Windows Vista Tips


Processes beginning with r

The table below includes any process titles beginning with r, from which further information can be found by clicking on the process title. The icon beside the information can be used to quickly determine if this is a safe file in combination with the key below:



This file is normally safe to leave running. In most cases, this file is not required to run on startup and can be run manually. Warning, this file may be a virus, spyware, resource hog and running it is not recommended. This file may or may not be necessary to load on startup, depending on your circumstances. No information is available for this item.

[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]

Processes beginning with r:

File Type Process Name and Information
R
Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
RA Server
Added by the RA TROJAN!
RabbitWannaHome
Added by the MIMAIL.S WORM!
Rabo Session Monitor
Related to RaboBank electronic banking software
RaConfig2500
RaLink wireless LAN configuration utility
RadarSync
Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically
RadBoot
RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings
Radio365Agent
Radio365 - create playlists and broadcast live straight from your PC!
RadioSvr
Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network
RAID Event Monitor
IAA Event Monitor User Notification Tool - part of Intel? Application Accelerator - "a performance software package for desktop PCs using select Intel? chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
RaidTool
VIA V-RAID Tool - hard disk striping/mirroring utility for increased performance and reliability
Rainlendar
Rainlendar is a customizable calendar that displays the current month
Rainlendar2
Rainlendar is a customizable calendar that displays the current month
Rainmeter
Rainmeter is a customizable performance meter, which can display the CPU load, memory utilization, etc
RAM Idle Professional
RAM Idle LE - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
RAMASST
Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs
RamBooster2
Added by the AKAK TROJAN!
RAMDef
Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
RAMDrive
Virtual Hard Drive (Ram Drive) from Farstone - takes a portion of your system memory (RAM) and uses it to simulate a hard disk drive
RamIdle
RAM Idle LE - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
RAMpage
Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source
Randex virus built for IRBMe
Added by the RANDEX.RH WORM!
random
Added by the DLOADER-KM TROJAN!
Random Interface Network
Added by the DELBOT-P WORM!
Random Interface Network Manager
Added by the DELBOT-L WORM!
Random Unique ID
Added by the XROVE-A WORM!
RandomWin32
Added by the SDBOT-DV WORM!
rant
Added by the RBOT-ZB WORM!
RapApp
Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch
Rapdata
Added by the QQPASS-V TROJAN!
Rapdatae
Added by the QQPASS-S TROJAN!
Rapdatybs
Added by the PWS-ACP TROJAN!
Rapid Restore
XPoint "Rapid Restore PC" - a "Managed Recovery? solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user"
RapidBlaster
RapidBlaster parasite. Recommended you use RapidBlaster Killer to uninstall - see here
Raptelnet
Added by the QQPASS-AA TROJAN!
Raptelt
Added by the QQPASS-AB TROJAN!
Raptor Mobile
Symantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking
RasCon Remote Access Service Manager
Added by the SPYBOT.EM WORM!
rasctrs
Hijacker, also detected as the ADWAHECK TROJAN!
Rase
PurityScan/Clickspring adware
rasman
Added by the BCKDR-QGN TROJAN!
RasMan.exe
Added by the FEUTEL-H TROJAN!
rate.exe
Added by the BEAGLE.E WORM and variants!
rate.exe
Unidentified adware
RAV8Tray
RAV anti-virus related
RavAv
Added by the BDOOR-DIJ TROJAN! Note - this file is located in the %WinDir% directory, and must NOT be confused with the legitimate RAV antivirus file of the same name!
RavAv
Added by the RJUMPF-F WORM!
RavAv
Added by the RJUMP.D WORM!
RAVEN_VLZS.EXE
DownloadReceiver parasite - no longer in existence
RavMon
RAV AntiVirus
ravshell
Added by the DLOADER.MAR TROJAN!
Ravshell
Added by the PAKES.HZ TROJAN!
Ravshell
Added by the AGENT.URZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
Ravshell
Added by the AGENT.OKZ TROJAN!
Ravshell
Added by the NSPM.PU TROJAN!
ravshell
Added by the DLOADER.MJF TROJAN!
RavStub
Rising antivirus
ravtask
Added by the DLOADER.IYT TROJAN!
ravtask
Added by the LINEAG-AIN TROJAN!
RavTask
Rising antivirus
RavTime
Added by the WUKILL.A WORM!
RavTimer
RAV AntiVirus
RavTimer
Added by the HOMEY-A TROJAN!
RavTimeXP
Added by the WULLIK.B WORM!
RavTimeXP
Added by the CAGER.A WORM!
RavTimXP
Added by the WULLIK.B WORM!
RavUptets
Added by the QQPASS-AK TROJAN!
RavUptkt
Added by the QQPASS-AJ TROJAN!
RavUptpe
Added by the QQPASS-T TROJAN!
rav_temp.exe
??
rawload
Added by the DARKIRC.QZ TROJAN!
RAX SYSTEM
Added by the MYTOB.KR WORM!
Ray Process Killer
Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL+ALT+DEL instead
Raymond present
Added by the RUBBLE-C WORM!
razer
Razer mouse driver
rb32 lptt01
RapidBlaster variant (in a "RapidBlaster" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
rb32 ml097e
RapidBlaster variant (in a "RapidBlaster" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here
rbenh ml***e
RapidBlaster variant (in a "RBEnhance" folder in Program Files) where *** represents random digits. Recommended you use RapidBlaster Killer to uninstall - see here
RBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Server
Added by the VANEBOT-J WORM!
