Is rundll32.exe safe?
Rundll32.exe is a executable file (a program) within Windows. The filename extension .exe denotes an executable file. You should only run executable files from publishers you trust, because executable files can potentially change your computer settings or harm your computer. The free file information forum can help you determine if rundll32.exe is a virus, trojan, spyware, or adware that you can remove, or a file belonging to a Windows system or to an application you can trust.
Rundll32.exe file information
The process known as Run a DLL as an App or Windows host process (Rundll32) or Eine DLL-Datei als Anwendung ausführen or Een DLL-bestand als toepassing starten or Exécuter une DLL en tant qu'application or Ejecutar un archivo DLL como una aplicación or Uob or Windows værtsproces (Rundll32)
belongs to software Microsoft Windows Operating System or Betriebssystem Microsoft Windows or Besturingssysteem Microsoft Windows or Sistema operativo Microsoft Windows or Système d'exploitation Microsoft Windows or Microsoft Windows Operativsystem or Lsz or Microsoft DRM
by Microsoft (www.microsoft.com) or Ocf or judokas négligent or Simple Productions or skb or DODQKDZQR or Microsoft Windows Operating System (windows.microsoft.com) or url.
Description: The original rundll32.exe from Microsoft is an important part of Windows, but often causes problems. rundll32.exe is located in the folder C:\Windows\System32.
Known file sizes on Windows 7/XP are 33,280 bytes (60% of all occurrences), 33,792 bytes and 49 more variants.
The file is a Microsoft signed file. Therefore the technical security rating is 6% dangerous, however also read the users reviews.
Recommended: Identify rundll32.exe related errors
Viruses with the same file name
Is rundll32.exe a virus? No, it is not. The true rundll32.exe file is a safe Microsoft Windows system process, called "Run a DLL as an App".
However, writers of malware programs, such as viruses, worms, and trojans deliberately give their processes the same file name to escape detection. Viruses with the same file name are for instance TROJ_VB.CHK or PE_VIRUT.AV (detected by TrendMicro), and Mal/KeyGen-M (detected by Sophos).
To ensure that no rogue rundll32.exe is running on your PC, click here to run a Free Malware Scan.
How to recognize suspicious variants? If rundll32.exe is located in a subfolder of C:\Windows, the security rating is 24% dangerous. The file size is 44,544 bytes (70% of all occurrences), 34,816 bytes and 25 more variants. The program is not visible. Rundll32.exe is a trustworthy file from Microsoft.
If rundll32.exe is located in a subfolder of "C:\Documents and Settings", the security rating is 55% dangerous. The file size is 24,576 bytes (23% of all occurrences), 120,992 bytes and 12 more variants. The file is not a Windows core file. There is no description of the program. The application starts upon Windows startup (see Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Runonce, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell, C:\Windows\win.ini, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders). The program has no visible window. Rundll32.exe is able to record inputs.
If rundll32.exe is located in the folder C:\Windows, the security rating is 69% dangerous. The file size is 1,264,832 bytes (15% of all occurrences), 135,168 bytes and 13 more variants.
If rundll32.exe is located in a subfolder of "C:\Program Files", the security rating is 48% dangerous. The file size is 33,280 bytes (15% of all occurrences), 33,792 bytes and 8 more variants.
If rundll32.exe is located in the folder "C:\Program Files\Common Files", the security rating is 66% dangerous. The file size is 178,180 bytes (63% of all occurrences), 183,296 bytes or 187,904 bytes.
If rundll32.exe is located in a subfolder of C:\, the security rating is 60% dangerous. The file size is 61,440 bytes (60% of all occurrences), 44,544 bytes or 589,874 bytes.
If rundll32.exe is located in a subfolder of C:\Windows\System32, the security rating is 70% dangerous. The file size is 26,112 bytes (20% of all occurrences), 1,930,240 bytes, 376,851 bytes, 71,168 bytes or 256,512 bytes.
If rundll32.exe is located in a subfolder of Windows Temp folder, the security rating is 56% dangerous. The file size is 310,359 bytes.
If rundll32.exe is located in the Windows Temp folder, the security rating is 54% dangerous. The file size is 20,480 bytes.
If rundll32.exe is located in a subfolder of the "My Files" folder, the security rating is 56% dangerous. The file size is 7,168 bytes.
External information from Paul Collins:
There are different files with the same name:
- "BatInfEx" can run at start up. Displays battery status information on an IBM Thinkpad
- "LoadPowerProfile" definitely not required. Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line
- "Rundll32" definitely not required. Added by the DVLDR TROJAN! Note - this is not the valid "Rundll32.exe" as it's in the Windows\Fonts directory
- "rundll32" definitely not required. Added by the SANKER WORM! Note that the valid "rundll32.exe" resides in C:\Windows\System32 wheras this version resides in C:\Windows
- "TaskMan" definitely not required. Added by the DVLDR TROJAN! Note - this is not the valid "rundll32.exe" as it's in the Windows\Fonts directory
- "UPDATEHOOK": ??
- "Win32 Rundll Loader" definitely not required. Added by the SDBOT.A TROJAN! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:\Windows directory. The version created by this virus is saved in the C:\Windows\System directory
- "Windows DLL Loader" definitely not required.
Important: Some malware disguises itself as rundll32.exe, particularly when not located in the C:\Windows\System32 folder. Therefore, you should check the rundll32.exe process on your PC to see if it is a threat. We recommend Security Task Manager for verifying your computer's security. This was one of the Top Download Picks of The Washington Post and PC World.
Security Task Manager shows all running Windows tasks including embedded hidden functions (e.g. keyboard or browser monitoring, autostart entry). A unique security risk rating indicates the likelihood of the process being potential spyware, malware, keylogger or a Trojan.
Malwarebytes Anti-Malware detects and removes sleeping spyware, adware, trojans, keyloggers, malware and tracking threats from your hard disk. Ideal supplement to Security Task Manager.
SpeedUpMyPC scans, cleans, repairs and optimizes your computer.
ati2evxx.exe iadhide5.dll wdfmgr.exe rundll32.exe mdnsresponder.exe pnkbstra.exe realsched.exe mdm.exe msnlnamespacemgr.dll spoolsv.exe taskman.exe [all]