Solved! Use RUNDLLL32.EXE (Backdoor RBot) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

RUNDLLL32.EXE – Backdoor RBot removal

File MD5 Virus Alias
RUNDLLL32.EXE 5cdf5246aada7c3829efdf4551f8acc5 Backdoor RBot
RUNDLLL32.EXE 5cdf5246aada7c3829efdf4551f8acc5 Trojan Agent

RUNDLLL32.EXE size: 94720 bytes
RUNDLLL32.EXE hash: 5CDF5246AADA7C3829EFDF4551F8ACC5

Created files:

%SysDir%\rundlll32.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\windows updatess: rundlll32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\windows updatess: rundlll32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\windows updatess: rundlll32.exe
HKLM\System\CurrentControlSet\Services\SYSTEMS\Type: 20000000
HKLM\System\CurrentControlSet\Services\SYSTEMS\Start: 02000000
HKLM\System\CurrentControlSet\Services\SYSTEMS\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\SYSTEMS\DisplayName: windows updatess
HKLM\System\CurrentControlSet\Services\SYSTEMS\ImagePath: “%WinDir%\System32\rundlll32.exe” -netsvcs
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\windows updatess: rundlll32.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\windows updatess: rundlll32.exe

Detected by UnHackMe:

RUNDLLL32.EXE
Default location: %SYSDIR%\RUNDLLL32.EXE

Dropper information:
MD5: 5cdf5246aada7c3829efdf4551f8acc5
File size: 94720 bytes

Leave a Reply