Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Y#NAME?ZkRunOnceR.exeInternet Security Suite used by ISPs to protect customers against many attacks
X(*)Runwin32API.exe"Homepage hijacker
X(default)"rundll32.exe [path to DLL file]Do98Work"
X98D0CE0C16B1"rundll32.exe D0CE0C16B1 D0CE0C16B1"
X;Rundll[filename]"Added by the PWSLEGMIR.E TROJAN!"
X@RUNDLL.EXE"Added by the SPYBOT-DN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EB"rundll32.exe E6F1873B.DLL D9EBC318C"
UAcronis Popup Blocker"RunDll32.exe [path] Blocker.dll Run"
XAddrPlus3[path] stup.exe [path] Adplus.dll Rundll32"TCent adware"
XAdobeManagerrundtl.exe"Added by the INJECT.IB TROJAN!"
YAdslTaskBar"rundll32.exe stmctrl.dll TaskBar"
NAlcohol.exe AutorunAlcohol.exe"Alcohol 120% - ""a powerful Windows CD and DVD burning software that makes it easy to create backups of DVDs and CDs. In addition
NAME_CSA"rundll32 amecsa.cpl RUN_DLL"
XAOL Instant Messenger dll runtimeMSAOL32dll.exe"Added by the RBOT-ATA WORM!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
XArucer"rundll32 Arucer.dllArucer"
XArucer Dynamic Link Library"rundll32 Arucer.dllArucer"
UASKrundll32.exe [path] ASK.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
?AsusStartupHelpAsRunHelp.exe"Unknown ASUS motherboard utility. What does it do and is it required?"
NATICCCcli.exe runtime"ATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting Windows"
?AudCtrl"RunDll32 AudCtrl.dll RCMonitor"
XAUNPS2"RUNDLL32 AUNPS2.DLL _Run@16"
YAuthentic-ID Toolbar"rundll32.exe [path] ToolbarATL.dll LoadTrayIcon"
UAuto Run Software for Photo FramePhotoManager.exe"Management software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the device"
Xautochk"rundll32.exe autochk.dll_IWMPEvents@16"
Xautochk"rundll32.exe protect.dll_IWMPEvents@16"
NAutoEAAhqrun.exeFor Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
Xautorunautorun.exe"Added by the AUTOM-B WORM!"
Xautorunsxs.exe"Added by the SMALLVBS-A WORM!"
Xautorunwinmain.exeAdded by a variant of the DELF.CNS TROJAN!
XAutoRunallrs.exe"Added by the MUDROP.LJ TROJAN!"
Xautorundemo[path to trojan]"Added by the AGENT-FPX TROJAN!"
XAUTORUN_VALAntiSpyCheck 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
XAUTORUN_VALasc 2.1.exe"AntiSpyCheck rogue spyware remover - not recommended
Xautoupdate"rundll32 DATADX.DLLSHStart"
Xautoupdate"rundll32 SUPDATE.DLLSHStart"
YAVG7_Runavgw.exe"This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts"
XAvptaskrund1132.exe"Added by the AGENT.PKZ TROJAN!"
?AxFilter"Rundll32 AXFILTER.DLL Rundll32"
Xbabeie"rundll32 cnbabe.dll dllstartup"
XBackground Intelligent Transfer Service[path] rundll32.exe"Added by the VB-ZD TROJAN! Note - this is not the legitimate rundll32.exe process
UBatInfEx"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
UBatLogEx"rundll32.exe [path] BatLogEx.DLLStartBattLog"
UBayden SlickRunsr.exe"""SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords)
UBCMHal"rundll32.exe bcmhal9x.dll bcinit"
UBelNotify"rundll32.exe [path] NPBelv32.dll RunDll32_BelNotify"
XBIE"Rundll32.exe [path] BDSrHook.dll Rundll32"
UBLOG"rundll32.exe [path] BatLogEx.DLLStartBattLog"
?Bluetooth HCI Monitor"RunDll32 HCIMNTR.DLLRunCheckHCIMode"
UBluetoothAuthenticationAgent"rundll32.exe irprops.cpl
UBluetoothAuthenticationAgent"rundll32.exe bthprops.cpl
UBMMGAG"RunDll32 [path] pwrmonit.dllStartPwrMonitor"
UBMMMONWND"rundll32.exe [path] BatInfEx.dllBMMAutonomicMonitor"
XBookedSpace"RunDLL32.EXE bs2.dllDllRun"
XBouncer RunStartupbouncer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove
XBridge"rundll32.exe [path] Bridge.dllLoad"
NBroadCamRunbroadCam.exe"BroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone"
XBsx3"RunDLL32.EXE bs3.dllDllRun"
Xbxsx5"RunDLL32.EXE bsx5.dllDllRun"
Xbxxs5"RunDLL32.EXE bxxs5.dlldllrun"
Xcalc"rundll32.exe [path] ntuser.dll_IWMPEvents@0"
Xcalc"rundll32.exe calc.dll_IWMPEvents@0"
XCaptcha7rundll captcha.dll"Added by the TINY.WRE TROJAN!"
NCcdecode"rundll32.exe streamci StreamingDeviceSetup"
Xcesmain.dll"Rundll32.exe [path] cmail.dll Rundll32"
Xcfgmgr51"RunDLL32.EXE cfgmgr51.dllDllRun"
Xcfgmgr52"RunDLL32.EXE cfgmgr52.dllDllRun"
XChansonsMP3"rundll32.exe MSA64CHK.dllDllMostrar"
Xcheckrunelite***32.exe [* = random char]"EliteBar adware"
Xcheckrunelitelsj32.exe"Added by the MULTIDR-ER TROJAN!"
Xchoperunlli32.exe"Added by the QQPASS-U TROJAN!"
XClassesrun_21.exe"""Switch"" premium rate adult content dialler variant"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
?clnwall"rundll.exe setupx.dll InstallHinfSection ..delwall.inf"
NCmaudio"Rundll32 cmicnfg.cpl CMICtrlWnd"
UCmPCIaudio"RunDll32 CMICNFG3.CPL CMICtrlWnd"
?CmUCRRunCmUCReye.exe"Related to Medion Display Information. What does it do and is it required?"
XCnsMin"Rundll32.exe [path] CNSMIN.DLL Rundll32"
UCognizanceTS"rundll32.exe [path] AsTsVcc.dll RegisterModule"
?Compaq Computer Security"Rundll32.exe SECURE32.CPL Service"
XConfiguration Loaderdosrun32.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadermsrun.exe"Added by the AGOBOT-Y WORM!"
XContentDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XControl"rundll32.exe ctrlpan.dll Restore ControlPanel"
XControlPanel"rundll32 internat.dll LoadKeyboardProfile"
XControlPanel"popcorn64.exe rundll.dll LoadMouseProfile"
XControlPanel"popcorn72.exe rundll.dll LoadMouseProfile"
XControlPanel"popcorn320.exe rundll.dll LoadMouseProfile"
XCoolDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XCoolMP3"rundll32.exe MSA64CHK.dllDllMostrar"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
XCPU Watcher"rundll32.exe cpu.dllload"
NCrazyTalk Serve"rundll32.exe CrazyTalk.dll DIIServeMediaFile"
XCTDrive"rundll32.exe drvmod.dllstartup"
XctfnomrundIl32.exe"Added by the LEGMIR-AW TROJAN!"
UCTNMRUNctnmrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
NCTRegRunCTRegRun.exeFor Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
Xdabrun"rundll32.exe dabapi.dllRundll32"
NDeadAIM"rundll32.exe DeadAIM.ocm ExportedCheckODLs"
UDelaydelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computers
UDelayrundelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computers
Xdelsubmit"rundll32.exe advpack.dll DelNodeRunDLL32 submit.exe"
XDescargaBromas"rundll32.exe MSA64CHK.dllDllMostrar"
XDesktop"rundll32.exe msconfd.dllRestore ControlPanel"
XDesktopUpdate"rundll32.exe MSA64CHK.dllDllMostrar"
XDialer"rundll32.exe MSA32CHK.dllReg"
XDisableKeybaord"Rundll32.exe KeyboardDisable"
XDisableMouse"Rundll32.exe MouseDisable"
YDLBTCATS"rundll32 [path] DLBTtime.dll _RunDLLEntry@16"
YDLBUCATS"rundll32 [path] DLBUtime.dll _RunDLLEntry@16"
YDLBXCATS"rundll32 [path] DLBXtime.dll _RunDLLEntry@16"
YDLCCCATS"rundll32 [path] DLCCtime.dll_RunDLLEntry@16"
YDLCDCATS"rundll32 [path] DLCDtime.dll _RunDLLEntry@16"
YDLCFCATS"rundll32 [path] DLCFtime.dll _RunDLLEntry@16"
YDLCGCATS"rundll32 [path] DLCGtime.dll _RunDLLEntry@16"
YDLCICATS"rundll32 [path] DLCItime.dll _RunDLLEntry@16"
YDLCJCATS"rundll32 [path] DLCJtime.dll _RunDLLEntry@16"
YDLCQCATS"rundll32 [path] DLCQtime.dll _RunDLLEntry@16"
YDLCXCATS"rundll32 [path] DLCXtime.dll _RunDLLEntry@16"
YDNE Binding Watchdog"rundll dnes.dll DnDneCheckBindings"
YDNE DUN Watchdog"rundll dnes.dll DnDneCheckDUN13"
XDownloadLegalMusic"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XDownloadsAndMP3"rundll32.exe MSA64CHK.dllDllMostrar"
Udrkly16j"rundll32.exe drkly16j.dll ServiceCheck"
Xdrvupdrundll32 ..drvupd.inf"Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
XEntraOcio"rundll32.exe MSA64CHK.dllDllMostrar"
UERUNT AutoBackupAUTOBACK.EXE"ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots
Xetbrunelit***32.exe [* = random char]"EliteBar adware"
XEtrafficJavaRun.exe"TopMoxie adware"
XExFilter"Rundll32.exe [path] cdnspie.dll ExecFilter"
XExplorerRunconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
?EZNORUNEZNORUN.EXE"Easy Internet related?"
XFastDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
Xfcrunfc.exe"Added by the CAMPURF WORM!"
Xfilename processRundil16.exe"Added by the GAOBOT.ZX WORM!"
UFlingRunfling.exe"Fling - free FTP software from NCH Software"
XForceShow"rundll32.exe QaBar.dllForceShowBar"
XFreeMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
Xfrunderc32xz.exeAdded by an unidentified TROJAN!
Xfstsvc"rundll32.exe fstsvc.dllstart"
Uftutil2"rundll32.exe ftutil2.dll SetWriteCacheMode"
XGames toolbarrundll32.exe [path] tbGame.dll DllShowTB"Topconverting.com/180Search ""Games Toolbar"" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XGddlib"rundll32.exe gddlib.dllstart"
XGetitAll"rundll32.exe MSA64CHK.dllDllMostrar"
XGetMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XGetTheMusic"rundll32.exe MSA64CHK.dllDllMostrar"
Xgfxtray"rundll32 ctccw32.dllfindwnd"
Xgovurarope"Rundll32.exe retasevo.dlls"
XGreatDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
?GsiFinal"rundll32 gspndll.dllpostInstall final"
UGuruNetGuruNet.exe"GuruNet lets you click on any word on your screen to get the relevant information you want"
Xgvagfxjrundll32 ...gvagfxj.dll"Unidentified adware
Xhe3bbcff"rundll32.exe he3bbcff.dllEnableRunDLL32"
Xhe3e3fc4"rundll32.exe he3e3fc4.dllEnableRunDLL32"
Xhelper.dllrundll32.exe [path] helper.dll"CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XHideRun.exeHiderun.exe and svhost.exe and pro.gif"Added by the BOOHOO WORM!"
XHKEYokrunlli32.exe"Added by the QQPASS-U TROJAN!"
XHKLMRunwindowsupdate.exe"Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
XHKLM\Runsvhost.exe"Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
XHP_runnerfront.exe"Added by the SILLYFDC WORM!"
Xicdd7ee6"rundll32.exe icdd7ee6.dllEnableRunDLL32"
Xicddefff"rundll32.exe icddefff.dllEnableRunDLL32"
UICSDCLT"rundll32.exe Icsdclt.dll ICSClient"
XIE Menu Extension toolbarrundll32.exe [path] tbextn.dll DllShowTB"Topconverting.com/180Search ""IEMenuExtension"" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XIE Runtimewini.exe"Added by the PICRATE.B WORM!"
XIE Runtimeswinis.exe"Added by the RBOT-ADZ TROJAN!"
Xiel2cde8"rundll32.exe iel2cde8.dllEnableRunDLL32"
Xielcaabe"rundll32.exe ielcaabe.dllEnableRunDLL32"
UIKLrundll32.exe [path] IKL.dll"IKL surveillance software. Uninstall this software unless you put it there yourself"
XImage"rundll32 [path] [trojan filename]Install"
Ximxecsvbrun70sp4.exe"Added by the AGOBOT.ALA WORM!"
XInfoData"rundll32.exe ********.dllrealset [* = random char]"
XInstant Access"rundll32.exe EGDHTML_1023.dll InstantAccess"
XInstant Access"rundll32.exe eg_auth_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe EGCOMLIB_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe EGCOMSERVICE_****.dll InstantAccess [**** = digits]"
XInstant Access"rundll32.exe p2esocks_****.dll InstantAccess [**** = digits]"
XipruniPY.exe"iProtectYou spyware"
XiSecurity applet"rundll32.exe iSecurity.cplSecurityMonitor"
XJava Runtime Environmentjbuild.exe"Added by the DELBOT-J WORM!"
XJava Runtime Valuerunjava.exe"Added by the RBOT-DDJ WORM!"
XJava Runtimesiexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
Xjmudkve.dll"rundll32.exe jmudkve.dllmzrwkwf"
Ujx_Key"Rundll32 JXKey.dllRundll32Main"
XKavRunsWindll.exe"Added by the TRYNOMA TROJAN!"
XKavSvc******.exe reg_run [* = random char]"Added by the QOOLOGIC TROJAN!"
YKB926239"rundll32.exe apphelp.dll ShimFlushCache"
Xkernctl32"rundll32 kctl32.dll initialize"
XKernelRuntime[path to worm]"Added by the MYTOB-JO WORM!"
Xkeymgrldr"rundll32 setupapi InstallHinfSection... keymgr3.inf"
Uklprun32dll.exe"PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online"
Ukmw_run.exekmw_run.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special features
Xkw3eef76"rundll32.exe kw3eef76.dllEnableRunDLL32"
Nlhttseng"rundll32.exe ..lhttseng.inf RemoveCabinet"
Xli01f948"rundll32.exe li01f948.dllEnableRunDLL32"
Xlibtec"rundll32.exe libtec.dllstart"
NLicCrtlrunservice.exe"Part of the eLicense Copy Protection scheme employed by some software and games. When this service is not running
ULicCtrl"rundll32.exe MMFS.DLL Service"
XLjxrundll32.exe"Added by the LINEAG-ABD TROJAN! Note - this is not the legitimate rundll32.exe process
?LLMODCL2"rundll.exe setupx.dll InstallHinfSection ..LLMODCL2.INF"
Xloadrundll32.exe"Added by the WOWCRAFT TROJAN!"
Xloadrundl132.exe"Added by the LOOKED-CK WORM!"
XLoadhgrundll32.exe"Added by the LINEAG-ABX TROJAN!"
XLoadHTML"rundll32.exe regsvr32.exeMShtmpre"
XloadMecq3rundll32.exe"Added by the LEGMIR-AS TROJAN! Note - this is not the legitimate rundll32.exe process
XloadMefsrundll32.exe"Added by the LEGMIR-JB TROJAN! Note - this is not the legitimate rundll32.exe process
ULoadPowerProfileRundll32.exe powrprof.dll"Power management specifics such as monitor shut-off
XLoadPowerProfileRundll.exe powerprof.dll"Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses ""Rundll.exe"" whereas the uninfected version uses ""Rundll32.exe"""
XLoadPowerProfilerundl.exe"Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
XLoadPowerProfileRundll32.exe"Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has ""powrprof.dll"" appended to the command/data line"
XLoadPowerSchemerundll32.exe powerprof.dll CheckPowerProfile"Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XLoadSIPS"rundll32.exe SIPSPI32.dll SIPSPI32"
XLocal runole servicesrvc32.exe"Added by the SMALL-DP TROJAN!"
XlogonUiInitRundll32.exe rgtndz.dll"Identified as a variant of the Trojan-Clicker.Win32.Agent.bqy malware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""rgtndz.dll"" file is found in %System%"
XLosMejoresMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XLotsOfGames"rundll32.exe MSA64CHK.dllDllMostrar"
XLotsOfJokes"rundll32.exe MSA64CHK.dllDllMostrar"
XLTM2RundlI.exe"Added by the MULTIDRP.BG TROJAN!"
Xltssvc"rundll32.exe ltssvc.dllstart"
XLTT2rundll32.exe"Added by the LINEAGE-BI TROJAN!"
NLwinst Run Profilerlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
YLXBSCATS"rundll32 [path] LXBStime.dll _RunDLLEntry@16"
YLXBTCATS"rundll32 [path] LXBTtime.dll _RunDLLEntry@16"
YLXBUCATS"rundll32 [path] LXBUtime.dll _RunDLLEntry@16"
YLXBXCATS"rundll32 [path] LXBXtime.dll _RunDLLEntry@16"
YLXBYCATS"rundll32 [path] LXBYtime.dll _RunDLLEntry@16"
YLXCCCATS"rundll32 [path] LXCCtime.dll _RunDLLEntry@16"
ULXCDCATS"rundll32 [path] LXCDtime.dll _RunDLLEntry@16"
YLXCECATS"rundll32 [path] LXCEtime.dll _RunDLLEntry@16"
YLXCFCATS"rundll32 [path] LXCFtime.dll _RunDLLEntry@16"
YLXCGCATS"rundll32 [path] LXCGtime.dll _RunDLLEntry@16"
YLXCJCATS"rundll32 [path] LXCJtime.dll _RunDLLEntry@16"
YLXCQCATS"rundll32 [path] LXCQtime.dll _RunDLLEntry@16"
YLXCRCATS"rundll32 [path] LXCRtime.dll _RunDLLEntry@16"
YLXCTCATS"rundll32 [path] LXCTtime.dll _RunDLLEntry@16"
YLXCYCATS"rundll32 [path] LXCYtime.dll _RunDLLEntry@16"
YLXDBCATS"rundll32 [path] LXDBtime.dll _RunDLLEntry@16"
YLXDCCATS"rundll32 [path] LXDCtime.dll _RunDLLEntry@16"
YLXDDCATS"rundll32 [path] LXDDtime.dll _RunDLLEntry@16"
YLXDICATS"rundll32 [path] LXDItime.dll _RunDLLEntry@16"
ULXDJCATS"rundll32 [path] LXDJtime.dll _RunDLLEntry@16"
XMainDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
NMass storage check registry"rundll32.exe MSDServ.dll check registry"
UMBMon"Rundll32 CTMBHA.DLLMBMon"
Nmdac_runoncerunonce.exeAssociated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe".
XMicosoft Data Corerunservice.exe"Added by the IRCBOT.BK WORM!"
XMicrosoftrundll.exe"Added by the RBOT-GSJ WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XMicrosoft (R) Windows DLL Loaderrundll32.exe"Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft 64 Bit Runtime Updaterwupdt64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Config Loadermsrun32.exe"Added by the AGOBOT-DY WORM!"
XMicrosoft DDEs ControlErun.pif"Added by the RBOT-AMU WORM!"
XMicrosoft Dllrunapidll.exe"Added by the RBOT-GRG WORM!"
XMicrosoft Install Shield Servicesrundll64"Added by the RBOT-FSH WORM!"
XMicrosoft JavaVMmsjarun.exe"Added by the RBOT-JW WORM!"
XMicrosoft Rundllwindos.exe"Added by the SDBOT-WF WORM!"
XMicrosoft RuntimeCfgDll32.exe"Added by the RANDEX.BD WORM!"
XMicrosoft Servicerundll.exe"Added by the POPO-A WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XMicrosoft Updaterundll32.dll"Added by the CIADOOR.GN BACKDOOR!"
XMicrosoft Update 32rundll32.exe"Added by the RBOT.AIE BACKDOOR! Note that this BACKDOOR modifies the file rundll32.exe
XMicrosoft Update Modulerundll24.exe"Added by the RBOT-PS WORM!"
XMicrosoft Windows Services Edtdllrun32.exe"Added by the RBOT-GAF WORM!"
XMicrosoft Windows Updaterundlls.exe"Added by the HABRACK WORM!"
XMicrosoftf DDEs ContDLLrune.pif"Added by the RBOT-AGF WORM!"
XMicrosoftf DDEs ContrDLrunm.pif"Added by the RBOT-AFQ WORM!"
XMicroSoftRunMSCOMM.dll"Added by the AGENT-DJG TROJAN!"
NMicrosoft® Windows® Operating System"RunDLL32.exe ehuihlp.dllBootMediaCenter"
NMicrosoft® Windows® Operating System"rundll32.exe oobefldr.dllShowWelcomeCenter"
?MigrationVendorSetupCaller"rundll32.exe migrate.dll CallVendorSetupDlls"
XMircrosoft Windows Config DLLrundllc32b.exe"Added by the RBOT-ZY WORM!"
?MMRunmmrun.exe"??"
XMMSystem"rundll32.exe mmsystem.dll RunDll32"
?mmusrstpprocrun.exe"??"
Xmmxrunmsosa.exeAdded by an unidentified TROJAN or WORM!
Xmmxrunmswinindex.exe"TwoSeven spyware"
XModule Call initialize"RUNDLL32.EXE reg.dll ondll_reg"
XMoreContent"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3Collection"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3download"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3files"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownload"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3freeDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3nice"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3Themes"rundll32.exe MSA64CHK.dllDllMostrar"
XMP3ToTheMax"rundll32.exe MSA64CHK.dllDllMostrar"
XMS-RunKeyarr.exeMS-Connect dialler/hijacker
XMsAudio"MsVM_STI.EXE RunDll32 cmicnfg.cpl CMICtrlWnd"
Xmscheckrundll32.exe wincheck071008.dll mymain"Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
XMSConfigsRUNDLL64.dll.vbs"Added by the WEKODE-B WORM!"
XMSDriverundll32.exe drvkoc.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDriverundll32.exe drvmod.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSDriverundll32.exe drvsoh.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
XMSFTP Service Configr3grun.exe"Added by a variant of the SDBOT WORM!"
XMsn"rundll32.exe ilss32.dllnetwork"
XMSN MessenggerMsRun32.exe"Added by the IMAUT.CO WORM!"
Xmsrundllmsrund1l32.exe"Added by the BINGHE TROJAN!"
Xmsrunocx32msrunocx32.exe"Added by the SKUS WORM!"
XMSServer"Rundll32.exe [random].dll#1"
XMSTaskrun dll.exe"Yuupsearch adware"
XMSTrayrundll.exe"Added by the BAMER-B TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
XMSxmlHpr"RUNDLL32.EXE [path] msxm192z.dllw"
UMxRunnerMxRunner.exeEasyUninstall from Aladdin Systems (formerly by Ontrack)
XMyPointsPointAlertwjview ...MyPointsPointAlertrun.exe"""With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles"". Dubious privacy policy"
XMyWebSearch Plugin"rundll32 [path] M3PLUGIN.DLLUPF"
NNaggerrunkeynagger.exePackard Bell Free Internet Signup screen
XNAVUpd"rundll32.exe navupd.dll Startup"
UNetRunNetRun.exe"NetRun - will 'RUN' a 'List' of programs only when a internet connection is detected
XNew.net Startup"rundll32 [path] NEWDOT~1.DLL ClientStartup"
XNew.net Startup"rundll32 [path] NEWDOT~1.DLL NewDotNetStartup"
XNew.net Startup"rundll32 [path] NEWDOT~2.DLL ClientStartup"
XNew.net Startup"rundll32 [path] NEWDOT~2.DLL NewDotNetStartup"
XNewDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XNewMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XNiceDownloads"rundll32.exe MSA64CHK.dllDllMostrar"
XNiceMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XNod32 Runtimesysregi.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UNOMAD Detectorctnmrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
Xnotepad"rundll32.exe notepad.dll_IWMPEvents@0"
Xnotepad"rundll32.exe ntload.dll_IWMPEvents@0"
XNT securityrundll32.com"Added by the RBOT-AJC WORM!"
