Posted by: Krutika on: July 13, 2008
Edit: 5th Dec ‘08: I have dropped in a line to McAfee’s Webimmune service and submitted the symptoms and the manifestations of the virus. Expecting a reply soon.
A request: Please read the whole post carefully and the second post too..Be assured i removed this virus in my PC and you can too..I have edited this post to write this because some readers have responded that they were unable to remove the virus. I have written my experience here with the rundll32.exe virus and the steps i took to remove it. I will try to help you in case this doesnt work. Good Luck!
FOR SOFTWARE ALSO READ: How To Remove Virus Affecting rundll32.exe: Part 2
HAS THE ICON OF rundll32.exe FILE TURNED INTO A PAGE TYPE ICON? THEN READ ON..
First, The Story: I am working on my project work at ISRO,Ahmedabad. I was allotted a PC which was relatively new and the company guys who maintained the PC had installed Windows Server 2003 OS with NO anti virus software..Can you believe that?? Some trainees worked on the PC for two months before me but none of them bothered to install anti-virus software.The very next day i brought my McAfee Setup from my home PC.McAfee ROCKS! I tried to install it but i got a FEAD error..couldnt figure it out then. I tried to install Adobe Reader 8 and got the same error. Then finally i got AVAST Server Edition from a friend. But every anti-virus software is as good as its updates.
So finally i was stranded in a world full of viruses! Some days back when i booted the PC in the morning, it showed all the following signs of virus:
I tried to click the existing shortcuts and got an APPLICATION ERROR: Coudnt find C:\Windows\system32\rundll32.exe
Try creating new shortcut: same error..
My Computer> Properties> Same error
Add-Remove Programs>Same error
Help and Support>Same error ..that meant i couldnt restore it too
I was really scared.It meant i couldnt install any new anti virus or anything else..nor could remove.
The only solution in distant horizon appeared to be the one horrible word – FORMAT..I hate this.
I was just wondering since how come the virus showed up suddenly.I had not inserted any pen drive that day.Then i remembered. Its my habit to HIBERNATE. I rarely SHUT DOWN my PC.The previous day in a hurry, i had not allowed it to hibernate properly and so it restarted next day instead of resuming windows.
SO THE SYMPTOMS:
Check this file C:\Windows\system32\rundll32.exe
It is an application so it should have the usual app symbol. But now the virus had turned its icon into a
page. See the image
WHAT I DID TO REMOVE THE VIRUS??
1. There exists a copy of all the dlls in the following location: find a copy o f rundll32.exe here
C:\windows\system32\dllcache
I found one and its size was approx 68 kb .As seen in image, the size of infected files is 32.5 kb.
I copied it and pasted to replace the infected files and within seconds my copied file’s icon got changed too.
SO I figured out that some file was continuously running in the background to modify these files.
2. So i searched( thankfully search was not disabled) for files modified, created and accessed the day before.
Paying particular attention to the files modified, created and accessed in windows folder.
I found certain files and folders satisfying the criteria. I was not sure what they did. When i right clicked them, the properties showed UNKNOWN APPLICATION. So i was pretty confident that these much be the virus related files.
I cut and pasted the following folders: (so that if something malfunctions and it doesnt turn out to be the virus..DONT REMOVE THEM>>INSTEAD CUT AND PASTE IN LOCATION OTHER THAN WINDOWS..better still in another drive altogether)
C:\Windows\system32\ NTMS DATA ( FOLDER)
C:\Windows\system32\DRIVERS\ETC ( FOLDER)
C:\Windows\system32\FNTCACHE.DAT (FILE)
3. Then i created a shortcut in system32 folder itself and gave the path to the unaffected DLL file..( creation of shortcut was disabled only on desktop)
I m not sure which of these worked. But after carrying out all these steps ..
I m not saying that the files i suspected are viruses.THey may be some files but they had been modified and so i moved them to another location.
It worked for me though..GREAT RELIEF
Like everyone i first searched up the matter but dint find any useful information except something like HIJACK which was pretty advanced stuff and i dint want to find myself trying to revive the PC instead of doing my project coding.So i tried some real BASIC STEPS .I hope this is helpful for you.
