6.3.9600.16384 (winblue_rtm.130821-1623) 0.64%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.32%
6.2.9200.16384 (win8_rtm.120725-1247) 0.48%
6.2.9200.16384 (win8_rtm.120725-1247) 2.24%
6.1.7600.16385 (win7_rtm.090713-1255) 20.29%
6.1.7600.16385 (win7_rtm.090713-1255) 28.91%
6.1.7600.16385 (win7_rtm.090713-1255) 0.16%
6.0.6000.16386 (vista_rtm.061101-2205) 6.87%
6.0.6000.16386 (vista_rtm.061101-2205) 3.51%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.16%
5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 0.16%
5.1.2600.5512 (xpsp.080413-2105) 27.32%
5.1.2600.5512 (xpsp.080413-2105) 0.16%
5.1.2600.5512 (xpsp.080413-2105) 0.16%
5.1.2600.3311 (xpsp.080212-0004) 0.16%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 8.47%



Windows host process (Rundll32) by Microsoft

Remove rundll32.exe
This is a Windows system installed file with Windows File Protection (WFP) enabled.


rundll32.exe has 16 known versions, the most recent one is 6.3.9600.16384 (winblue_rtm.130821-1623). rundll32.exe is run as a standard windows process with the logged in user's account privileges. By adding a startup entry to the run registry key, the file will be executed when the user logs into Windows. In addition the the run registry key, it also creates a scheduled job to be executed by the Windows Task Scheduler up user login, this is typically done in order to bypass a User Account Control (UAC) prompt. The average file size is about 42.5 KB. The programs ASUS Security Protect Manager, Musicmatch® Jukebox and Crystal Reports ActiveX have been observed as installing specific variations of rundll32.exe. During the process's lifecycle, the typical CPU resource utilization is less than 0.01%, the average private memory consumption is about 11.7 MB with the maximum memory reaching around 12.33 MB. Addionally, typically read and write I/O disk operations is about 35.9 KB per minute for reads and 51.6 KB per minute for writes.


File name:rundll32.exe
Publisher:Microsoft Corporation
Product name:Windows host process (Rundll32)
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\rundll32.exe
Original name:RUNDLL32.EXE.MUI

3% remove
ASUS Security Protect Manager increases system security through the use of Multifactor AuthenticationPolicy. A system administrator can assign multifactor authentication policies to other users and ad...
City of San Jose
1% remove
MAPILab Ltd.
5% remove
Mail Merge Toolkit is a powerful add-in for Microsoft Office 2002 (XP), 2003, 2007, 2010 and 2013 designed to extend the mail merging capabilities in Microsoft Outlook, Microsoft Word and Microsoft Pu...
MicroVideo Software Corp.
7% remove
With Micro Video Capture, you can record video and image from webcam, TV tuner card, digital camera and other capture devices in real time, and all captured video files can be saved as AVI format by u...
Musicmatch Inc.
1% remove
The Jukebox has a skinnable, graphical interface and allows users to manage a catalogue of digital music, as well as CD and stream-based audio. It has a fairly advanced AutoDJ but has been noted as ha...


(Note, the behaviors below are for all versions of rundll32.exe, select a unique version for details.)
Autoplay handlers
Runs under the registry key 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers'
  • Handler name 'VLCPlayVideoFilesOnArrival'
  • Handler name 'VLCPlayVCDMovieOnArrival'
  • Handler name 'VLCPlaySVCDMovieOnArrival'
  • Handler name 'VLCPlayMusicFilesOnArrival'
  • Handler name 'VLCPlayDVDMovieOnArrival'
  • Handler name 'VLCPlayDVDAudioOnArrival'
  • Handler name 'VLCPlayCDAudioOnArrival'
  • Handler name 'NeroAutoPlay2LaunchNeroStartSmart'
  • Handler name 'NeroAutoPlay2DataDisc'
  • Handler name 'NeroAutoPlay2CopyCD'
  • Handler name 'NeroAutoPlay2CDAudio'
  • Handler name 'MSWMEncVCArrival'
  • Handler name 'SonicSCDataTask'
  • Handler name 'SonicSCDataProject'
  • Handler name 'SonicSCCopyDisc'
  • Handler name 'SonicSCCopyCD'
  • Handler name 'SonicSCAudioCDTask'
  • Handler name 'muveeVideoCameraArrival'
  • Handler name 'MSSHAudioDevHandler'
  • Handler name 'RPCDBurningOnArrival'
  • Handler name 'MSWMPBurnCDOnArrival'
  • Handler name 'MSWMDMHandler'
Approved shell extensions
Located in the registry at 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
  • CLSID: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}
Scheduled tasks
  • The task 'SpeedMaxPc Registration3' runs daily in the path 'C:\WINDOWS\Tasks\SpeedMaxPc Registration3.job'
  • The task 'SparkTrust Registration3' runs daily in the path 'C:\WINDOWS\Tasks\SparkTrust Registration3.job'
  • The task 'SpeedyPC Registration3' runs in the path 'C:\WINDOWS\Tasks\SpeedyPC Registration3.job'
  • The task 'EasyShare Registration Task' runs daily in the path 'C:\WINDOWS\Tasks\EasyShare Registration Task.job'
  • The task 'EasyShare Registration RunOnce Task' runs on logon in the path 'C:\WINDOWS\Tasks\EasyShare Registration RunOnce Task.job'
  • The task 'ParetoLogic Registration3' runs daily in the path 'C:\WINDOWS\Tasks\ParetoLogic Registration3.job'
  • Entry path 'C:\WINXP\Tasks\ParetoLogic Registration3.job'
  • Entry path 'C:\WINDOWS\Tasks\SpeedMaxPc Registration3.job'
  • Entry path 'C:\WINDOWS\Tasks\ParetoLogic Registration3.job'
  • Entry path 'C:\WINDOWS\Tasks\SpeedyPC Registration3.job'
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\WINDOWS.0\system32\rundll32.exe'
  • Firewall exception for 'C:\WINDOWS\system32\rundll32.exe'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
  • Login entry path 'C:\WINDOWS\Tasks\EasyShare Registration RunOnce Task.job'
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'NextLive' → C:\WINDOWS\system32\rundll32.exe ",EntryPoint -m l