Nntlfreedom"rundll32 [path] RyDial.dll QuickStart"
XNumberOneMP3"rundll32.exe MSA64CHK.dllDllMostrar"
?NVCLOCK"rundll32 nvclock.dll fnNvclock"
?NvColorInit"rundll32.exe NvQtwk.dll NvColorInit"
UNvCpl"RUNDLL32.EXE NvCpl.dllNvStartup"
XNvCplrundl32.exe"Added by the AGOBOT-TO WORM! Note - the valid version of this entry has the command line as ""rundll32.exe NvCpl.dll
UNvCplDaemon"RUNDLL32.EXE NvQTwkNvCplDaemon"
UNvCplDaemon"RUNDLL32.EXE NvCpl.dllNvStartup"
UNVHotkeyrundll32.exe nvHotkey.dll"Enables the use of ""hot keys"" for changing setting on Nvidia graphics"
UNVIDIA Media Center Library"RunDLL32.exe NvMCTray.dllNvTaskbarInit"
NNvidiaQuickTweak"rundll32.exe NvQtwk.dll NvTaskbarInit"
UNVIEW"rundll32.exe nview.dllnViewLoadHook"
NNvInitialize"rundll32.exe NvQtwk.dll NvXTInit"
Xnvirundllnvirundll.exe"Added by the SPYBOT.NPS WORM!"
UNVMCTRAY"RunDLL32.exe NvMCTray.dllNvTaskbarInit"
UNvMediaCenter"RunDLL32.exe NvMCTray.dllNvTaskbarInit"
NNVQuickTweak"rundll32.exe NvQtwk.dll NvTaskbarInit"
YNvRegisterMCTray"RUNDLL32.EXE NVMCTRAY.DLLNvMCRegisterApp NvCpl.dll"
YNvRegisterMCTrayNview"RUNDLL32.EXE NVMCTRAY.DLLNvMCRegisterApp nView.dll"
UNvSvc"RUNDLL32.EXE nvsvc.dllnvsvcStart"
Xnxgsvc"rundll32.exe nxgsvc.dllstart"
Xnxosys"rundll32.exe nxosys.dllstart"
UOEMRUNONCEoemrun.exeWindows Millennium file - used by setup when installing the OEM 'express' version of the operating system. Uncheck after setup has finished
XOfficeDeamonmsorunner.exe"Added by a variant of the TACTSLAY TROJAN!"
NOfotoNow USB Detection"Rundll32.exe OFUSBS.DLL WatchForConnection OfotoNow"
XOLEDb Servicerunoledb32.exe"Added by a variant of the SPYRE.B TROJAN!"
Xoo4"RunDLL32.EXE oo4.dllDllRun"
XOpen2Enterrunme.exeAdult content dialler
XOpen2Enterrunme2.exeAdult content dialler
UP17Helper"Rundll32 P17.dll P17Helper"
?P17Helper"Rundll32 SPIRun.dll RunDLLEntry"
?P17RunE"RunDll32 P17RunE.dllRunDLLEntry"
NPaperportrunppdrv.exe"Loads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see here"
UPCDrProfilerRunProfiler.exePart of PC Doctor software installed for some machines. Disabling or enabling it is down to your preference
XPolicyRunspoolsv32.exe"Added by the BACKDOOR-DNV TROJAN!"
XPolicyRunsvchost.exe"Added by the SILLYFDC-AW WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XPopularScreensaversWallpaper"rundll32 [path] F3SCRCTR.DLLLES"
XPostSetupCheckRundll32.exe atgban.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""atgban.dll"" file is found in %System%"
XpostSetupCheckRundll32.exe gzmrt.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""gzmrt.dll"" file is found in %System%"
XPostSetupCheckRundll32.exe cpmsky.dll"TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""cpmsky.dll"" file is found in %System%"
XPowerManagementRundlll.exe"Added by the SURDUX TROJAN!"
XPowerPrifile"rundl132 kenel.dll PowerProfileEnable"
UPPCRunoncePPCRunOnce.exe"Related to PeoplePC ISP software - may display advertising
NpreloadRUNXMLPL.exeSoftware found on Acer computers from Wistron. Information suggests it maps keyboard buttons to operating system functions
NProdikeysAutorunProdload.exe"Creative Prodikeys software - 'an interactive music entertainment device which not only functions as a full-featured
XProtected StorageRUNDLL32.EXE MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XProtection[path] runtask.exe [path] protection.exeAdded by a variant of the AGENT.3.AU TROJAN!
Xprunnet[path to trojan]"Added by the AGENT-HVB TROJAN!"
?Ptipbmf"rundll32.exe ptipbmf.dll SetWriteCacheMode"
UPtiuPbmd"Rundll32.exe ptipbm.dll SetWriteBack"
XPTRGMYGK"rundll32.exe ptmg1v.dll DllRunMain"
Uptrun32ptrun32.exe"ParentTools surveillance software. Uninstall this software unless you put it there yourself"
UPTRUN32ptr32w.exe"ParentTools surveillance software. Uninstall this software unless you put it there yourself"
Upttrunpttrun.exe"Transmeta Crusoe processor related. Reduces application launch times and makes the computer ""more responsive"""
Upwrmonit"RunDll32 [path] pwrmonit.dllStartPwrMonitor"
NQBCD autorunautorun.exeQuick Books CD
Xqkoszvd.dll"rundll32.exe qkoszvd.dlljwezubg"
XRrundll32.exe msprt.dll"Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XRavshellrund1132.exe"Added by the AGENT.OKZ TROJAN!"
Xravtaskrund1132.exe"Added by the DLOADER.IYT TROJAN!"
XRDLLRunDll16.exe"Added by the SDBOT.F TROJAN!"
Xreaddb40"rundll32.exe readdb40.dll EnableRunDLL32"
Xrecover.bmp.exeRundll.exe"Added by the ANAFTP-01 TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
XREEGRUN[path to file]"Added by the SECDROP.AI TROJAN"
Xreg runSysten.exe"Added by the BANCOS-BS TROJAN!"
XRegexitrunlli32.exe"Added by the QQPASS-U TROJAN!"
XRegistry CheckerRegrun.exe"Added by the SDBOT TROJAN!"
XRegistryCheck"rundll32.exe chkreg.dll CheckRegistry"
XRegistryConfigrundll.exe"Added by the AGOBOT-KN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XRegrorundll132.exe"Added by the OKARAG TROJAN!"
XRegRunmActiveX.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XREGRUNwinfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XREGRUN[path to trojan]"Added by the LOWZONE-AH TROJAN!"
XREGRUNregeditt.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XREGRUNsory.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
XREGRUNdialer.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
URegRun WinBaitwinbait.exe"Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.."
YRegrun2WatchDog.exe"Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's
XREGRUNMautoprotect.exeAdded by an unidentified WORM or TROJAN!
XRegrxrundll32.exe"Added by the WAYIC-A TROJAN! Note - this is not the legitimate rundll32.exe process
XRemote Procedure Call LocatorRUNDLL32.EXE reg678.dll ondll_reg"Added by the LOVGATE.F WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XRemote System Protection"rundll32.exe [random].dll HUI_proc"
NRFX_auto_upgraderundll32.exe npvpg005.dll"A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade"
XRhgrundll32.exe"Added by the LINEAG-BIT TROJAN! Note - this is not the legitimate rundll32.exe process
XRichMedia"rundll32.exe [path] hbcast.dll WaitWindows"
XRKrxrundll32.exe"Added by the LINEAG-ADA TROJAN! Note - this is not the legitimate rundll32.exe process
XRKrxrundll32.exe"Added by a variant of the LINEAG-ADA TROJAN! Note - this is not the legitimate rundll32.exe process
Xrmdrfje.dll"rundll32.exe rmdrfje.dll[random characters]"
XRr2rundll32.exe"Added by the LINEAG-ADI TROJAN! Note - this is not the legitimate rundll32.exe process
Xrrorundll32.exe"Added by the LINEAG-AAE TROJAN! Note - this is not the legitimate rundll32.exe process
XRSS"rundll32 RSSToolbar.dll DllRunMain"
XRunreal.exe"Added by the LOVGATE.E WORM!"
XrunAutoexec.com"Added by the HOLCAS.A WORM!"
Xruninetinfo.exe"Added by the BINGHE TROJAN!"
XRunhelp.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
Xrunservices.exe"Added by the KREPPER-N TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\inet10066"
Xrunrundll32.exe rsrc.dll"Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
Xruncchost.exe"Added by the SQUATBOT-C TROJAN!"
Xrune.exe"Added by the IMONI-E TROJAN!"
Xrunwinsys32.exe"Added by the DELF.CP BACKDOOR!"
Xrunmexica.exe"Added by the AUTORUN.AEV WORM!"
XRunManager.exe"Added by the DELF.EUN TROJAN! The file is found in %AppData%\Roaming\Adobe - see the link for more information"
URun Google Web AcceleratorGoogleWebAccWarden.exe"Google Web Accelerator"
XRun Msn Messengermsnmgr.exe"Added by the AGOBOT.HA WORM!"
