CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]rundll.exe question

 
Post new topic   Reply to topic       All -> FavForums -> Windows NT/2000/2003/XP [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
angus49

Corporal
Corporal


Joined: Jul 21, 2006
Posts: 57
Location: Hudson, FL

PostPosted: Sun Jan 06, 2008 3:04 pm    Post subject: rundll.exe question
Reply with quote

I have rundll32.exe in my system32 directory. It has just a blank icon. Legit or possible virus. Any help greatly appreciated.

Ed


_________________
"The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
Back to top
View users profile Send private message
John B.

1st Responder


Joined: Dec 03, 2006
Posts: 843
Location: Netherlands
1st Responders

PostPosted: Sun Jan 06, 2008 3:25 pm    Post subject:
Reply with quote

Hi angus,

You could upload the file to VirusTotal to check it for malicious code:

Quote:
Visit Virustotal

  • Click the Browse... button
  • Navigate to the file
  • Click the Open button
  • Click the Send button
  • Copy and paste the results back here please.


Greets, John.


_________________
Trained by MalWare Removal

Proud member of ASAP - Alliance of Security Analysis Professionals

Proud member of UNITE - Unified Network of Instructors and Trusted Eliminators
Back to top
View users profile Send private message
k027

Special Response Team
Guest Forums Host
Guest Forums Host

Joined: Aug 25, 2003
Posts: 8519

1st Responders SRT

PostPosted: Sun Jan 06, 2008 3:26 pm    Post subject:
Reply with quote

That file is usually a part of Windows:

http://windowsxp.mvps.org/rundll32.htm

It might also be malware:

http://www.liutilities.com/products/wintaskspro/processlibrary/rundll32/

The only way to determine whether your computer has malware is to check for it. Try working through the MRP:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview

Back to top
View users profile Send private message
angus49

Corporal
Corporal


Joined: Jul 21, 2006
Posts: 57
Location: Hudson, FL

PostPosted: Sun Jan 06, 2008 3:32 pm    Post subject:
Reply with quote

John,
Just copy and then paste the file at virustotal?


_________________
"The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2758
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Sun Jan 06, 2008 3:35 pm    Post subject:
Reply with quote

No. Follow the directions above. You have to upload the file.

Copy and paste the results of the scan here.

Hope this helps.


_________________
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
Back to top
View users profile Send private message
angus49

Corporal
Corporal


Joined: Jul 21, 2006
Posts: 57
Location: Hudson, FL

PostPosted: Sun Jan 06, 2008 3:45 pm    Post subject:
Reply with quote

Here are the results from Virustotal.

MD5: da285490bbd8a1d0ce6623577d5ba1ff
Date: 12.15.2007 03:28:31 (CET) [>22D]
Results: 1/32
Permalink: analisis/2d375b7def0914fffd9d35369281650f


_________________
"The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
Back to top
View users profile Send private message
John B.

1st Responder


Joined: Dec 03, 2006
Posts: 843
Location: Netherlands
1st Responders

PostPosted: Sun Jan 06, 2008 4:00 pm    Post subject:
Reply with quote

That's the 'foot' of the log. There should be a list above it telling which Anti-Virus programs detected what.


_________________
Trained by MalWare Removal

Proud member of ASAP - Alliance of Security Analysis Professionals

Proud member of UNITE - Unified Network of Instructors and Trusted Eliminators
Back to top
View users profile Send private message
angus49

Corporal
Corporal


Joined: Jul 21, 2006
Posts: 57
Location: Hudson, FL

PostPosted: Sun Jan 06, 2008 4:13 pm    Post subject:
Reply with quote

Nothing else on the page. As a matter of fact, ever time I try to use the scroll bar on the page it jumps me back to your tab.


_________________
"The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
Back to top
View users profile Send private message
angus49

Corporal
Corporal


Joined: Jul 21, 2006
Posts: 57
Location: Hudson, FL

PostPosted: Sun Jan 06, 2008 4:15 pm    Post subject:
Reply with quote

Just found it by clicking a link.

File rundll32.exe received on 12.15.2007 03:28:31 (CET)
Current status: finished

Result: 1/32 (3.12%)
Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - -
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - -
ClamAV - - -
DrWeb - - -
eSafe - - -
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - -
F-Prot - - -
F-Secure - - -
Ikarus - - -
Kaspersky - - -
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - -
Panda - - -
Prevx1 - - -
Rising - - -
Sophos - - -
Sunbelt - - -
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - BlockReason.0
Additional information
MD5: da285490bbd8a1d0ce6623577d5ba1ff


ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.


_________________
"The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
Back to top
View users profile Send private message
John B.

1st Responder


Joined: Dec 03, 2006
Posts: 843
Location: Netherlands
1st Responders

PostPosted: Sun Jan 06, 2008 6:27 pm    Post subject:
Reply with quote

Hi Ed,

The results showed that 1/32 Anti-Virus programs that scanned the file thought it is infected. The program isn't among the best known programs and so there's a low chance that it isn't infected.

There's a low chance it is infected, anyway, because I think I've never seen rundll32.exe getting infected. My rundll32.exe file also shows a 'blank page'.

If you want to check the file even more you can open 'My Computer'. Go to the right folder (SYSTEM32) and right-click on 'rundll32.exe'. Now choose for 'Properties' and check when it was last editted. Mine was in August 2004 (it depends on when you installed the OS). You can also check the filesize, mine is 33kb.

Greets, John.


_________________
Trained by MalWare Removal

Proud member of ASAP - Alliance of Security Analysis Professionals

Proud member of UNITE - Unified Network of Instructors and Trusted Eliminators
Back to top
View users profile Send private message
angus49

Corporal
Corporal


Joined: Jul 21, 2006
Posts: 57
Location: Hudson, FL

PostPosted: Sun Jan 06, 2008 8:26 pm    Post subject:
Reply with quote

Thanks John. The one hit on the list is probably a false positive.

My file is Microsoft v.5.1.2600.2180, 2/28/2006, 32.5Mb.


_________________
"The only thing necessary for the triumph of evil is for good men to do nothing" Edmund Burke
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Windows NT/2000/2003/XP All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer