| Status | Autorun name | Command | Description |
| X | run= | DRDOOM.EXE | Added by the SEMAPI-A WORM! |
| X | run= | svhost.exe | Added by the ADMINCASH.B TROJAN! |
| X | run= | dllreg.exe | Added by the DUMARU-L TROJAN! |
| X | run= | Celine.scr | Added by the CELINE-A TROJAN! |
| N | run= | cmmpu.exe | MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI) |
| N | run= | hpfsched | HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature |
| N | run= | lxdboxcp.exe | Lexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS |
| X | Run_cd | Run_cd.exe | Added by the GHOST.23 BACKDOOR! |
| Y | run_pbnext | PBNext.exe | PBNext is virtual phone system which offers the same functionality as expensive PBX hardware |
| X | Run05 | rundll_32.exe | Added by the BANCOS-DT TROJAN! |
| X | run32 | run32dll.exe | Added by the SDBOT-CWB WORM! |
| X | run32 | lsass.exe | Added by the MDROP-CQQ TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Win |
| X | run32dll | WINClock.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | run32dll | task32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Run32dll | ocxdll.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| U | RunAlert | AService.exe | PC Alert III - MSI motherboard monitoring software. Only required if you "overclock" your system. Appears as a service in XP/Vista and under the "RunServices" registry key in Win98/2K |
| N | runAP | runAP.exe | Not required but what is it? |
| X | runapp | icqchk.exe | Added by the BOMKA TROJAN! |
| X | Runapp32 | Runapp32.exe | Added by the NEODURK TROJAN! |
| Y | RunCA | InvokeSvc3.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required |
| X | Rund11 | Rund11.EXE | Added by the MARIO-C WORM! |
| X | rund1132 | rund1132.exe | Added by the DOPBOT-A WORM! |
| X | Rund1132.exe | Rund1132.exe | Added by the STARTPA-HS TROJAN! |
| X | Rund1l32 | Winfi1e32.exe | Added by the MERTIAN WORM! |
| X | runddlfile | runddl.exe | Added by the DELF.D TROJAN! |
| X | Rundil32 | runlli32.exe | Added by the QQPASS-U TROJAN! |
| X | Rundil32 | Updadv.exe | Added by the QQPASS-N TROJAN! |
| X | rundl332 | math.exe ...pluged.exe | Added by the DOOMJUICE WORM! |
| X | rundli32 | rundli32.exe | Added by the LADE WORM! |
| X | RunDLL | rundll32.exe [path] Bridge.dll,Load | WinFavorites adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Bridge.dll" file is located in %System% |
| X | Rundll | Rundll~.exe | Added by the DELF-KT TROJAN! |
| X | Rundll | rundll32.exe [random filename].dll | Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System% |
| X | RunDll | RunDll.exe | Added by the QQPASS-AH TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here |
| X | RunDll | [path to trojan] | Added by the DROPPER.EAT TROJAN! |
| X | RunDLL Kernel File Core | rundll.exe | Added by a variant of the RBOT WORM! Note - this is NOT the Win9x/Me system file of the same name as described here |
| X | rundll*** | die.exe [path] mdll.exe | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
| X | rundll*** | die.exe [path] secure.bat | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
| X | rundll*** | die.exe [path] secure.exe | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
| X | rundll*** | die.exe [path] ttg.exe | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
| X | Rundll16 | Rundll16.exe | Added by a number of VIRUSES, WORMS and TROJANS! |
| X | Rundll32 | Rundll32.exe | Added by a variant of the DVLDR TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\Fonts |
| U | RUNDLL32 | RUNDLL32.EXE NvQTwk,NvCplDaemon | Installed with display drivers for NVIDIA based graphics cards prior to late 2002, this entry allows the System Tray icon to be displayed - which gives access to (amongst others) the display settings (such as Antialiasing, OpenGL, Direct3D and colour) and Desktop Manager (nView). If you don't change display settings very often then this is not required and settings can be changed manually via display properties |
| U | RunDLL32 | RunDLL32.exe NvMCTray.dll,NvTaskbarInit | Installed with display drivers for NVIDIA based graphics cards since late 2002, this entry allows the System Tray icon to be displayed - which gives access to (amongst others) the display settings (such as Antialiasing, Rotation and Colour) and the Desktop Manager (nView). If you don't change display settings very often then this is not required and settings can be changed manually via display properties. No tray icon option is available in Vista. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest" |
| X | RunDLL32 | winupdate.exe | Added by an unidentified TROJAN! - possibly a BMBOT variant |
| X | Rundll32 | Windows.exe | Added by the QQPASS.E TROJAN! |
| U | Rundll32 | Rundll32.exe ptipbm.dll, SetWriteBack | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. Tells the drivers that the connected Drives should use the "Write Back" Caching. You can disable this if you don't want to use "Write Back" Caching or if you have not connected any driver to your Promise Controller |
| X | rundll32 | [path to worm] | Added by the AUTEX WORM! |
| ? | rundll32 | rundll32.exe ptipbmf.dll, SetWriteCacheMode | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