VersionsAll file variations of rundll32.exe

MD5SHA-1File size
6e0bdfbeeed65b017f2e4c2c910b0520 7c341e51a38b93e4fe329f0f2ef6f0a5fe94cb44 51.5 KB
be1dae43dfbca94fb6b4157c1b16923e aa4e976039bece6dbd242c97a019fd29a6dc63f7 48.5 KB
224f6b374852153c8c24bed141ae3a20 e267a1a7dae5702e18ebdd0d451578a50df5abca 47.5 KB
3a6209ac494296c24c2065cb4392b5f4 c1028a34b22f7fa9a52ffe5de6181bb4dadcce86 50.5 KB
51138beea3e2c21ec44d0932c71762a8 8939cf35447b22dd2c6e6f443446acc1bf986d58 43.5 KB
dd81d91ff3b0763c392422865c9ac12e 963b55acc8c566876364716d5aafa353995812a8 44.5 KB
32ec7c7992948f368a0e000171b234ff 34f8b2bd22d8bcee42b9870b35d7c9ba02b5e3df 70.5 KB
4b555106290bd117334e9a08761c035a 2d77b2ac185828a6300c8838355444279929bcb0 43.5 KB
10446646d128e580c46615338e74e672 2b8096e9746daef534ba03ddad3d9f38e12841c8 45.5 KB
b17657d5fad3c1ec4a594fb2aab67658 b07a7a63c0d6abf5612cad4dca6e89b8c1f3209e 34 KB
f9a942758040b5b60fb6315753ce94c3 42effc11f97e7e8744e216f7a859a12baaeb4b8c 36.5 KB
037b1e7798960e0420003d05bb577ee6 303a90020bf3beaf9acd0ea86487c853636a99a3 32.5 KB
f118dd568838512d2dec06d8a84b3fcf 25f8237921ef60f45f6db52e9865e54ce4e9c7f7 34 KB
b9fd0e2a781257d410ba1e4b6daf95e2 3563a0b3e750594bd7d86309dc8e2c8e589209fd 32.5 KB
081002d8f4176a10bca3a2f93c4d31c2 cf94e4992ae193467e45c5bb80aeb52b49f30caf 32.5 KB
da285490bbd8a1d0ce6623577d5ba1ff c466b4f4c2600fd62fbe943d8049afd0f6606f48 32.5 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 41.31%
Windows 7 Home Premium 21.66%
Windows 7 Ultimate N 8.56%
Windows Vista Ultimate 5.54%
Windows Vista Home Premium 4.79%
Windows Vista™ Home Premium 4.53%
Windows 7 Professional 2.77%
Windows 8 Pro 1.51%
Windows Vista Home Basic 1.26%
Windows 8 1.26%
Microsoft Windows 7 Professional 1.26%
Windows 8.1 1.01%
Windows 8 Pro with Media Center 0.76%
Windows 7 Starter 0.76%
Windows 8.1 Pro 0.50%
Windows 8 Enterprise 0.50%
Windows 7 Home Basic 0.50%
Microsoft Windows XP 0.50%
Windows 8 Single Language 0.25%
Windows 7 Home Premium N 0.25%
Windows Server 2008 Standard 0.25%
22 other Windows OS version

Distribution by countryDistribution by country

United States installs about 54.23% of Windows host process (Rundll32).

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 20.00%
Acer 17.27%
Dell 16.36%
Toshiba 12.73%
Sony 9.09%
Lenovo 9.09%
Alienware 4.55%
ASUS 3.64%
Gateway 1.82%