XRun MSupdt32wscript MSupdt32.vbs"Added by the CASER WORM!"
URun Nintendo Wi-Fi USB Connector Registration ToolNintendoWFCReg.exe"Related to Wi-Fi USB Connector from Nintendo"
URun POPFile in backgroundperl.exe"POPFile - E-mail spam blocker"
URun POPFile in backgroundwperl.exe"POPFile - E-mail spam blocker"
XRun Services as Applicationlocalsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationnetsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationspoolsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcadmin.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcman.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationtcpsvc.exe"Added by the DLOADER-NY TROJAN!"
XRun Services as Applicationwebsvc.exe"Added by the DLOADER-NY TROJAN!"
URun StartupMonitorStartupMonitor.exe"Mike Lin's StartupMonitor
Xrun windowsservic.bat"Added by the REBOOT-AP TROJAN!"
XRun05rundll_32.exe"Added by the BANCOS-DT TROJAN!"
Xrun32run32dll.exe"Added by the SDBOT-CWB WORM!"
Xrun32dllWINClock.exe"Added by an unidentified VIRUS
Xrun32dlltask32.exe"Added by an unidentified VIRUS
XRun32dllocxdll.exe"Added by an unidentified VIRUS
Nrun=cmmpu.exeMIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI)
Nrun=hpfschedHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
Nrun=lxdboxcp.exeLexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS
Nrun=pcfix2k.exepcfix2k splash screen
Xrun=ptlseq.cpl"PhoenixNet BIOS adware. See here"
Urun=ramsys.exe"Advanced Startup Manager from Rays Lab"
?run=wallflip.exe"Desktop wallpaper changer?"
Xrun=svcinit.exe"CoolWebSearch parasite variant"
Xrun=fntldr.exe"CoolWebSearch Tapicfg parasite variant"
Yrun=smsrun16.exe"Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1
?run=win.ini"??"
Xrun=RAVMOND.exe"Added by the LOVGATE-F WORM!"
Xrun=dec25.exe"Added by the ATAK.F WORM!"
?run=LXBTppls.exe"Reportedly part of Lexmark printer software - what does it do and is it required?"
Nrun=fmedia.exeFMedia FaxWorks related - can be run manually
Yrun=wswpd.exe"Used with some models of Panasonic
Xrun=cyxid98.exeUnidentified malware
Xrun=info32.exe"CoolWebSearch Tapicfg parasite variant"
Xrun=mouse_configurator.win"Added by the GAGGLE.E WORM!"
Xrun=RegistryReminder.exe"Added by the APSTROJAN.OB TROJAN!"
Xrun=sec5dec.exe"Added by the ATAK.G WORM!"
Xrun=wmplayer.exe"CoolWebSearch Smartsearch parasite variant"
Xrun=Autoexec.com"Added by the HOLCAS.A WORM!"
Xrun=htmlsync.exeSearchforfree.info browser hijacker
Xrun=msoffice.exe"Added by the ADWARELOADER TROJAN! Note - do not confuse with the legitimate Microsoft Office file
Xrun=DRDOOM.EXE"Added by the SEMAPI-A WORM!"
Xrun=svhost.exe"Added by the ADMINCASH.B TROJAN!"
Xrun=dllreg.exe"Added by the DUMARU-L TROJAN!"
Xrun=Celine.scr"Added by the CELINE-A TROJAN!"
URunAlertAService.exe"PC Alert III - MSI motherboard monitoring software. Only required if you ""overclock"" your system. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/2K"
NrunAPrunAP.exe"Not required but what is it?"
Xrunappicqchk.exe"Added by the BOMKA TROJAN!"
XRunapp32Runapp32.exe"Added by the NEODURK TROJAN!"
YRunCAInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be required
XRund11Rund11.EXE"Added by the MARIO-C WORM!"
Xrund1132rund1132.exe"Added by the DOPBOT-A WORM!"
XRund1132.exeRund1132.exe"Added by the STARTPA-HS TROJAN!"
XRund1l32Winfi1e32.exe"Added by the MERTIAN WORM!"
Xrunddlfilerunddl.exe"Added by the DELF.D TROJAN!"
XRundil32runlli32.exe"Added by the QQPASS-U TROJAN!"
XRundil32Updadv.exe"Added by the QQPASS-N TROJAN!"
Xrundl332math.exe ...pluged.exe"Added by the DOOMJUICE WORM!"
Xrundli32rundli32.exe"Added by the LADE WORM!"
XRunDLL"rundll32.exe [path] Bridge.dllLoad"
XRundllRundll~.exe"Added by the DELF-KT TROJAN!"
XRundllrundll32.exe [random filename].dll"Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System%"
XRunDllRunDll.exe"Added by the QQPASS-AH TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
XRunDll[path to trojan]"Added by the DROPPER.EAT TROJAN!"
XRunDLL Kernel File Corerundll.exe"Added by a variant of the RBOT WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
Xrundll***die.exe [path] mdll.exe"Added by the SUMTAX TROJAN! where *** is 134
Xrundll***die.exe [path] secure.bat"Added by the SUMTAX TROJAN! where *** is 134
Xrundll***die.exe [path] secure.exe"Added by the SUMTAX TROJAN! where *** is 134
Xrundll***die.exe [path] ttg.exe"Added by the SUMTAX TROJAN! where *** is 134
XRundll16Rundll16.exe"Added by a number of VIRUSES
XRundll32Rundll32.exe"Added by a variant of the DVLDR TROJAN! Note - this is not the legitimate rundll32.exe process
URUNDLL32"RUNDLL32.EXE NvQTwkNvCplDaemon"
URunDLL32"RunDLL32.exe NvMCTray.dllNvTaskbarInit"
XRunDLL32winupdate.exe"Added by an unidentified TROJAN! - possibly a BMBOT variant"
XRundll32Windows.exe"Added by the QQPASS.E TROJAN!"
URundll32"Rundll32.exe ptipbm.dll SetWriteBack"
Xrundll32[path to worm]"Added by the AUTEX WORM!"
?rundll32"rundll32.exe ptipbmf.dll SetWriteCacheMode"
Xrundll32rundll32.exe"Added by the SANKER WORM! Note - this is not the legitimate rundll32.exe process
Xrundll32csrss.exe"Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Urundll32"rundll32.exe irprops.cpl
XRUNDLL32rundl32.exe"Added by the DEMOTRY-A WORM!"
Xrundll32rundll32.exe"Added by the AGENT-EZ TROJAN! Note - this is not the legitimate rundll32.exe process
XRundll32RUNDDLL32.EXEAdded by the STARTPAGE.AXH TROJAN!
Xrundll32kernel32.exe"Added by the STAP-C WORM!"
Xrundll32kernel33.exe"Added by the STAP-D WORM!"
Xrundll32MSDTC.exe"Added by the STAP-E WORM!"
Xrundll32rookie.vbs"Added by the ROOKIE-A TROJAN!"
Xrundll32rundll64.exe"Added by the DELF.BKC TROJAN!"
Urundll32"rundll32.exe bthprops.cpl
Urundll32"rundll32.exe nview.dllnViewLoadHook"
Xrundll32svchs0t.exe"Added by the PWSTEAL-E TROJAN!"
NRundll32 cmicnfg"Rundll32 cmicnfg.cpl CMICtrlWnd"
YRunDll32 essprops"RunDll32 essprops.cpl TaskbarIconWnd"
URundll32 P17"Rundll32 P17.dll P17Helper"
XRundll32.exeProyecto1.exe"Added by the GRUEL WORM!"
XRundll32.exeRoot.exe"Added by the GRUEL WORM!"
XRundll32_7"rundll32.exe MSIEFR40.DLL DllRunServer"
XRundll32_8"rundll32.exe inetp60.dll DllRunServer"
XRundll32_8"rundll32.exe 1.dll DllRunServer"
XRunDLL34syscnfg.exe"Added by an unidentified VIRUS
Xrundll64[path to worm]"Added by the AUTEX WORM!"
XRundllSvrRundll.exe"Added by the HUAYU WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XRundllsystem32Rundllsystem32.exe"Added by the NETDEVIL.B TROJAN!"
XRundnmRundnm.exe"Added by the DELF-HA TROJAN!"
XRUNGogoToolsLaunchAdware.exe"GoGoTools adware"
XRUNGogoToolsGoGoLaunch.exe"GoGoTools adware"
XRUNHYPERhyperx.exe"PurityScan/Clickspring adware"
Xruningwin.exe"Added by the DELF-LC TROJAN!"