| X | rundll32 | rundll32.exe | Added by the SANKER WORM! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir% |
| X | rundll32 | csrss.exe | Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| U | rundll32 | rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent | If your system has Bluetooth (either integrated or via an adapter) and use's Microsoft's support software/drivers, this entry is required in order to successfully "pair" your system with a Bluetooth device (such as a mobile phone, PDA, headset) using this wireless protocol (via a PIN). Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here for more information |
| X | RUNDLL32 | rundl32.exe | Added by the DEMOTRY-A WORM! |
| X | rundll32 | rundll32.exe | Added by the AGENT-EZ TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %System%\SHELLEXT |
| X | Rundll32 | RUNDDLL32.EXE | Added by the STARTPAGE.AXH TROJAN! |
| X | rundll32 | kernel32.exe | Added by the STAP-C WORM! |
| X | rundll32 | kernel33.exe | Added by the STAP-D WORM! |
| X | rundll32 | MSDTC.exe | Added by the STAP-E WORM! |
| X | rundll32 | rookie.vbs | Added by the ROOKIE-A TROJAN! |
| X | rundll32 | rundll64.exe | Added by the DELF.BKC TROJAN! |
| U | rundll32 | rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent | If your system has Bluetooth (either integrated or via an adapter) and use's Microsoft's support software/drivers, this entry is required in order to successfully "pair" your system with a Bluetooth device (such as a mobile phone, PDA, headset) using this wireless protocol (via a PIN) |
| U | rundll32 | rundll32.exe nview.dll,nViewLoadHook | Part of NVIDIA's NVIEW Display Management Software - included in drivers for consumer and professional graphics products. In earlier drivers this entry enables the Desktop Manager and makes it's features such as multiple desktops and hot keys available to the user. Available via Control Panel → NVIDIA nView Desktop Manager |
| X | rundll32 | svchs0t.exe | Added by the PWSTEAL-E TROJAN! |
| X | rundll32 | ntdevice.exe | Added by the AGENT-OUM TROJAN! |
| X | rundll32 | userinit.exe | Added by the AGENT-OUM TROJAN! |
| N | Rundll32 cmicnfg | Rundll32 cmicnfg.cpl, CMICtrlWnd | System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel |
| Y | RunDll32 essprops | RunDll32 essprops.cpl, TaskbarIconWnd | Associated with a Logitech mouse - required for proper operation |
| U | Rundll32 P17 | Rundll32 P17.dll, P17Helper | ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
| X | Rundll32.exe | Proyecto1.exe | Added by the GRUEL WORM! |
| X | Rundll32.exe | Root.exe | Added by the GRUEL WORM! |
| X | Rundll32_7 | rundll32.exe msiefr40.dll,DllRunServer | BrowserAid adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "msiefr40.dll" file is located in %System% |
| X | Rundll32_8 | rundll32.exe inetp60.dll,DllRunServer | BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "inetp60.dll" file is located in %System% |
| X | Rundll32_8 | rundll32.exe 1.dll,DllRunServer | BrowserAid adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "1.dll" file is located in %Root% (i.e. C:\ D:\, etc) |
| X | RunDLL34 | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in %Windir%\fonts\font2 where no *.exe files should reside |
| X | rundll64 | [path to worm] | Added by the AUTEX WORM! |
| X | RundllSvr | Rundll.exe | Added by the HUAYU WORM! Note - this is NOT the Win9x/Me system file of the same name as described here |
| X | Rundllsystem32 | Rundllsystem32.exe | Added by the NETDEVIL.B BACKDOOR! |
| X | RUNDNB | Rundnb.exe | Added by the DIALER-C dialler! |
| X | Rundnm | Rundnm.exe | Added by the DELF-HA TROJAN! |
| X | RUNGogoTools | LaunchAdware.exe | GoGoTools adware |
| X | RUNGogoTools | GoGoLaunch.exe | GoGoTools adware |
| X | RUNHYPER | hyperx.exe | PurityScan/Clickspring adware |
| X | runing | win.exe | Added by the DELF-LC TROJAN! |
| X | RunJava | jcview.exe | Added by the AUTORUN-BEL WORM! |
| X | RunJava2 | systtray.exe | Added by the AUTORUN-BEL WORM! |
| X | RUNLOAD | l0ad.exe | PurityScan/Clickspring adware |
| X | RUNLOUD | loud.exe | PurityScan/Clickspring adware |
| U | Runmarc8mManager | marc8m95.exe | MARC Sound System Manager for the Marc 8 MIDI sound card - allows for easy adjustment of the settings |
| X | RunmeAtStartup | dx5.exe | Added by the BULILIT.A TROJAN! |
| U | RunNarrator | Narrator.exe | Associated with the Narrator accessibility feature on Windows XP. It is used to convert text to speech |
| X | Runner | lsass.exe [trojan filename] | Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Runner | csrss.exe | Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Runner | lsass.exe | Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Runner | svchost.exe | Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | runner1 | updater.exe | Added by the CRYPT.ULPM.GEN TROJAN! |
| X | runner1 | retadpu.exe | Added by the AGENT.SLZ TROJAN! |
| X | runner1 | mrofinu.exe | Added by the AGENT.CZC TROJAN! |
| X | runner1 | retadpu[random digits].exe | Added by the SMALL.CTV TROJAN! |
| X | runner1 | tsitra.exe | Added by the AGENT.ABFQ TROJAN! |
| X | runner1 | faceback.exe | Added by the DLOADR-BSX TROJAN! |
| U | RunOnce | RUNONCE.EXE | Part of MS Data Access Components - only required if you use these |