rundll32mgr.exe threat report

MD5 a8245f71e4e4aff10e574300abd2bcc2
Latest seen 2021-01-10 11:22:20 (5 years ago)
First seen 2017-05-28 12:01:51 (8 years ago)
Size 354 KB
Publisher Avira GmbH

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Agent. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Agent
Recommended action
Scan and remove
Last analysis
2021-01-10 11:22:20 (5 years ago)
File hash
a8245f71e4e4aff10e574300abd2bcc2
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Agent.

Timeline

First seen 2017-05-28 12:01:51 (8 years ago); latest analysis 2021-01-10 11:22:20 (5 years ago).

Publisher context

Company metadata: Avira GmbH.

Aliases

This hash has appeared under multiple file names, which can happen with repackaging, bundling, or deliberate renaming.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

rundll32mgr.exe is a Windows file recorded in the ThreatInfo database. The reported company name is Avira GmbH. The current detection status is Trojan.Agent, based on the latest analysis from 2021-01-10 11:22:20 (5 years ago).

If rundll32mgr.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Agent.

Company Name: Avira GmbH
MD5: a8245f71e4e4aff10e574300abd2bcc2
Size: 354 KB
First Published: 2017-05-28 12:01:51 (8 years ago)
Latest Published: 2021-01-10 11:22:20 (5 years ago)
Status: Trojan.Agent (on last analysis)
Analysis Date: 2021-01-10 11:22:20 (5 years ago)
rundll32mgr.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%programs%\startup
%programfiles%\nhatcuongsoft\proerp
%programfiles%\microsoft
%programfiles%\droid4x
%programfiles%\google\chrome\application
%programfiles%\etcrbtbi
%localappdata%\temp
%localappdata%\s-1-5-31-1286970278978-5713669491-166975984-320\rotinom\recycler\s-5-5-57-2128253284-0146111087-426580867-6241
%desktop%\rodrigo\recycler
%programfiles%\iobit\driver booster

ThreatInfo has observed rundll32mgr.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

