| Status Code | Name | Command | Description |
| Y | r_server | r_server.exe | Radmin - remote admistrator server |
| N | RxMon | rxmon9x.exe | Dell Resolution Assistant |
| X | rvde | N/A | Related to li-speed**** |
| X | RVP | bpc.exe | Spyware included with the latest version of Grokster. Also see here |
| X | Run_cd | Run_cd.exe | Added by the GHOST.23 TROJAN!
|
| ? | RUSBHOLoader | rundll32.exe RUSBHOLoader.dll, AutoRegister | ?? |
| X | Run[0] | syscnfg.exe | Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
| X | RunWindowsUpdate | uptodate.exe | BrowserAid/BrowserPal foistware |
| X | runwin32 | runwin32.exe | Added by the ESEARCH-A TROJAN! |
| U | RunSysd32 | RunSysd32.exe | DesktopShield2000 by St?phane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within |
| X | RunServices | runsvc32.exe | Added by the AGOBOT.QJ WORM!
|
| X | RunProg | wini.exe | Added by the OPTIX.04.D TROJAN! |
| U | RunOnce | RUNONCE.EXE | Part of MS Data Access Components - only required if you use these |
| X | RunProg | Server.exe | Added by the OPTIX.04.A TROJAN! |
| X | Rundnm | Rundnm.exe | Added by the DELF-HA TROJAN!
|
| X | Rundllsystem32 | Rundllsystem32.exe | Added by the NETDEVIL.B TROJAN! |
| X | RundllSvr | Rundll.exe | Added by the HUAYU WORM!
|
| X | Rundll32_8 | rundll32.exe inetp60.dll, DllRunServer | BrowserAid parasite variant |
| X | rundll64 | [path to worm] | Added by the AUTEX WORM! |
| X | Rundll32_7 | rundll32.exe MSIEFR40.DLL, DllRunServer | BrowserAid "Featured Results" hijacker variant |
| X | Rundll32.exe | Root.exe | Added by the GRUEL WORM! |
| X | Rundll32.exe | Proyecto1.exe | Added by the GRUEL WORM! |
| N | Rundll32 cmicnfg | Rundll32 cmicnfg.cpl, CMICtrlWnd | System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel |
| U | rundll32 | RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent | Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup |
| X | rundll32 | csrss.exe | Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | rundll32 | rundll32.exe | Added by the SANKER WORM! Note that the valid "rundll32.exe" resides in C:WindowsSystem32 wheras this version resides in C:Windows |
| ? | rundll32 | rundll32.exe ptipbmf.dll, SetWriteCacheMode | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
| X | rundll32 | [path to worm] | Added by the AUTEX WORM! |
| X | Rundll32 | Rundll32.exe ptipbm.dll, SetWriteBack | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. If used is it required? |
| X | Rundll32 | Windows.exe | Added by the QQPASS.E TROJAN! |
| X | RunDLL32 | winupdate.exe | Added by an unidentified TROJAN! - possibly a BMBOT variant |
| U | rundll32 | Rundll32.exe Wf2kcpl.dll DllLoadDefaultSettings | Loads default settings for Leadtek Winfast graphics cards |
| N | RunDLL32 | RunDLL32.exe NvMCTray.dll, NvTaskbarInit | System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
| N | RUNDLL32 | RUNDLL32.EXE NvQtwk, NvCplDaemon | System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here) |
| X | Rundll16 | Rundll16.exe | Added by a number of VIRUSES, WORMS and TROJANS! |
| X | Rundll32 | Rundll32.exe | Added by the DVLDR TROJAN! Note - this is not the valid "Rundll32.exe" as it's in the WindowsFonts directory |
| X | rundll*** | die.exe [path] ttg.exe | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
| X | rundll*** | die.exe [path] secure.exe | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
| X | rundll*** | die.exe [path] secure.bat | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
| X | rundll*** | die.exe [path] mdll.exe | Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
| X | rundli32 | rundli32.exe | Added by the LADE WORM! |
| X | RunDLL | rundll32.exe bridge.dll, Load | Flingstone.com browser hijacker |
| X | rundl332 | math.exe ...pluged.exe | Added by the DOOMJUICE WORM! |
| X | Runapp32 | Runapp32.exe | Added by the NEODURK TROJAN! |
| X | Rund1l32 | Winfi1e32.exe | Added by the MERTIAN WORM! |
| N | runAP | runAP.exe | Not required but what is it? |
| U | RunAlert | AService.exe | MSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you "overclock" your system |
| X | run= | real.exe | Added by a variant of the LOVGATE WORM! |
| ? | run= | win.ini | ?? |
| X | run= | RAVMOND.exe | Added by a variant of the LOVGATE WORM! |
| Y | run= | smsrun16.exe | Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs |
| X | run= | fntldr.exe | CoolWebSearch parasite variant |
| X | run= | svcinit.exe | CoolWebSearch parasite variant |
| ? | run= | wallflip.exe | Desktop wallpaper changer? |
| U | run= | ramsys.exe | Advanced Startup Manager from Rays Lab |
| X | run= | ptlseq.cpl | PhoenixNet BIOS adware. See here |
| N | run= | pcfix2k.exe | pcfix2k splash screen |
| N | run= | lxdboxcp.exe | Lexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS |
| N | run= | hpfsched | HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature |
| N | run= | cmmpu.exe | MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI) |
| X | Run32dll | ocxdll.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | run32dll | task32.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | run32dll | WINClock.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | Run XP Service Pack | xpservicepack.exe | Added by the SDBOT.AQA WORM! |
| X | Run TaskMrg | csrss.exe | Added by the LDPINCH-W TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| U | Run StartupMonitor | StartupMonitor.exe | Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
| U | Run POPFile in background | wperl.exe | POPFile - E-mail spam blocker |
| U | RuLaunch | RuLaunch.exe | Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis |
| X | Run MSupdt32 | wscript MSupdt32.vbs | Added by the CASER WORM! |
| U | Run POPFile in background | perl.exe | POPFile - E-mail spam blocker |
| X | Ruby14 | Ruby14.exe | Added by the FIGHTRUB-A WORM!
|
| X | Ruby13 | Ruby13.exe | Added by the MEXER.E WORM! |
| Y | rtvscn95 | RTVSCN95.EXE | Real-time virus scanner component of Norton Anti-Virus Corporate Edition |
| X | rtos | rtos.exe | IRC trojan |
| ? | RTStartMute | N/A | ?? |
| Y | RTMonitor | RTMonitor.exe | Cheyenne (now eTrust) antivirus |
| N | RtlMon.exe | RtlMon.exe | Monitor for RealTek network card |
| X | RSS | rundll32 RSSToolbar.dll, DllRunMain | "Related Sites" toolbar - SearchAndClick hijacker variant |
| ? | RSRCMTZ | RSRCMTZ.exe | ?? |
| U | rsMenu | rsMenu.exe | Synchronizes a Casio PDA with MS Outlook |
| U | rscmpt | rscmpt.exe | Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status |
| X | RRMedic | rrmedic.exe | Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection |
| Y | RPCSS.exe | rpcss.exe | Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here |
| X | RPC Patcher | [path to worm] | Added by the BOLGI WORM! |
| X | RPC | MSschost.exe | Added by a variant of the GAOBOT/AGOBOT WORM! |
| U | RP32 | rp32.exe | ControlIT (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems. |
| Y | RoxioEngineUtility | EngUtil.exe | Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking |
| N | RoxioDragToDisc | DrgToDsc.exe | Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly |
| N | RoxioAudioCentral | RxMon.exe | Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. "Includes a player, media manager, ripper, tag and sound editor - integrated in a single application". Not required for Roxio to work properly. |
| ? | Roxio Engine | MSMNGR32.EXE | Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN! |
| N | RoxAssist | RoxAssist.exe | Roxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use "Add Remove Programs" in "Control Panel"). Can be run manually |
| ? | ROUTD | ROUTD.exe | ?? |
| X | romahere3 | ************.exe [* = random char] | CoolWebSearch parasite related |
| U | romahere2 | ************.exe [* = random char] | CoolWebSearch parasite related |
| X | romahere | matrixhere.exe | CoolWebSearch parasite related |
| ? | roketpipe | rpclient.exe | ?? |
| U | Rocket.Time | RocketTime.exe | Time synchronization software from Rocket Software |
| N | RoboFormWatcher | RoboFormWatcher.exe | AI Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs |
| N | RoboForm | RoboTaskBarIcon.exe | Roboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin |
| X | rngmf | [path to trojan] | Added by the RANKY.C TROJAN! |
| ? | rndll2 | rndll2.exe | May be related to the DivX program as a *.dat file in the same directory had "DivXPro505Bundle.exe" mentioned within? |
| U | RNBOStart | sentstrt.exe | Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools |
| N | rmmon | mprmmon.exe | Resource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card |
| ? | RMremote | RmRemote.exe | Remote control driver for REALmagic Xcard. Is it required? |
| U | rmctrl | rmctrl.exe | Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
| ? | RjLyraInstaller | setup.exe | ?? |
| U | RivaTunerStartupDaemon | RivaTuner.exe | RivaTuner for tweaking nVidia graphics cards. Required if you make any changes |
| U | RivaTuner | RivaTuner.exe | RivaTuner for tweaking nVidia graphics cards. Required if you make any changes |
| X | rIOphosIs | rIOPHosIs.vBS | Added by the RIOSYS MACRO! |
| U | Ring Central Fax | rcenterrll.exe | Only needed if you want a PC to answer faxes automatically |
| U | RhinoBlocker | RhinoBlocker.exe | RhinoBlocker - pop-up stopper |
| N | RHSI SHS | SHS.exe | Rogers Hi-Speed Internet software. "Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash" |
| X | Rhino | [random name]32.exe | Added by the BOFRA.A WORM! |
| U | RH | rh32.exe | EuroFonts - adds Euro symbols to pre-Euro computers |
| N | RFX_auto_upgrade | rundll32.exe npvpg005.dll | A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade |
| Y | rfw | Rfw.exe | RAV AntiVirus
|
| ? | rfwydg | rfwydg.exe | ?? |
| X | RFTray | RFTRay.exe | Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs |
| U | rfagent | rfagent.exe | Registry First Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders |
| N | RexSyMon | rexsymon.exe | Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC |
| U | RevoTaskbarApp | RevoTask.exe | Control Application for M-Audio Revolution 7.1 sound card. The sound card will function without it - but changes to speaker setup and sound modification (Bass/Treble etc) will not be available |
| U | RetrieverScheduler | retrieverscheduler.exe | 80-20 Retriever from 80-20 - "80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information". Real-time scheduler - shortcut available |
| X | retime | retime.exe | Added by the GIPMA TROJAN! |
| U | ResumeFixClocks | resumefix.exe | Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards |
| U | Resume Copy | copyfstq.exe | Part of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that function |
| X | restory | restory.exe | Added by the RETSAM TROJAN! |
| Y | RestoreIT! | VBPTASK.EXE | RestoreIT! from FarStone "allows you to recover instantly your files, system configuration, and even your operating system, to any point in time prior to the data loss or system failure." |
| ? | Restart_VS | Viewsonic.exe | Could be a left-over from the installation of a Viewsonic flat panel display |
| ? | Restart Watch | Watch.exe | Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required? |
| U | Restart WSC Setting | wscrestp.exe | WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes |
| N | Resource Meter | rsrcmtr.exe | Windows Resource Meter. Available via Start -> Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes |
| N | Resolution Assistant | matcli.exe | Dell Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decide |
| U | RepliGo Assistant | RepliGoMon.exe | Cerience RepliGo software - "any document you have on your PC can be transferred to your mobile device" |
| X | requester | requester.5.exe | Adware downloader, identified as TrojanProxy.Win32.Delf.h
|
| ? | RemStart | remstart.exe | Part of McAfee's Remote Desktop 32 Agent application. What does it do and is it required? |
| ? | RenolB | ib.exe | ?? |
| N | Removecpl | Removecpl.exe | Related to a Belkin 54Mbps Wireless Utility Control Panel applet |
| X | Removed.exe | Removed.exe | GatorCheat - adware downloader |
| U | RemoteControl | PDVDServ.exe | Remote Control background application for CyberLink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
| N | Remote_Agent | RemoteAgent.exe | Cyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings, you will need this, otherwise can be disabled. Available via Start -> Programs |
| U | RemoteCenter | RcMan.exe | Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats |
| U | RemoteControl | rmctrl.exe | Remote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
| Y | RemoteAgent | RAUAgent.exe | Trend Micro's Office Scan Client, see here - "Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates" |
| X | Remote Procedure Calls | mswinc.exe | Added by the RBOT-IT WORM!
|
| X | Remote Procedure Calls | win.exe | Added by the SDBOT-QI WORM!
|
| X | Remote Procedure Calls | mswinrpc.exe | Added by the RBOT.KJ WORM! |
| X | Remote Procedure Call Locator | RUNDLL32.EXE reg678.dll ondll_reg | Added by a variant of the LOVGATE WORM! |
| X | Remote Procedure Call For Windows 32bit | rpc.exe | Added by the RBOT-MD WORM! |
| X | Remote Procedure Call | winsysrpc.exe | Added by the SDBOT-PS WORM! |
| X | Remote Procedure Call | winrpc.exe | Added by the RBOT-KM WORM! |
| U | remote master | remote master.exe | Required if you want your ASUS Remote control to work at all. Available via Start -> Programs |
| U | Remote Management Agent | zenrc32.exe | Part of Novell's ZENworks - "Complete End-to-End Directory-enabled Network Management". Installed on a managed workstation fo an administrator to remotely manage the workstation. Required if the PC is a managed workstation |
| U | Remote Desktop Computing | marspc.exe | Marspc Remote Desktop Computing |
| N | Remote Control | Rc.exe | Hinet Hi-Five ISP software |
| X | Remote Access Slave | Synchost.exe | Added by the RIPJAC TROJAN! |
| U | Remote Access | rnaapp.exe | Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed |
| X | Remndr | CsRemnd.exe | CasinoOnline foistware |
| U | RemindMe | RemindMe.exe | Remind-Me - calendar software |
| N | Remind_XP | Remind_XP.exe | HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list |
| N | reminder-ScanSoft Product Registration | remind32.exe | Registration reminder for ScanSoft products such as PaperPort |
| N | Reminder-ranXXXXX | remind32.exe | Registration reminder widget for Rand Mcnally maps |
| N | Reminder-cpqXXXXX | remind32.exe | Compaq printer Registration |
| N | Reminder-hpcXXXXX | remind32.exe | HP CD-Writer Registration |
| N | Reminder | Remind_XP.exe | HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list |
| N | RemHelp | Remhelp.exe | BT Voyager ADSL Modem Help related |
| N | Reminder | reminder.exe | From MS Money. Reminds you of your bills |
| X | reload | reload.vbs | Added by the LOVELETTER.AS VIRUS! |
| U | ReleaseRAM | RRAM.exe | "Release RAM allows your computer to run faster and uses your computer's RAM more efficiently". Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| X | reg_key | loader_name.exe | Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS! |
| X | Reg_WFT | Regsysw.com | Added by the WILSEF VIRUS! |
| X | reg_key | FUKULAMER.exe | Added by the BEAGLE.AH WORM! |
| U | Regx10EXE | atix10.exe | ATI Remote Wonder - PC wireless remote control |
| X | RegWrite | csrss.exe | Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | RegVer | REGVER.EXE | Added by the LATINUS.16 TROJAN! |
| ? | regtmlp | N/A | ?? |
| U | RegTweak | RegTwk.exe | Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface |
| U | REGSVR32 | regsvr32.exe ctasio.dll | ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
| X | regsvr | regsvr.exe | Added by the WEBMONEY-G TROJAN!
|
| X | regsvc32 | regsvc32.exe | Homepage hijacker that changes your homepage to an adult content site |
| X | Regsv | regsv.exe | Search hijacker - redirecting to scheo.com |
| X | regsrv | regsrv.exe | Added by the OPTIXPRO.11 TROJAN! |
| N | RegShave | regshave.exe | Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly
|
| X | regservices.exe | regservices.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| Y | Regrun2 | WatchDog.exe | Greatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc |
| X | RegRun | mActiveX.exe | Added by a variant of the RBOT WORM!
|
| Y | RegProt | Regprot.exe | RegistryProt from Diamond Computer Systems - protects the system registry against changes |
| U | RegistryMechanic | RegMech.exe | Registry Mechanic for Windows - "you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages" |
| X | RegistryChk | winbackup.exe | Added by the MERTIAN WORM! |
| X | Registry Services | Registry.exe | Added by the DOWNLOADER.CILE TROJAN! |
| X | Registry Server | regsrv32.exe | Added by the RBOT-GM WORM!
|
| X | Registry Scanner | regscanr.exe | Added by a variant of the OPTIX TROJAN! |
| X | Registry Loader | regloadr.exe | Added by the GAOBOT.AO WORM! |
| X | Registry Loader | winhlpp32.exe | Added by the GAOBOT.AO WORM! |
| X | Registry Checkup | winreg.exe | Added by an unidentified WORM or TROJAN!
|
| X | Registry | wscript.exe | Added by the VBSWG.AQ WORM! |
| N | Registration-Studio 8 | RegTool.exe | Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems |
| U | RegisterDropHandler | REGIST~1.EXE | Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
| ? | Register SeqChk | regsvr32.exe ..csseqchk.dll | ?? |
| N | Register MediaRing Talk | register.exe | If you don't want to register MediaRing and be reminded about it every bootup disable it |
| ? | reginfo32 | reginfo32.exe | ?? |
| U | RegFreeze | regfreeze.exe | RegFreeze anti-spyware software |
| X | REGEDIT | Regsrv32.com | Added by the SOUTHGHOST WORM! |
| X | regedit | regedit.exe | Added by the BRID.A WORM! Note - resides in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP). The valid "regedit.exe" resides in C:Windows (Win9x/Me/XP) or C:Winnt (WinNT/2K) |
| X | RegDoneEx | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup! |
| X | RegDone Ex | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
| X | RegDone | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | Regcxn | Regcxn.exe | Added by the COIBOA-D TROJAN!
|
| X | RegDone | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | RegCompres | REGCPM32.EXE | Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return |
| X | RegCompres | Regcpm32.exe | Added by the POLDO.B TROJAN! |
| X | RegCleaner | SYSio32.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware |
| X | Regcheck | ~CAB001.EXE | Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS! |
| X | Reg32 | reg33.exe | CoolWebSearch parasite variant |
| X | reg32 | reg32.exe | Added by the NOUPDATE.B TROJAN! |
| X | Reg32 | Reg32.exe | Hijacker - redirecting to only-virgins.com |
| X | Reg Services | Winboot32.exe | Added by the RBOT.PB WORM! |
| X | Reg Service | winsy.exe | Added by a variant of the SPYBOT WORM!
|
| N | Refresh | Refresh.exe | (Iomega) Refresh - loads the Iomega desktop icons at startup |
| X | Reg | Reg.hta | Homepage hi-jacker. Removal instructions here |
| U | Referee | referee.exe | MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run |
| X | REEGRUN | [path to file] | Added by the SECDROP.AI TROJAN
|
| N | Redline Taskbar | taskbar.exe | Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards |
| X | redirect | redirect*.exe | Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit |
| N | Red Flag | redflag.exe | PMS prediction program with modes for guys and girls - no longer available |
| X | Red Swoosh EDN Client | RSEDNClient.exe | Red Swoosh - mechanism used by web sites to allow you to download files from those sites quicker and more efficiently. Note from the license agreement they automatically update the software and share non-personally identifiable information with others in the network |
| N | RecShe | RecSche.exe | Recording scheduler for WatchTV Capture Card (TV Tuner card) |
| ? | RecoverFromReboot | RecoverFromReboot.exe | ?? |
| ? | RecoverFromReboot | RECOVE~1.EXE | ?? |
| ? | RecoverFromReboo | RecoverFromReboot.exe | ?? |
| ? | RecoverFromReboo | RECOVE~1.EXE | ?? |
| N | Recover | N/A | Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete |
| X | Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} | RH.DLL | SmartPops adware |
| N | Reclip | reclip.exe | Reclip Popup Clipboard manager |
| Y | Recguard | recguard.exe | On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense |
| N | Reboot | Reboot.exe | MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards |
| X | RealUpdater | realupd.exe | Added by the PARLAY or MITGLIEDER.I TROJANS! |
| N | RealTray | RealPlay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
| ? | RealTimeUpdate | RealTimeUpdate.exe | Product description in properties is "InternetExplorerCommunicationAgent Module" ? |
| Y | Realtime Monitor | realmon.exe | Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates |
| ? | Realtime Audio Engine | mmrtkrnl.exe | ?? |
| N | Realsched | realsched.exe | Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry |
| ? | Realpopup | Realpopup.exe | RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor" |
| X | Realplayer One | realplay.exe | Added by the RBOT-NK WORM!
|
| X | realplay ml097e | realplay.exe | Variant of the RapidBlaster parasite (in a "RealPlay" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name |
| X | realplay lptt01 | realplay.exe | Variant of the RapidBlaster parasite (in a "RealPlay" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name |
| X | realone_nt2003 | moniker.exe | Added by the SNONE.A WORM! |
| N | RealJukeboxSystray | tsystray.exe | System Tray icon for RealJukebox |
| N | RealDownload | RealPlay.exe | Download manager. Available via Start -> Programs |
| X | RealDownload Express | npnzdad.exe | Advertising spyware |
| N | Reality Fusion GameCam SE | RFTRay.exe | System Tray access for Logitech's Reality Fusion GameCam. For more details see here. Available via Start -> Programs |
| X | RealAudio | RealAudio.exe | Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player |
| X | Real player updater | realupd.exe | Added by the PARLAY TROJAN! |
| X | Real-Tens | Real-Tens.exe | DownloadWare based advetising spyware |
| X | Real Internet Player | Reaiplay.exe | Added by a variant of the SPYBOT WORM! |
| X | Reactor9 | [random name]32.exe | Added by the BOFRA.E WORM!
|
| X | readdb40 | rundll32.exe [path] readdb40.dll, EnableRunDLL32 | LZIO.com adware downloader |
| X | Reactor7 | [random name]32.exe | Added by the BOFRA.B WORM! |
| X | Reactor8 | [random name]32.exe | Added by the BOFRA.E WORM! |
| X | Reactor6 | [random name]32.exe | Added by the BOFRA.C WORM! |
| X | Reactor5 | [random name]32.exe | Added by the BOFRA.D WORM! |
| X | Reactor3 | [random name]32.exe | Added by the BOFRA.A WORM! |
| X | rdvs | [worm filename] | Added by the ULTIMAX WORM! |
| X | RDLL | RunDll16.exe | Added by the SDBOT.F TROJAN! |
| U | RDClient | RDCLIENT.EXE | Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection |
| X | RCSync | RCSync.exe | PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware |
| U | RCScheduleCheck | RCSCHED.EXE | Scheduler for VCOM's Recovery Commander - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running" |
| X | Rcf Driver | rcf.exe | Added by the RANDEX.BLD WORM! |
| X | rbenh ml***e | rbenh.exe | Variant of the RapidBlaster parasite (in a "RBEnhance" folder in Program Files) where *** represents random digits. It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | rb32 ml097e | rb32.exe | Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | rb32 lptt01 | rb32.exe | Variant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| N | Ray Process Killer | Prkill.exe | Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL+ALT+DEL instead |
| ? | rav_temp.exe | rav_temp.exe | ?? |
| X | RavTimXP | [worm filename] | Added by the WULLIK.B WORM! |
| X | RavTimeXP | [worm filename] | Added by the WULLIK.B WORM! |
| X | RavTimer | RavTimer.exe | RAV AntiVirus
|
| Y | RavMon | RavMon.exe | RAV AntiVirus
|
| X | RavTime | Mstray.exe | Added by the WUKILL.A WORM! |
| X | RAVEN_VLZS.EXE | RAVEN_VLZS.EXE | Another eAcceleration program - spyware. Read their privacy statement here |
| X | rate.exe | ********.exe [* = random char] | Unidentified adware
|
| Y | RAV8Tray | ravtray8.exe | RAV anti-virus related |
| X | rate.exe | i11r54n4.exe | Added by the BEAGLE.E or BEAGLE.F or BEAGLE.G or BEAGLE.H or BEAGLE.I WORMS! |
| X | RasCon Remote Access Service Manager | rasmngr.exe | Added by the SPYBOT.EM WORM! |
| X | Rase | boln.exe | PurityScan/Clickspring adware
|
| Y | Raptor Mobile | vpnservices.exe | Symantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking |
| X | RapidBlaster | rb32.exe | Homepage hijacker (adult content) - see this newsgroup thread |
| U | Rapid Restore | rrpcsb.exe | XPoint "Rapid Restore PC" - a "Managed Recovery? solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user" |
| Y | RapApp | RAPAPP.EXE | Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch |
| X | RandomWin32 | mgnwin32.exe | Added by the SDBOT-DV WORM! |
| X | Randex virus built for IRBMe | irbme.exe | Added by the RANDEX.RH WORM! |
| U | RAMpage | RAMpage.exe | Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source |
| U | RamIdle | ramidle.exe | RAM Idle - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| U | RAMDef | ramdef.exe | Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| X | RamBooster2 | rb.exe | Added by the AKAK TROJAN! |
| U | RAMASST | RAMASST.exe | Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs |
| U | RadioSvr | RadioSvr.EXE | Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network |
| U | RadBoot | RadBoot.exe | RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings |
| Y | Rabo Session Monitor | RaboSessionMon.exe | Related to RaboBank electronic banking software |
| N | RadarSync | RadarSync.exe | Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically |
| X | RabbitWannaHome | rabbit.exe | Added by the MIMAIL.S WORM! |
| X | RA Server | Slave.exe | Added by the RA TROJAN! |
| X | RA Server | Slave.exe | Added by the RA TROJAN! |
| X | RabbitWannaHome | rabbit.exe | Added by the MIMAIL.S WORM! |
| Y | Rabo Session Monitor | RaboSessionMon.exe | Related to RaboBank electronic banking software |
| N | RadarSync | RadarSync.exe | Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically |
| U | RadBoot | RadBoot.exe | RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings |
| U | RadioSvr | RadioSvr.EXE | Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network |
| U | RAMASST | RAMASST.exe | Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs |
| X | RamBooster2 | rb.exe | Added by the AKAK TROJAN! |
| U | RAMDef | ramdef.exe | Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| U | RamIdle | ramidle.exe | RAM Idle - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| U | RAMpage | RAMpage.exe | Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source |
| X | Randex virus built for IRBMe | irbme.exe | Added by the RANDEX.RH WORM! |
| X | RandomWin32 | mgnwin32.exe | Added by the SDBOT-DV WORM! |
| Y | RapApp | RAPAPP.EXE | Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch |
| U | Rapid Restore | rrpcsb.exe | XPoint "Rapid Restore PC" - a "Managed Recovery? solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user" |
| X | RapidBlaster | rb32.exe | Homepage hijacker (adult content) - see this newsgroup thread |
| Y | Raptor Mobile | vpnservices.exe | Symantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking |
| X | RasCon Remote Access Service Manager | rasmngr.exe | Added by the SPYBOT.EM WORM! |
| X | Rase | boln.exe | PurityScan/Clickspring adware
|
| X | rate.exe | i11r54n4.exe | Added by the BEAGLE.E or BEAGLE.F or BEAGLE.G or BEAGLE.H or BEAGLE.I WORMS! |
| X | rate.exe | ********.exe [* = random char] | Unidentified adware
|
| Y | RAV8Tray | ravtray8.exe | RAV anti-virus related |
| X | RAVEN_VLZS.EXE | RAVEN_VLZS.EXE | Another eAcceleration program - spyware. Read their privacy statement here |
| Y | RavMon | RavMon.exe | RAV AntiVirus
|
| X | RavTime | Mstray.exe | Added by the WUKILL.A WORM! |
| X | RavTimer | RavTimer.exe | RAV AntiVirus
|
| X | RavTimeXP | [worm filename] | Added by the WULLIK.B WORM! |
|