XRUNLOADl0ad.exe"PurityScan/Clickspring adware"
XRUNLOUDloud.exe"PurityScan/Clickspring adware"
URunmarc8mManagermarc8m95.exe"MARC Sound System Manager for the Marc 8 MIDI sound card - allows for easy adjustment of the settings"
URunNarratorNarrator.exeAssociated with the Narrator accessibility feature on Windows XP. It is used to convert text to speech
XRunnerlsass.exe [trojan filename]"Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunnercsrss.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunnerlsass.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRunnersvchost.exe"Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xrunner1updater.exeAdded by the CRYPT.ULPM.GEN TROJAN!
Xrunner1retadpu.exe"Added by the AGENT.SLZ TROJAN!"
Xrunner1mrofinu.exe"Added by the AGENT.CZC TROJAN!"
Xrunner1retadpu[random digits].exe"Added by the SMALL.CTV TROJAN!"
Xrunner1tsitra.exe"Added by the AGENT.ABFQ TROJAN!"
Xrunner1faceback.exe"Added by the DLOADR-BSX TROJAN!"
URunOnceRUNONCE.EXEPart of MS Data Access Components - only required if you use these
XRunoncerunouce.exe"Added by the CHIR-B WORM!"
XRunOnce[path to trojan]"Added by the BANCBAN-P TROJAN!"
XRunOnce[path to mstask32.exe]"Added by the DELF-IA TROJAN!"
XRunOnce2Upd[path to trojan]"Added by the MURLO.FI TROJAN!"
XRunOnceExsms.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XRunProgServer.exe"Added by the OPTIX.04.A TROJAN!"
XRunProgwini.exe"Added by the OPTIX.04.D TROJAN!"
Xrunreperviewer.exe"Added by the REPER.A VIRUS!"
Xrunsrun.exe"Added by the RBOT-BWF WORM!"
XRunSearvicestread.exeIESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
XRunServicesrunsvc32.exe"Added by the AGOBOT.QJ WORM!"
Xrunservicesservices.exe"Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xrunsqlrunsql.exe"Added by the DELF.ZWK TROJAN!"
XrunSubvalues[path to file]"Added by the DLOADER-QY TROJAN!"
Xrunsvcrunsvc.exe"Added by the SMALL-CF TROJAN!"
URunSysd32RunSysd32.exeDesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within
XRuntime ProcessCsrss.exe"Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRuntime Server Subsystemcsrss.exe"Added by the IRCBOT-XV WORM!"
Xruntime.exeruntime.exeAdded by a variant of the Tibs malware
XRuntt1Internat.exe"Added by the LINEAGE-R TROJAN!"
XRuntt1Internet.exe"Added by the LINEAGE-Q TROJAN!"
XRunWin[path to file]"Added by the BANKER-ES TROJAN!"
Xrunwin32runwin32.exe"Added by the ESEARCH-A TROJAN!"
XRUNWIN32runwin32.exe"Added by the VB-AET TROJAN!"
XRunWindowsUpdateuptodate.exe"BrowserAid/BrowserPal foistware"
Xrunwinlogonwinlogon.exe"Added by the AGENT.TQY TROJAN! Note - this is not the legitimate winlogon.exe process
XRun_cdRun_cd.exe"Added by the GHOST.23 TROJAN!"
Yrun_pbnextPBNext.exe"PBNext is virtual phone system which offers the same functionality as expensive PBX hardware"
?RUSBHOLoader"rundll32.exe RUSBHOLoader.dll AutoRegister"
Xrxrundll32.exe"Added by the LINEAGE-BP TROJAN! Note - this is not the legitimate rundll32.exe process
Xryyrundl132.exe"Added by the PWS-ANA TROJAN!"
Xrztrundll32.exe"Added by the LINEAGE.BDP TROJAN! Note - this is not the legitimate rundll32.exe process
USamsung MJC-900 Series Monitor"RUNDLL32.EXE SMMASHLL.DLLAutoUpdatePnPValue"
XsaSyncMgr"rundll32.exe sasync.dll SyncWait"
XSavsvc"rundll32.exe savsvc.dllstart"
USbUsb AudCtrl"RunDll32 sbusbdll.dll RCMonitor"
Uscrun.exe"All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes
XScreenSaverPlus"rundll32.exe MSA64CHK.dllDllMostrar"
XSearchMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XServer Runtime Errorunsec.exe"Added by the SDBOT-DFA WORM!"
XServer Runtime Processwbemstest.exe"Added by the SDBOT-DDB WORM!"
XService Pack DLL Runtimespdll32.exe"Added by a variant of the RBOT WORM!"
XServices Administratorsvcrun.exe"Added by the DLOADER-NY TROJAN!"
XServRunsrss32.exe"Added by the AGOBOT.ABS WORM!"
?SetCacheMode"rundll32.exe ptipbmf.dll SetWriteCacheMode"
Xsetuparunt32.exe"Added by the QQPASS-K TROJAN!"
XShellRunlexplore_.exe"Added by the MSNOPT-A TROJAN!"
XShellRun32iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XShutDownWindows"Rundll32.exe UserExitWindows"
Xsi91e44b"rundll32.exe si91e44b.dll EnableRunDLL32"
YSiSPower"Rundll32.exe SiSPower.dllModeAgent"
USlickRunsr.exe"""SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords)
Xsmrtdrvruntime.exe"Added by the AGOBOT.MT WORM!"
XSOProc_RegSoAlertWxLiteNnAj"rundll32 shell32.dll ShellExec_RunDLL [path] soproc.exe"
?SoundFusionrundll32 cwcprops.cpl"Control panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?"
?SoundFusion"rundll32 hercplgs.cpl BootEntryPoint"
?SoundFusion"RunDll32 cwaprops.cpl C25CrystalControlWnd"
Xsp"rundll32 (Path to Trojan DLL) DllInstall"
Xspa_startRundll32.exe spads.dll"IconAds adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""spads.dll"" file is located in the Winnt or Windows folder"
Xspa_startRundll32.exe sprt_ads.dll"Superiorads adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""sprt_ads.dll"" file is located in %System%"
XSpeedRunnerSpeedRunner.exeIdentified as a variant of the TrojanDownloader.Matcash malware
?SPIRun"Rundll32 SPIRun.dll RunDLLEntry"
XSpooler SubSystem Applicationsvcrun.exe"Added by the DLOADER-NY TROJAN!"
?SPPrun.exe"??"
Xsre"rundll32.exe sre.dll Register"
?srePostpone"rundll32.exe [path] srescan.dll DoSpecialAction"
?SRFirstRun"rundll32 srclient.dll CreateFirstRunRp"
XSrv32 spool servicerunsrv32.exe"Topantispyware.com malware - detected by Kaspersky as the SPYRE.B TROJAN!"
Xssate.exeirun4.exe"Added by the BEAGLE.J WORM!"
YsscRunSSCRun.exeAOL's firewall
Xssgrate.exeirun.exe"Added by the MITGLIEDER.D TROJAN!"
Xssgrate.exeirun4.exe"Added by the MITGLIEDER.F TROJAN!"
XstartkeyRunWinRaR.exeAdded by a variant of the BIFROSE-LV TROJAN!
XStartwd"rundll32.exe wd081025.dllHook"
Xstartwindowskeyuserrundle2.exe"Added by the JAVAKILLER TROJAN!"
Xstlbdist"rundll32exe stlbdist.DLL DllRunMain"
Xstlbupdt"rundll32.exe stlbupdt.DLLDllRunMain"
Xsupdate2.dll"rundll32.exe supdate2.dllRun"
XSurfBuddyrundll32 [path] sbuddy.dll"SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
Xsvchostrundll16.exe"Added by the STARTPA-PB TROJAN!"
Xsvrrunsvrrun.exeAdware hailing from Deskwizz.com
USWLrundll32.exe [path] SWL.dll rdl"StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XSymRunN/A"Added by the KANGAROO-A TROJAN!"
XSymRunccApps.exe"Added by the KAGEN-A TROJAN!"
XSyncManagermsorunner.exe"Added by a variant of the TACTSLAY TROJAN!"
?SynSetupSynTP.tmp RunOnce.exe"Probably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?"
Xsysrundll32.exe"Added by the LINEAG-G TROJAN! Note - this is not the legitimate rundll32.exe process
XSysDeskqqfxRunddll32.exe"Added by the CHANGGAME TROJAN!"
Xsysdirwinrun.exe"Added by the WINBUR.B WORM!"