nnnurpsn.exe
proerpsrvsrvsrvsrvsrvsrvsrvsrvsrvmgr.exe
desktoplayerSrvSrvmgr.exe
proerpsrvsrvsrvsrvsrvsrvsrvmgr.exe
proerpsrvsrvsrvsrvsrvsrvsrvSrvmgr.exe
proerpsrvsrvsrvsrvsrvmgr.exe
proerpsrvsrvsrvsrvsrvsrvmgr.exe
proerpsrvsrvsrvmgr.exe
droid4xservicesrvsrvmgr.exe
desktoplayerSrvmgr.exe
proerpsrvSrvmgr.exe
desktoplayermgr.exe
proerpsrvmgr.exe
chromemgr.exe
proerpsrvsrvsrvSrvmgr.exe
Droid4XPopupsmgr.exe
nlvfugnl.exe
svchost.exe
tbmglwng.exe
jRGpVCPc.exe
JSPGpJPo.exe
VvgylRSL.exe
mHysTiJg.exe
UDkobuyv.exe
WJYQQLIP.exe
iHIAJuFo.exe
xFUKZmFs.exe
MlLqtmAc.exe
EZlKALbY.exe
HPZVIEiO.exe
UMhnJACn.exe
MAoOUJvo.exe
CgOxaaCw.exe
MSoLdKHm.exe
bNCEHfle.exe
PERIueFg.exe
nkIJUUVQ.exe
MLwEdHhc.exe
DmTiihbG.exe
OpKAHVeE.exe
VFlWgnOP.exe
gnsOYoEp.exe
avBDBjZg.exe
XrqSdaAt.exe
IpYmPtcD.exe
tduULiSx.exe
jxTTLfjX.exe
Schedulermgr.exe
slimjetmgr.exe
xbpwabid.exe
Vpnmgr.exe
IEMonitormgr.exe
snuvcdsmmgr.exe
EvernoteClippermgr.exe
Appmgr.exe
PIconStartupmgr.exe
UltraViewer_Desktopmgr.exe
dcomchangemgr.exe
DCSHelpermgr.exe
DriverBoostermgr.exe
IEXPLOREmgr.exe
4G_Servermgr.exe
vsnp2uvcmgr.exe
GoogleUpdatemgr.exe
IDManmgr.exe
idmBrokermgr.exe
UIExecmgr.exe
Skypemgr.exe
spoolsvmgr.exe
PluginAdminExecmgr.exe
BBtalkmgr.exe
GarenaTalkLoadermgr.exe
UpdateManagermgr.exe
LoLmgr.exe
UpdateExmgr.exe
League of Legendsmgr.exe
GarenaMessengermgr.exe
LOLClientmgr.exe
Groundmgr.exe
Flash_toolmgr.exe
FlashToolmgr.exe
patchmgr.exe
Keygenmgr.exe
Miracle Box_Cracked 2.58mgr.exe
rllgsduj.exe
kbdmgr.exe
PotPlayerMinimgr.exe
cnqmgr.exe
DllHostmgr.exe
SVPMgrmgr.exe
kvpncsvcmgr.exe
$RD5NV23.exe
SamsungToolPROmgr.exe
AndroidMTK_Avengersmgr.exe
Infinity Best Nokia By SAHILmgr.exe
Photoshopmgr.exe
Patchmgr.exe
eveedvxw.exe
A0038420.exe
A0037237.exe
A0036052.exe
A0038422.exe
A0036009.exe
A0036201.exe
A0038475.exe
A0038439.exe
A0038421.exe
A0035921.exe
A0037238.exe
A0035916.exe
A0036202.exe
A0036183.exe
A0036053.exe
A0038441.exe
A0038497.exe
A0036182.exe
A0036181.exe
A0038436.exe
A0036020.exe
A0038498.exe
A0035970.exe
Explorermgr.exe
A0036200.exe
A0038474.exe
A0038440.exe
A0035969.exe
A0038435.exe
A0036014.exe
A0036019.exe
A0035968.exe
plugin_hostmgr.exe
uxlnwanc.exe
cmalwrco.exe
UhJXKUeV.exe
arZnabFl.exe
NDOKcmre.exe
wpqdywjw.exe
rukvlrvc.exe
nyedbfsl.exe
xxjmcqlx.exe.Startup
MsiExecmgr.exe
Infinity Best Nokia By M.Waqas Qamarmgr.exe
hyomefbx.exe
adbmgr.exe
7zmgr.exe
fastbootmgr.exe
QSaharaServermgr.exe
Setupmgr.exe
ulsouvnd.exe
rundll32mgr.exe

This hash has been seen with multiple file names. Alternate names can appear when software is updated, copied between folders, packed by an installer, or deliberately renamed to avoid recognition. Compare the exact MD5 above before assuming two names refer to the same file.

60.5%
22.2%
3.4%
3.2%
2.3%
1.6%
1.5%
1.3%
1.0%
0.6%
0.5%
0.3%
0.2%
0.2%
0.2%
0.2%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%

The strongest geographic signal for this file is Belgium with 60.5% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 7 96.4%
Windows XP 2.9%
Windows 10 0.8%

The most common operating system signal for rundll32mgr.exe is Windows 7 with 96.4% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

rundll32mgr.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00001000

PE Sections:

Name Size of data MD5
.text 2048 d923bcd038a517d6c55dd4b32d91aa00
.rdata 2048 a99571fc5348ba72e7bcfa9f3172b25b
.data 89088 094065f7c38c94af61214611179ecb37
.rsrc 13312 456709dde1c09d9c85e562dabc1d8e76
.reloc 72704 50b1503903e92eebddb24e57eec2427b
.text 182784 804d1955d74a12f8f7f001687d813c8d

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: