File details
File name: rundll32.exe
Name: Windows host process (Rundll32)
Description: Microsoft® Windows® Operating System
Version: 6.3.9600.16384 (winblue_rtm.130821-1623)
Product version: 6.3.9600.16384
Size: 48.5 KB
Original file name: RUNDLL32.EXE.MUI
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0005320959%
Privileged CPU:
0.0003533822%

User CPU:
0.00017871363340%

Privileged CPU time: 781.25 ms
Privileged CPU time /min: 1 ms
CPU cycle count:
432,948,609
CPU cycle count /min: 13,088,006
 | Memory utilization averages |
Committed memory:
200.97 MB
Peak committed memory: 251.41 MB
Paged memory:
15.83 MB
Peak paged memory: 49.93 MB
Paged system memory:
354.56 KB
Non-paged system memory: 33.19 KB
Working set memory:
26.76 MB
Peak working set memory: 66.11 MB
Min working set memory: 5.14 MB
Private memory:
15.83 MB
Page faults:
37,520
Page faults /min: 63
 | Process I/O averages |
Total read operations:
760
Read operations /min: 1
Total read transfer: 1.08 MB
Read transfer /min: 1.83 KB
Total write operations:
363
Write operations /min: 1
Total write transfer: 863.32 KB
Write transfer /min: 1.44 KB
Total other operations:
7,471
Other operations /min: 10
Total other transfer: 377.31 KB
Other Transfer /min: 610 Bytes
 | GUI Object Averages |
GDI objects:
27
Peak GDI objects: 34
USER objects:
22
Peak USER objects: 42
Resources
Handle count average: 322
Thread count average: 10
Thread resource averages
Total CPU: 0.001225691870%
Privileged CPU: 0.000372664927%
User CPU: 0.000853026943%
CPU Cycle count /sec: 40,164
Module memory size: 64 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
Parent Process
Process Command
"C:\Windows\System32\rundll32.exe" "C:\Users\liang\funshion\base\FunshionPopup.dll",runDllW \\.\pipe\NamedPipe.511565390
Autoplay handler details
Name: MSPhotoAcqHWEventHandler
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPhotoAcqHWEventHandler
Scheduled task details
Name: \{00BAB955-E3A4-40EE-A715-E595C89513B0}
Startup files (user) run details
Name: uprkr
Command: rundll32.exe ",RetrieveKey
Approved shell extension details
CLSID: {9D687A4C-1404-41ef-A089-883B6FBECDE6}
User start menu folder details
Name: lsass.exe
Startup files (all users) run details
Name: CTMasterOnOffMonitor
Command: Rundll32.exe CTMWatch.dll StartCTMasterOnOffWatch
Image hashes
MD5: be1dae43dfbca94fb6b4157c1b16923e
SHA-1: aa4e976039bece6dbd242c97a019fd29a6dc63f7
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.05669
File packed: No
Import Table
api-ms-win-core-path-l1-1-0.dll

imagehlp.dll

ImageDirectoryEntryToData
kernel32.dll

ExitProcess
GetCommandLineW
EncodePointer
GetNativeSystemInfo
SetFilePointer
SetErrorMode
FreeLibrary
CreateProcessW
LoadLibraryExW
GetCurrentProcess
SetProcessDEPPolicy
WaitForSingleObject
SetEvent
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
GetSystemDirectoryW
WideCharToMultiByte
FormatMessageW
ReadFile
CreateFileW
ReleaseSRWLockShared
Wow64EnableWow64FsRedirection
GetLastError
GetProcAddress
LocalAlloc
IsWow64Process
CreateEventW
DecodePointer
HeapSetInformation
AcquireSRWLockShared
GetCurrentThreadId
CloseHandle
LocalFree
SetUnhandledExceptionFilter
GetStartupInfoW
InterlockedCompareExchange
InterlockedExchange
Sleep
QueryPerformanceCounter
GetCurrentProcessId
GetModuleHandleA
GetSystemTimeAsFileTime
GetTickCount
UnhandledExceptionFilter
TerminateProcess
QueryActCtxW
SearchPathW
SetSearchPathMode
GetModuleHandleW
CreateActCtxW
ActivateActCtx
ResolveDelayLoadedAPI
DelayLoadFailureHook
ReleaseActCtx
GetFileAttributesW
DeactivateActCtx
CompareStringW
lstrlenA
lstrlenW
LoadLibraryW
LoadLibraryA
LoadLibraryExA
msvcrt.dll
ntdll.dll

NtOpenProcessToken
NtQueryInformationToken
NtSetInformationToken
NtClose
RtlNtStatusToDosError
RtlImageNtHeader
NtSetInformationProcess
shlwapi.dll

PathIsRelativeW
SHSetThreadRef
user32.dll

CreateWindowExW
SetWindowLongW
GetClassNameW
SetClassLongW
RegisterClassW
LoadIconW
GetClassLongW
DestroyWindow
GetMessageW
DefWindowProcW
GetWindow
CharNextW
GetWindowLongW
LoadCursorW
TranslateMessage
LoadStringW
PostThreadMessageW
MessageBoxW
DispatchMessageW