this annoying svchost.exe
running again but it disappeared fast.
I also noticed the harddisk light flickering (thankfully).
Then I noticed this rundll32.exe was running again !
This time I took some advice from you guys and had the image path showing on
columns always !
And this time I was able to bust and caught it red-handed ! ;) =D (took a
screenshot ! =D)
Now the investigation can start to what this is.
And yes it's behaviour is the same... it seems to scan *.exe files, why I
don't know.
Here is the screenshot:
Loading Image...
It's command line is:
c:\Windows\system32\rundll32.exe appraiser.dll,DoScheduledTelemetryRun
Bye,
Skybuck.
I was just running Firefox webbrowser with many tabs open, I closed all of
them.
Then I returned to task manager... first I noticed this annoying svchost.exe
running again but it disappeared fast.
I also noticed the harddisk light flickering (thankfully).
Then I noticed this rundll32.exe was running again !
This time I took some advice from you guys and had the image path showing on
columns always !
And this time I was able to bust and caught it red-handed ! ;) =D (took a
screenshot ! =D)
Now the investigation can start to what this is.
And yes it's behaviour is the same... it seems to scan *.exe files, why I
don't know.
Here is the screenshot:
Loading Image...
It's command line is:
c:\Windows\system32\rundll32.exe appraiser.dll,DoScheduledTelemetryRun
Bye,
Skybuck.