rundll32.exe

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Microsoft Windows’.
MD5:
19d35e8232aeeb4932f9ef9b69232695

SHA-1:
b2b6ab0fbf5b5bc8f49a6ebef409babf1f4502e7

SHA-256:
7970e386596807bf0eea0933281e52caf94f58f70578980a50a17ad1ff4db71e

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/1/2025 8:24:22 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.10181624-6
0.98/23207

File size:
736.4 KB (754,121 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\microsoft\office\rundll32.exe

File PE Metadata
Compilation timestamp:
1/18/2011 8:14:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x7ADD4

Entry point:
88, FE, 68, 5B, 69, 6E, 00, 52, C7, C1, 9B, 74, FC, BA, EB, 03, FF, CA, 46, 0F, AF, D0, 0F, B6, F7, F3, 85, C3, 81, FD, 23, 47, 00, 00, C6, C4, 8B, 3C, 05, 68, FE, E4, EB, 00, 51, FF, CE, 8A, C7, 31, FB, 8B, FD, E8, 10, 00, 00, 00, 89, F5, 01, EF, 89, FE, 85, FF, 8A, D0, 81, F9, 75, 56, 00, 00, 0F, AF, FE, 0F, AF, D7, 89, C5, 85, EA, 8A, D1, 8B, FF, 0F, B6, EF, C7, C2, 9B, 76, 4D, A5, 75, 03, 42, 0B, F3, 8B, DF, 02, D4, 8D, 2D, F8, 8B, 50, 56, 0F, B6, F2, EB, 02, 29, D5, 53, 10, F6, 01, F5, 58, 76, 04, 86...
 
[+]

Entropy:
6.8515

Code size:
556.5 KB (569,856 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Microsoft Windows

Command:
C:\users\{user}\appdata\roaming\microsoft\office\rundll32.exe


Scan rundll32.exe - Powered by Reason Core Security