XSysPnP"rundll32 setupapi InstallHinfSection [varies] oemsyspnp.inf"
XSystemrun322.exe"Added by the LANFILT TROJAN!"
XSystemUpdaterun.exe"Added by the QQHELP-DX TROJAN!"
XSYSTEMRUNDLL16.exe"Added by the DELF-EW BACKDOOR!"
USystem Check"Rundll32.exe SysDll32.dll SystemCheck"
XSystem32 Runtime StartUpsysrs.exe"Added by the AGOBOT.ANW WORM!"
XSystemHelp"RUNDLL32.EXE SystemHper.dllInstall"
USystemKeyrundll32.exe [path] SystemKey.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XSystemMessengerrundll32.exe [path] SystemMessenger.dll"Stealth Chat Monitor spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XSystems Restart"Rundll32.exe beem.dll DllRegisterServer"
XSystems Restart"Rundll32.exe snim.dll DllRegisterServer"
XSystems Restart"Rundll32.exe zolk.dll DllRegisterServer"
XSystems Restart"Rundll32.exe boln.dll DllRegisterServer"
USystemWebrundll32.exe [path] SystemWeb.dll rdl"StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XSysWyrundll32.exe"Added by the LINEAGE-JH TROJAN! Note - this is not the legitimate rundll32.exe process
XSys_Runghost.exe"Added by the LINEAGE-N TROJAN!"
Xsys_Runtt1explorer.exe"Added by the LINEAGE-M TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XtaengtaeAutoRun.bat"Added by the GATINA-B WORM!"
XTakeMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XTANG_INA_MOAutoRun.bat"Added by the FILUKIN.A WORM!"
NTaskbar Display Controls"RunDLL deskcp16.dll QUICKRES_RUNDLLENTRY"
XTaskbell.exeRund1.exe"Added by the YIPID TROJAN!"
XTaskManRundll32.exe"Added by the DVLDR TROJAN! Note - this is not the legitimate rundll32.exe process
UtcomantidialerrunT-Com Antidialer.exe"T-Com Antidialer from T-Com internet provider. It's a small antidialer utility which monitors whether you're trying to dial a new connection. It basically asks you do you want to dial the shown number or not. Protects agains dialer malware"
XTcp Application Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XTencent QQ"Rund1132.exe qq.dll Rundll32"
NTesco.net"rundll32 [path] RyDial.dll QuickStart"
XTheBestMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XThemeMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XTilerunTilecom32.com"Added by a variant of the SDBOT WORM!"
XTimeServicetrun.exe"TlfLic-A premium rate adult content dialler"
XtopmoxieJavaRun.exe"TopMoxie adware"
Xtransys"rundll32.exe transys.dllstart"
XTrayrundll32.exe"Added by the LINEAG-ADR TROJAN! Note - this is not the legitimate rundll32.exe process
UTrunk32sb32mon.exe"Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
UTweak UI"rundll32.exe tweakui.cpl tweakmeup"
UTweak UI"rundll32.exe tweakui.cpl tweaklogon"
XTweak UI"RunDLL32 tweakUI.DLL TWEAKUI /tweakmeup"
UTweak UI 1.33 deutsch"RUNDLL32.EXE TWEAKUI.CPL TweakMeUp"
UUCmore XP - The Search Accelerator"rundll32.exe UCMTSAIE.dll DllShowTB"
Xuhvjsul.dll"rundll32.exe uhvjsul.dllmrpmvyf"
Xupdate run doslogon.exe"Added by a variant of the SDBOT WORM!"
XUpdate Run MSwordLOGON.EXE"Added by the RBOT.TY WORM!"
?UPDATEHOOKRundll32.exe"??"
Xuserun32userun32.exe"Added by the LYDRA-B TROJAN!"
Xusrgtway.exesyswrun4x.exe"Added by the MITGLIEDER.E TROJAN!"
Xutasvc"rundll32.exe utasvc.dllstart"
XUtilitiesAndSoftware"rundll32.exe MSA64CHK.dllDllMostrar"
YV128IID"Rundll32.exe v128iitw.dll STB_InitTweak"
XVB_runcomctl_32.exeDubious downloader from densmail.com
XVFW Encoder/Decoder SettingsRUNDLL32.exe MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XVisualStudiomsorunner.exe"Added by a variant of the TACTSLAY TROJAN!"
UVoodooBanshee"rundll32.exe 3DBBps.dll BansheeLoadSettings"
XW3KNetwork"rundll32.exe w3knet.dll dllinitrun"
XWebRun[random filename]"Added by the ADWARELOADER TROJAN!"
XWebSavingsfromEbatesWebSavingsfromEbatesrun.exe"Web Savings From Ebates Software
XWebSpecialsrundll32 [path] webspec.dll"WebSpecials spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
NWIAWizardMenu"RUNDLL32.EXE sti_ci.dll WiaCreateWizardMenu"
?WildTangent CDA"RUNDLL32.exe cdaEngine0400.dll cdaEngineMain"
XWin32 Rundll LoaderRundll32.exe"Added by the SDBOT.A TROJAN! Note - this is not to be confused with the legitimate rundll32.exe file!"
XWin32 USB Driverrundll.exe"Added by the FORBOT-BN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWin32 USB2.0 Driverrundll16.exe"Added by the WOOTBOT.H WORM!"
XWin32.Exploit.mzHmzrun.exe"Added by the PAINTER TROJAN!"
Xwinabc"rundll32.exe [Temp][ORIGFILENAME].DLLInstallLaunchEv"
Xwincls"rundll32.exe wincls.dllstart"
Xwincomvbrun6win.exe"Added by the AGOBOT-AFK WORM!"
Xwinconnvbrun6nt.exe"Added by the AGOBOT-AEI BACKDOOR!"
Xwindirwinrun.exe"Added by the WINBUR.B WORM!"
XWinDLL (algs.exe)"rundll32.exe algs.exestart"
XWinDLL (asdfsa.exe)"rundll32.exe asdfsa.exestart"
XWinDLL (bee.dll)"rundll32.exe bee.dllstart"
XWinDLL (bix.exe)"rundll32.exe bix.exestart"
XWinDLL (csmss.exe)"rundll32.exe CSMSS.EXEstart"
XWinDLL (ctfmonm.exe)"rundll32.exe ctfmonm.exestart"
XWinDLL (dasda.com)"rundll32.exe dasda.comstart"
XWinDLL (diem.exe)"rundll32.exe diem.exestart"
XWinDLL (dlfksdld.exe)"rundll32.exe dlfksdld.exestart"
XWinDLL (jbi32.dll)"rundll32.exe jbi32.dllstart"
XWinDLL (lcass.exe)"rundll32.exe lcass.exestart"
XWinDLL (mysnlive.exe)"rundll32.exe mysnlive.exestart"
XWinDLL (qwex.dll)"rundll32.exe qwex.dllstart"
XWinDLL (redyLive.exe)"rundll32.exe redyLive.exestart"
XWinDLL (scvhost32.dll)"rundll32.exe scvhost32.dllstart"
XWinDLL (slmss.exe)"rundll32.exe slmss.exestart"
XWinDLL (slsass.exe)"rundll32.exe slsass.exestart"
XWinDLL (smaprnter.exe)"rundll32.exe smaprnter.exestart"
XWinDLL (smms.exe)"rundll32.exe smms.exestart"
XWinDll (sslms.exe)"rundll32.exe sslms.exestart"
XWinDLL (start0s.exe)"rundll32.exe start0s.exestart"
XWinDLL (steam.dll)"rundll32.exe steam.dllstart"
XWinDLL (svc.exe)"rundll32.exe svc.exestart"
XWinDLL (svchost.dll)"rundll32.exe svchost.dllstart"
XWinDLL (sysx32.dll)"rundll32.exe sysx32.dllstart"
XWinDLL (tepmlayer.exe)"rundll32.exe tepmlayer.exestart"
XWinDLL (tmp.exe)"rundll32.exe tmp.exestart"
XWinDLL (tock24.dll)"rundll32.exe tock24.dllstart"
XWinDLL (tqurity.exe)"rundll32.exe tqurity.exestart"
XWinDLL (v4mon.dll)"rundll32.exe v4mon.dllstart"
XWinDLL (vdm32.dll)"rundll32.exe vdm32.dllstart"
XWinDLL (vxd32.dll)"rundll32.exe vxd32.dllstart"
XWinDLL (wchshield.exe)"rundll32.exe wchshield.exestart"
XWinDLL (wimimi.exe)"rundll32.exe wimimi.exestart"
XWinDLL (windns32.dll)"rundll32.exe windns32.dllstart"
XWinDLL (wingatey32.exe)"rundll32.exe wingatey32.exestart"
XWinDLL (wintmp.exe)"rundll32.exe wintmp.exestart"
XWinDLL (Wseclayer.exe)"rundll32.exe Wseclayer.exestart"
XWinDLL (wsync32.dll)"rundll32.exe wsync32.dllstart"
XWinDLL (xvd32.dll)"rundll32.exe xvd32.dllstart"
XWindosupdate managerrunwin32.exe"Added by the SDBOT.NNS BACKDOOR!"
