| View previous topic :: View next topic |
| Author |
Message |
angus49
Corporal

 Joined: Jul 21, 2006 Posts: 57 Location: Hudson, FL
|
Posted: Sun Jan 06, 2008 3:04 pm Post subject: rundll.exe question |
|
|
I have rundll32.exe in my system32 directory. It has just a blank icon. Legit or possible virus. Any help greatly appreciated.
Ed _________________ "The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
|
|
| Back to top |
|
 |
John B.
1st Responder
 Joined: Dec 03, 2006 Posts: 843 Location: Netherlands
|
Posted: Sun Jan 06, 2008 3:25 pm Post subject: |
|
|
Hi angus,
You could upload the file to VirusTotal to check it for malicious code:
| Quote: | Visit Virustotal
- Click the Browse... button
- Navigate to the file
- Click the Open button
- Click the Send button
- Copy and paste the results back here please.
|
Greets, John. _________________ Trained by MalWare Removal
Proud member of ASAP - Alliance of Security Analysis Professionals
Proud member of UNITE - Unified Network of Instructors and Trusted Eliminators
|
|
| Back to top |
|
 |
k027
Special Response Team Guest Forums Host

 Joined: Aug 25, 2003 Posts: 8519
|
|
| Back to top |
|
 |
angus49
Corporal

 Joined: Jul 21, 2006 Posts: 57 Location: Hudson, FL
|
Posted: Sun Jan 06, 2008 3:32 pm Post subject: |
|
|
John,
Just copy and then paste the file at virustotal? _________________ "The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
|
|
| Back to top |
|
 |
mrsugg
Special Response Team Premium Member
 Joined: Aug 15, 2006 Posts: 2758 Location: Somewhere, over the rainbow...
|
Posted: Sun Jan 06, 2008 3:35 pm Post subject: |
|
|
No. Follow the directions above. You have to upload the file.
Copy and paste the results of the scan here.
Hope this helps. _________________ "We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
|
|
| Back to top |
|
 |
angus49
Corporal

 Joined: Jul 21, 2006 Posts: 57 Location: Hudson, FL
|
Posted: Sun Jan 06, 2008 3:45 pm Post subject: |
|
|
Here are the results from Virustotal.
MD5: da285490bbd8a1d0ce6623577d5ba1ff
Date: 12.15.2007 03:28:31 (CET) [>22D]
Results: 1/32
Permalink: analisis/2d375b7def0914fffd9d35369281650f _________________ "The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
|
|
| Back to top |
|
 |
John B.
1st Responder
 Joined: Dec 03, 2006 Posts: 843 Location: Netherlands
|
Posted: Sun Jan 06, 2008 4:00 pm Post subject: |
|
|
That's the 'foot' of the log. There should be a list above it telling which Anti-Virus programs detected what. _________________ Trained by MalWare Removal
Proud member of ASAP - Alliance of Security Analysis Professionals
Proud member of UNITE - Unified Network of Instructors and Trusted Eliminators
|
|
| Back to top |
|
 |
angus49
Corporal

 Joined: Jul 21, 2006 Posts: 57 Location: Hudson, FL
|
Posted: Sun Jan 06, 2008 4:13 pm Post subject: |
|
|
Nothing else on the page. As a matter of fact, ever time I try to use the scroll bar on the page it jumps me back to your tab. _________________ "The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
|
|
| Back to top |
|
 |
angus49
Corporal

 Joined: Jul 21, 2006 Posts: 57 Location: Hudson, FL
|
Posted: Sun Jan 06, 2008 4:15 pm Post subject: |
|
|
Just found it by clicking a link.
File rundll32.exe received on 12.15.2007 03:28:31 (CET)
Current status: finished
Result: 1/32 (3.12%)
Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - -
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - -
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - -
F-Prot - - -
F-Secure - - -
Ikarus - - -
Kaspersky - - -
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - -
Panda - - -
Prevx1 - - -
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - BlockReason.0
Additional information
MD5: da285490bbd8a1d0ce6623577d5ba1ff
ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware. _________________ "The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
|
|
| Back to top |
|
 |
John B.
1st Responder
 Joined: Dec 03, 2006 Posts: 843 Location: Netherlands
|
Posted: Sun Jan 06, 2008 6:27 pm Post subject: |
|
|
Hi Ed,
The results showed that 1/32 Anti-Virus programs that scanned the file thought it is infected. The program isn't among the best known programs and so there's a low chance that it isn't infected.
There's a low chance it is infected, anyway, because I think I've never seen rundll32.exe getting infected. My rundll32.exe file also shows a 'blank page'.
If you want to check the file even more you can open 'My Computer'. Go to the right folder (SYSTEM32) and right-click on 'rundll32.exe'. Now choose for 'Properties' and check when it was last editted. Mine was in August 2004 (it depends on when you installed the OS). You can also check the filesize, mine is 33kb.
Greets, John. _________________ Trained by MalWare Removal
Proud member of ASAP - Alliance of Security Analysis Professionals
Proud member of UNITE - Unified Network of Instructors and Trusted Eliminators
|
|
| Back to top |
|
 |
angus49
Corporal

 Joined: Jul 21, 2006 Posts: 57 Location: Hudson, FL
|
Posted: Sun Jan 06, 2008 8:26 pm Post subject: |
|
|
Thanks John. The one hit on the list is probably a false positive.
My file is Microsoft v.5.1.2600.2180, 2/28/2006, 32.5Mb. _________________ "The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
|
|
| Back to top |
|
 |
|
|