system
February 23, 2013, 2:28am
1
i found a news in forum that tell a new virus who infected rundll32.exe which is infected windows OS. (it just their opinions)
http://s16.postimage.org/yv4tebi1x/virus_rundll32_exe_RESIZE.jpg
that the rundll32, but it has “.exe” extensions (is it weird?).
http://s12.postimage.org/ushqn980t/virus_rundll32_exe_2_RESIZE.jpg
sometimes it’s happen when shutting down the computer
then, that’s another one.
if the infected computer open task manager. there are proccess rundll32 run as the administrator.
avast not detect this thing as malware. and the another antivirus like kaspersky, norton, avira, even microsoft security essential patch program.
the victims say, this thing make a bad effect to computer
make computer run slow
steal a password and data that come from online session
the worst, can insert DDOS virus.
i want ask for your analysis. is that true???
it’s weird if many antivirus not detect that thing as virus.
sorry if my english bad
note: the picture is take from the forum kaskus.co.id
http://www.kaskus.co.id/thread/50ae031f7d12437c6c00012d/hati-hati--lagi-marak-virus-rundll32exe-os-windows---gak-kedetect-anti-virus/
hey and welcome to the forum.
the file is a windows file that is needed for your operation system.
are you having trouble with it or?
system
February 25, 2013, 11:26am
3
hey and welcome to the forum.
the file is a windows file that is needed for your operation system.
are you having trouble with it or?
yeah, of course…
people say there is a virus who infected it. and the problem, avast can’t detect it as virus
system
February 25, 2013, 12:22pm
4
It’s not a “virus” just a safe file from the system …
polonus
February 25, 2013, 1:32pm
5
Hi spywar,
That is only part of the story. In normal circumstances, yes. But most probably malware just uses rundll32.exe to load itself, and then malware is being detected.
I hope for the victim he can still use his Safe Mode…This should be an issue for a qualified malware removal specialist to look at. Let us wait for his comments,
polonus
Pondus
February 25, 2013, 1:37pm
6
upload suspicious file(s) to www.virustotal.com and test wih 40+ malware scanners (if tested before click new scan)
post link to scan result here for us to see…
system
February 26, 2013, 1:01pm
7
ok, thank you. i know that.
there is a miss understanding here.
dont look the tittle.
i mean, there is a virus who infected the rundll32. then the avast not detect it as virus
Thank you
system
February 26, 2013, 1:09pm
8
File already analysed
This file was already analysed by VirusTotal on 2013-02-25 23:23:13 .
Detection ratio: 0/46
You can take a look at the last analysis or analyse it again now.
ok, here it’s…
the scan result from https://www.virustotal.com/en/
it said no virus??
i upload the rundll32.exe from my system32 folder.
but, are you see something wrong here?? (Look At My SREENSHOOT )
the uninfected file (rundll32) doesn't have extension ".exe"
but the infected file (rundll32) has extension ".exe
are you agree with me??
Pondus
February 26, 2013, 1:28pm
9
the link posted does not go to the scan result… and if scanned before click new scan
when done copy the url in your browser and post here
system
February 26, 2013, 11:03pm
10
Pondus
February 26, 2013, 11:27pm
11
First seen by VirusTotal
2008-05-21 02:27:09 UTC ( 4 years, 9 months ago )
file should be okay…