Share via

RuntimeBroker.exe a Virus?

Anonymous
2019-07-23T23:47:26+00:00

Windows security has blocked the subject "App" (as it titles it)  there is a file (my title) with this name in "C" drive dated 2018; I presume if this new 2019 one came via a normal Windows update it would have been excepted ergo it is likely malware.  Have no idea where it came from.  Does deletion seem the prudent option?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

5 answers

Sort by: Most helpful
  1. Anonymous
    2019-07-23T23:49:42+00:00

    Hi D. Charner

    Runtimebroker.exe is an essential Windows process. Below is a link to a guide that gives full details on this.

    May I ask what exactly was the message that you saw when it said that this was blocked?

    https://www-groovypost-com.cdn.ampproject.org/v...

    Note: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Virginia M 40,995 Reputation points Independent Advisor
    2019-07-24T11:47:36+00:00

    That file should be located in the C:\Windows\System32 folder - is this where you see the file? If not then it may be malware.

    Try running these programs:

    MBAM free: https://www.malwarebytes.com/mwb-download/

    Eset online scanner: http://www.eset.com/us/online-scanner/

    Adwcleaner: https://www.malwarebytes.com/adwcleaner/

    If these find one or more infections but do not fully remove them it will be wise to register with a malware removal site to receive dedicated malware removal instructions, an expert will remain with you throughout the process until confirmation that your PC is 100% clean.

    Malwarebytes virus/malware removal forum:

    https://forums.malwarebytes.com/forum/7-windows...

    Bleeping computer malware/virus removal forum:

    https://www.bleepingcomputer.com/forums/forum22...

    Disclaimer - This post contains reference to non-Microsoft websites and there may be ads on the page for products & services including products frequently classified as a PUP (Potentially Unwanted Product). Please thoroughly research any product / service advertised on the page before you decide to use them. Your discretion is very much advised.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Virginia M 40,995 Reputation points Independent Advisor
    2019-07-25T18:17:43+00:00

    Check within the program folders & also the programdata folder (this is hidden).

    Just in case try running these programs:

    MBAM free: https://www.malwarebytes.com/mwb-download/

    Eset online scanner: http://www.eset.com/us/online-scanner/

    Adwcleaner: https://www.malwarebytes.com/adwcleaner/

    If these find one or more infections but do not fully remove them it will be wise to register with a malware removal site to receive dedicated malware removal instructions, an expert will remain with you throughout the process until confirmation that your PC is 100% clean.

    Malwarebytes virus/malware removal forum:

    https://forums.malwarebytes.com/forum/7-windows...

    Bleeping computer malware/virus removal forum:

    https://www.bleepingcomputer.com/forums/forum22...

    Disclaimer - This post contains reference to non-Microsoft websites and there may be ads on the page for products & services including products frequently classified as a PUP (Potentially Unwanted Product). Please thoroughly research any product / service advertised on the page before you decide to use them. Your discretion is very much advised.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2019-07-25T15:24:35+00:00

    The one dated 2018 is in the C System 32 folder; the one that is blocked with exactly the same name but dated 2019  I can't find so it's not an urgent issue; presumably one day it will be found again; I think I got a notification about it but can't find anything in Settings/Security.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2019-07-23T23:58:39+00:00

    Hello,

    My name is Jennifer, an independent advisor trying to help.

    What RuntimeBroker.exe does that program, among other things, is to change some rules belonging to local Windows directives, I advise you not to delete it and analyze it with your antivirus and if it is to leave it in quarantine do it ..

    Although that shouldn't cause you trouble

    Regards.

    Was this answer helpful?

    0 comments No comments