What is rundll32.exe?
rundll32.exe is a legitimate process file that is responsible for running all DLL files and placing them in proper memory libraries. It is associated with Windows Operating System and developed by Microsoft Corporation. It is typically located in C:\Windows\System32.Malware programmers create virus files and name them after rundll32.exe with an aim to spread malicious codes on the internet.
rundll32.exe runs and distributes various DLL within the memory of the file system controlling the loading and running of DLL files. It runs the core function itself and it is considered as Command line Application. Its memory usage is low. The rundll32.exe uses 33280 bytes worth of RAM resources.
How to check if your computer is infected with rundll32.exe malware?
Keep an eye for the following symptoms to see if your PC is infected with rundll32.exe malware:
- Internet connection fluctuates
- rundll32.exe takes too much CPU space
- PC slows down significantly
- Browser automatically redirects to some irrelevant websites
- Unsolicited ads and popups starts appearing
- Screen freezes constantly
- PHP:GENERIC:07
- PHP:MAILER:33
- Website Malware Directory
- Check Site Security
- Website Malware Removal
- Website malware fix
| No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | N/A | Executable | aafa69b49212690a 3d84a16263b33297 47854a2c |
c1ae8b8fa8e79699 c437c5d78438425d |
Backdoor.Win 32.Poison.as |
No | N/A | N/A | United States |
N/A |
| 2 | Корпорация Майкрософт | Executable | 898f767d4970ef5d d0d866862884242c 430994b8 |
8c08c0193e69d000 c7a628553c9f89de |
Virus.Win32. Sality.gen |
No | 5.1.2600.2 180 (xpsp_sp2_ rtm.040803 -2158) |
5.1.2600.2 180 |
Ukraine |
N/A |
| 3 | Microsoft Corporation | Executable | 6901749943f19f86 89c36af6b62c12ee c0bd2f9b |
68d9745f64215854 8d543d7fc70e46fe |
Virus.Win32. Virut.CE |
No | 6.1.7601.2 3755 (win7sp1_l dr.170330- 0600) |
6.1.7601.2 3755 |
156.207.88.166/32 |
N/A |
| 4 | N/A | Executable | 6e63e09d9ef76670 13b85c28aba30e7b a84a9d53 |
4e40c5bdb6d1670b e2a1e30c04bc0bd7 |
Backdoor.Win 32.Poison.as |
No | N/A | N/A | 37.212.17.164/32 |
N/A |
| No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
|---|---|---|---|---|---|---|---|---|
| 1 | Microsoft Corporation | Executable | cebc439f2a308029 b78bd949f0d1718e c413c97e |
180f801aeb40e227 293ad194904ad32b |
No | 4.00 | 4.00 | United States |
| 2 | Microsoft Corporation | Executable | 2576c63f45fbe13d bdc619c39124fade 94e002d0 |
100f56a73211e0b2 bcd076a55e6393fd |
No | 10.0.19041 .3636 (WinBuild. 160101.080 0) |
10.0.19041 .3636 |
United States |
| 3 | N/A | Non-executable | 18ed02b12da44541 c5c05dd0c4484305 5b8d11dc |
ef1d576d3d6973ee 95b684c38b38bc1b |
No | N/A | N/A | United States |
| 4 | Microsoft Corporation | Executable | 84ddb2b3d1158485 b2b66867ca945293 0a258edd |
44b041922105e01b fd0d096123f7d312 |
No | 10.0.19041 .1 (WinBuild. 160101.080 0) |
10.0.19041 .1 |
United States |

United States
Ukraine
156.207.88.166/32
Taiwan
Russian Federation
Egypt
Vietnam
Pakistan
Algeria