XWindowsrun.exe"Added by the SPYBOT.OFN WORM!"
XWindows .Net Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows 32-bit DLL Integrity Verifierdllrun.exe"Added by Remote Storm - a remote control tool that is a network application that allows users to manage and control PCs or networks from a remote location"
XWindows AutomaticUpdaterrunddls.exe"Added by a variant of the RBOT WORM!"
XWindows Client/Server Runtime Servercsrs.exe"Added by the RBOT.KD WORM!"
XWindows ConfigRUNDLL.EXE"Added by the SPYBOT-DX WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWindows DLL LoaderRUNDLL16.EXE"Added by the DOMWIS TROJAN!"
XWindows DLL Loaderrundll32.exe"Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process"
XWindows Firevall Control Crundll.exe"Added by the GAERTOB.A TROJAN!"
XWindows Firewallrundll32.exe"Added by a variant of the IRCBOT BACKDOOR!"
XWindows Local Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
NWindows Media Center"RunDLL32.exe ehuihlp.dllBootMediaCenter"
XWindows Memory Running Servicesmemrun.exe"Added by the IRCBOT.BLL BACKDOOR!"
Xwindows runsystem.exe"Added by the ICPASS-A WORM!"
XWindows Run-Time 64bitwin64rt.exe"Added by a variant of the RBOT WORM!"
XWindows Rundll Centermsnsmgr.exe"Added by the AGENT-LLB TROJAN!"
XWindows Rundll Centermsmsgrs.exe"Added by the IRCBOT-AFA WORM!"
XWindows Running DLL Servicerundll128.exe"Added by the IRCBOT.XDH BACKDOOR!"
XWindows Running DLL Servicerundll64.exe"Added by the SLENFBOT.HV WORM!"
XWindows Runtime Helpwin32hlp.exe"Added by a variant of the AIMVISION TROJAN!"
XWindows Runtime HelpWinRunHelp.wrh"Added by a variant of the AIMVISION TROJAN!"
XWindows Runtime Proccess32RUNdll.exe"Added by the SDBOT.QW WORM!"
XWindows Security Assistantrundll32.vbe"CoolWebSearch Alfasearch parasite variant - also detected as the STARTPA-U TROJAN!"
XWindows Service Managersvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows Services B-Runnersvcbrun.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Services B-Runnersvcbrunner.exe"Added by the IRCBOT.BYV BACKDOOR!"
XWindows StartupWdrun32.exe"Added by the GAOBOT.AO WORM!"
XWindows Startup 32 Bitssysrun32.exeAdded by a variant of the DARKSUN TROJAN!
XWindows TMrundlI32.exe"Added by the RBOT.EL BACKDOOR!"
XWindows Upaterundll.exe"Added by the HAKO TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
XWindows Update Svcrundll32.exe xpupdate.dll"ContraVirus rogue security software - not recommended
XWindows Web Servicessvcrun.exe"Added by the DLOADER-NY TROJAN!"
XWindows32rundll.exe"Added by the AGOBOT-LK or AGOBOT-ND WORMS! Note - this is NOT the Win9x/Me system file of the same name as described here"
NWindowsWelcomeCenter"rundll32.exe oobefldr.dllShowWelcomeCenter"
XWINDRUNtaskgmrs.exe"Added by the MYTOB-BT WORM!"
UWinfast2KLoadDefault"rundll32.exe wf2kcpl.dllDllLoadDefaultSettings"
UWinFast_Gamma"Rundll32.exe wfcpl.dll DllLoadGammaRampSettings"
UWinFast_Taskbar"rundll32.exe wftask.dll WFDllLoadDefaultSettings"
NWinHacker"rundll32.exe wh95.dll HackMe"
XWinIeRunwinierun.exe"Added by the RNWATCH-A WORM!"
Xwinrunmsconfig.exe"Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
Xwinrunwinrun.exe"Added by the WINBUR.B WORM!"
XWINRUNtaskgmr32.exe"Added by the MYTOB.AP WORM!"
XWINRUNsvchost32.exe"Added by the MYTOB-AI WORM!"
XWINRUNtaskgmr.exe"Added by the MYTOB-BX WORM!"
XWinRunAutoRun.ini"Added by the LOVELET-AD WORM!"
XWINRUNTASKMGR32.exe"Added by the MYTOB.AX WORM!"
XWINRUN zW1NT45K.exe"Added by the MYTOB.BL WORM!"
XWinRunnersWinDrivers.exe"Added by the DULOAD.C WORM!"
XwinstroRUN32DLL.exe"Added by the FTP_ANA TROJAN!"
Xwinsync******.exe reg_run [* = random char]"Added by a variant of the QOOLOGIC TROJAN!"
Xwinupd"RUNDLL32.EXE [random value].dll _mainRD"
Xwinupdate2846vbsystem35.exe msvbrun.exe"Added by a variant of the MUTIN-C TROJAN!"
XwinupdtRUNDLL32.EXE [random.dll]"Added by the MABUT.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the Windows or Winnt folder"
Xwinurwinrun.exe"Added by the WINUR.B WORM!"
UWinXPLoad"Rundll32 LoadDll LoadExe WinXPLoad.exe"
UWireLessMouseStartAutorun.exe MouseDrv.exe"Related to WireLess Mouse Multimedia Combo Set by SANSUN Industries"
Xwm41a398"rundll32.exe wm41a398.dll EnableRunDLL32"
Xwmcbaaca"rundll32.exe wmcbaaca.dll EnableRunDLL32"
Xwrclib"rundll32.exe wrclib.dllstart"
Xwtzlank.dll"rundll32.exe wtzlank.dllqttwuwc"
Xwupipenimi"Rundll32.exe jinorije.dlls"
Xwupipenimi"Rundll32.exe luyenofe.dlls"
Xwupipenimi"Rundll32.exe poyimimu.dlls"
Xwupipenimi"Rundll32.exe siremase.dlls"
Xwupipenimi"Rundll32.exe tamuyiko.dlls"
Xxccinitrundll33.exe xccdf16_090131a.dll"Added by the BUZUS-AD TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090131a.dll"" file is located in %Windir%"
Xxccinitrundll33.exe xccdf16_090305a.dll"Added by the BUZUS-AF TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090305a.dll"" file is located in %Windir%"
?xkstartup"RunDll32 InstZ82.dll SetUsbPrinterPort"
Xyahoo!"rundll32.exe [random]don.dllSet"
XYourMP3"rundll32.exe MSA64CHK.dllDllMostrar"
XZenet"rundll32 CNBabe.dll DllStartup"
UZIBMACCrundll.exe ZIBMACC.INFZIBMACC.INF is an IBM file that is only loaded and installed under a recovery operation. The file is a support file for IBM access to the system if needed. You may delete this file. This is as from IBM Technical Support (USA - 800-887-7435)
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
Xzsmsccrundll32.exe mycc071208.dll mymain"Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
Xztrundll32.exe"Added by the LINEAG-ABA TROJAN! Note - this is not the legitimate rundll32.exe process
X[random name]rundl13a.exe"Added by the GAMPASS-L TROJAN!"
X[random number]"rundll32.exe shell32.dllControl_RunDLL [random number].cpl"
X[Randomly chosen existing folder name]_autorun.exe"Added by the ANTINNY-L WORM!"
X[various names]runload32.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_rxrundll32.exe"Added by the LINEAG-B TROJAN!! Note - this is not the legitimate rundll32.exe process
X_System_Run_svchost_.exe"Added by the LINEAGE-Z TROJAN!"
X{12EE7A5E-0674-42f9-A76B-000000004D00}"rundll32.exe stlb2.dll DllRunMain"
X{2CF0B992-5EEB-4143-99C0-5297EF71F444}"rundll32.exe stlbdist.dllDllRunMain"
X{2CF0B992-5EEB-4143-99C2-5297EF71F44B}"rundll32.exe stlbupdt.DLLDllRunMain"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.