And yes do drop me a comment on whether this works or not.
EDIT: In response to confused’s comment:
Please see the following screenshot which clearly shows how rundll32.exe file should look like. An exe file should have an application icon not a page icon.
HELP ME HELP OTHERS.
[...] I have been featured on the home page in the HOW TO department for my post HOW TO REMOVE VIRUS AFFECTING RUNDLL32.EXE .. [...]
[...] work around solution forthe virus affecting system file rundll32.exe without any antivirus at hand: How To Remove Virus Affecting rundll32.exe: Part 1 and felt that there was the need for a permanent [...]
hey buddy!!! i am facing the same issue to which you have offered solution but the irony being that the file in the dll cache folder also shows page icon and is of same size i.e 32.5 kb…any solutions to this now… and one thing more.. i am using genuine… norton endpoint protection and i have also tried mcafee enterprise edition 8.5i….but these cannot catch this virus…
I have this same problem, the dllcache has a 32.5 kb one as well, the steps you listed didn’t seem to work…
thats it, man
I have this same problem. The dll cache folder also shows page icon and whenever I restore both from Windows CD it is immediatly overwritten by the infected file. Even if I expand rundll32.exe to some other folder it gets infected.
Also can’t install several programs, this isn’t detected by any anti-spyware, IE crashes often.
I first noticed this when I couldn’t use the “rundll32.exe sethibernate” shotcut that I use to hibernate.
The solution of “Spyware Terminator” described in part 2 doesn’t detect anything!!
Can you send me a fresh copy of rundll32.exe . I don’t have this. It also infected in my dllcache .
Thanks,
Hi. I tried out your steps but all the rundll32.exe files for XP I found is not 68 KB nd they all have the page icon. Everything iss infected even the ones in the dll cache. I tried looking on the net but I still did not get any proper result. My Pc comes pre-installed with XP so I don’t have the installer disk.
Not to impose; but could you kindly send me a copy of your rundll32.exe. Also, if you have some spare time may i ask if you could compress the file in a zip format so that hopefully after downloading; it doesn’t get infected again.
Thanks in advance and I’ll owe you a debt of gratitude.
Ann
Hi kir,
My files are also affected. rundll32.exe in the other folder also has been affected. As Ann said, can you please zip it and send to me?
Thanks much
HI plz help me my system has very slow becaus registry virus so how
can remove that any can help me thanks
rundll32.exe is an executable file not a dll so it does not have the app symbol. also the correct size of that file should be 32.5 kb
Second that. Are u sure this is correct?
I expanded the file from the windows xp install disk from an xp computer and also a vista one. Both results show the following.
rundll32.exe – XP(Dell Restore CD)
31kb (size on disk = 32.0kb)
Version 5.1.2600.0
Icon picture = PAGE icon(Not app icon!)
It follows that the 32.5kb file found on the computers is merely a different version.
rundll32.exe – Vista (Already installed on Hardrive)
43.5 (size on disk = 44.0kb)
Version 6.0.6000.16386
Icon picture = PAGE icon(Not app icon!)
Are you sure that the original file should be 68kb?? And that the icon is supposed to be app??
It is unlikely that the newly expanded file is immediate infected on both computers. If this is true, this means that both of the computers(vista and xp) are infected but instead, none of them shows sign of “multiple” rundll in the task manager and the control panel stuff works fine.
The control panel error only appears on another laptop, sadly with similar rundll32.exe
I hope that this is the case of misdiagnosis. Please revert!
thanks for commenting!
actually i have tried expanding the rundll32.exe from the original installation cd.
I believe immediate infection occurs.
Because i have seen original uninfected rundll32.exe file and it is an application icon. Now whichever PC or laptop you look, you will see a page icon. It is so widespread i wonder why nobody is alarmed. MY solution sadly doesnt work for all. It has woorked for some. It didnt work for others.
In my case i came to know about the problem in 5 minutes and solved it in about 2 hours.
You do any later and you fresh copy in dllcache would be infected too..In some cases i have seen that the virus hides the ‘dllcache’ folder itself..!
Thx for replying!
I doubt that the virus is that robust.. like i said, I expanded the same file in windows vista and in came to the exact size as that done on XP. To do that, the “vista virus” has to differentiate XP/Vista cd(replace the expanded file appropriately) and also alter the created/modified data attributes.
This might be true because the infected laptop has many system files that were “edited/created” on the same date i.e 8/4/2002 . One of which is the control panel .ico files. I think such a widespread compromise can only be fixed fully by reformatting, which I did but this time installing linux.
I just hope this is not the case for the other computers.
Just to confirm, can u upload the properties for the file opened on windows explorer? Anyway, I don’t think fixing this is as easy as replacing the rundll32.exe file. Other files are perhaps impossible to find since the time attributes seem to be messed up.
The weird thing is that these computers do not exhibit the symptoms mentioned.
I have the similar problem, in taskmanager there are 100’s of rundll32.exe process running, it consumes lots of memory & makes the system slow. donno whether it is a virus or system process.
There will be a folder ‘Prefetch’ in system32
C:\Windows\system32\Prefetch (Folder)
Inside that folder there will be some files in the name of ‘RUNDLL32.EXE’ delete all the files in that name. I hope this works, it worked for me.
i LOOKED AT THE FILES LISTED ABOVE AND not only looked at the date modifie, but I right clicked on the bar and looked the date created. The only one that was newly created ( as in 06/11/09) was the C:\Windows\system32\FNTCACHE.DAT (FILE)!
Now… I haven’t powered down my computer yet. I am about to, but I wanted to let you all know that is what I did and am hopeful that is the damnable file that is causing all the havoc for us all. I will come back and repost. IF…. i haven’t “deleted” a functioning piece of the windows process.
In the meantime, someone google: FNTCACHE.DAT (FILE) and the purpose… and let us all know what it is.
I will chime in, once i’m back online
Peace
HARK
Alright so can someone confirm that i do have the rundll32 virus like the file is a page the size is same as the posted virus size but i only have one rundll32 in task manager and also when in system32 i cant find the prefech (folder) or the dllcashe (folder) oh and in the dllcashe folder there is no rundll32 backup at all
i have the same problem that of rindll32.exe but there is no dll cache folder in my system 32
what to do now??
i cant even copy or paste nything
plz help!
plz
i am facing the same problem and the rundll32.exe is about 52.5kb.i did run my computer from ubuntu and fibd this file in both location as u specified.but the problem is the size.and it is infecting my windows operatin system.so what to do now?
please help me to get rid of this.
Regards
Aryan
just so you know I attempted to replace my friends Windows XP Home systems rundll32.exe with the one you said would be in driver cache. There is no driver cache to speak of. Furthermore the corrupted run is 32.5kb. So I downloaded a new one to replace it, and low and behold within 5 seconds of pasting the new one in. Whatever is in his computer overwrote it and changed it to 32.5kb and switched it from an application to a page file icon
im about to say screw it and just format.
To everyone who haves the page icon:
The page icon is normal.
I’ve checked all my pc’s (5) and they all had the page icon
Don’t be worried people!
hi, i also have the virus, although when i went to the dllcache folder and searched for the rundll file. THe infected file is 51kb, and the one in the dllcache file is also 51kb and also a page icon. What do i do now?
Although Gold Sparrow said not to worry ifthe icon is a page, i know for sure mine is a virus because of the symptoms (applications like burning cds doesnt work and you can’t remove/change programs). And it doesn’t allow me to install anti-virus programs.
Is there any way without re-formatting because I have ALOT of important files i have not backed-up yet
hi
my computer is affected by rundll32
when i connect the any removable media to pc . that exe and auto run file get copy in that removable media please help me ………..,
hello…my computer is also affected by RUNDLL virus…
i only scan and heal it with AVG Anti-Virus..
Thank god..then it was gone already..
July 17, 2008 at 3:35 am
Nice post.
To stop unwanted programs from running in the background on your pc just go to Start > Run > then type “msconfig”, click ok, click the “Startup” tab. You can now uncheck whatever programs you dont want to startup with windows. Usually there’s alotta crap there which you dont want slowing your pc down.