Rcf Driver
Added by the RANDEX.BLD WORM!
rcimlby.exe
Added by the SDBOT-DHK WORM!
rCron
"Switch" premium rate adult content dialler variant
rCron
"Switch" premium rate adult content dialler variant
RCScheduleCheck
Scheduler for VCOM's Recovery Commander - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"
RCSync
PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware
RCSystem
Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems
RDClient
Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection
RDLL
Added by the SDBOT.F TROJAN!
rdvs
Added by the ULTIMAX WORM!
Reactor3
Added by the BOFRA.A WORM!
Reactor5
Added by the BOFRA.D WORM!
Reactor6
Added by the BOFRA.C WORM!
Reactor7
Added by the BOFRA.B WORM!
Reactor8
Added by the BOFRA.E WORM!
Reactor9
Added by the BOFRA.E WORM!
readdb40
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "readdb40.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
readericon
Tray icon to set various configuration settings for Sunkist (and maybe other) media card readers
REAL
Real Jukebox - MP3 and music files player
Real Internet Player
Added by a variant of the SPYBOT WORM!
Real Media Player
Added by a variant of the RBOT WORM!
Real player updater
Added by the PARLAY TROJAN!
real scheduler.hta
Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player
Real Spy Monitor
Realspy keystroke logger/monitoring program - remove unless you installed it yourself!
Real Statics Agent
Added by a variant of the RBOT WORM!
Real-Tens
DownloadWare adware
RealAudio
Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player
Realaudio Player
Added by the AGOBOT.AFR WORM!
RealDownload
Download manager. Available via Start -> Programs
RealDownload Express
Advertising spyware
Reality Fusion GameCam SE
Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs
RealJukeboxSystray
System Tray icon for RealJukebox
realone_nt2003
Added by the SNONE.A WORM!
RealP1ayer
Added by the RPLAY.A TROJAN! Note that the name has a number "1" in place of the second lower case "L"
realplay
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
realplay lptt01
RapidBlaster variant (in a "RealPlay" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name
realplay ml097e
RapidBlaster variant (in a "RealPlay" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name
RealPlayer
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
RealPlayer Ath Check
Added by the MYTOB.AG WORM!
Realplayer Codec Support
Added by the AGOBOT-AAD WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
Realplayer One
Added by the RBOT-NK WORM!
Realplayer Video
Added by a variant of the RBOT WORM!
Realplayer.exe
Added by the DELF.CNV TROJAN!
RealPlayer2
RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way
RealPlayerUpdater
Added by the LOHAV-T TROJAN!
Realpopup
RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor"
Realsched
Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry
RealSPEED
RealSPEED - tweaking utility to speed-up your internet connection
Realtek Sound Manager
Added by a variant of the IRCBOT BACKDOOR!
Realtime Audio Engine
Associated with ALCATech BPM Studio
Realtime Monitor
Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates
RealTimeUpdate
Product description in properties is "InternetExplorerCommunicationAgent Module" ?
realtpsk
Chinese originated adware - detected by Panda antivirus as NewWeb. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
RealTray
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
RealUpdater
Added by the PARLAY or MITGLIEDER.I TROJANS!
RebateNation0
RebateNation adware
Reboot
MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards
Receiver
Incorporated on multifunction digital copiers (such as the MX-3500NM), Sharp's innovative PC fax driver enables users to send fax documents right from their desktop
Recguard
On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense
Reclip
Reclip Popup Clipboard manager
Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B}
SmartPops search hijacker
Recover
Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete
recover.bmp.exe
Added by the ANAFTP-01 TROJAN! Note - this is NOT the Windows system file of the same name as described here
RecoverFromReboo
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry
RecoverFromReboo
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry
RecoverFromReboot
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry
RecoverFromReboot
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry
Recoveru system
Added by a variant of the LINEAGE-AV TROJAN!
Recoveru systems
Added by a variant of the SDBOT WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! ! This file is located in the "temp" folder
RecShe
Recording scheduler for WatchTV Capture Card (TV Tuner card)
Recycle Bin Handler
Added by the SHUCKBOT-A TROJAN!
Recycle Bin Handler 2005
Added by the HO TROJAN!
Recycler DO NOT MODIFY
Added by the RBOT.DDA WORM!
RecycleSTR
Added by the RBOT-TC WORM!
Red Flag
PMS prediction program with modes for guys and girls - no longer available
Red Swoosh EDN Client
Red_Swoosh distributed networking software - a desktop client that enables users to download and stream files from each other, rather than from webservers
redirect
Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit
Redline Taskbar
Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
REEGRUN
Added by the SECDROP.AI TROJAN
Reek 32 Server
Added by the RANDEX.AL WORM!
Referee
MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run
Reflex Vision
Reflex Vision from Increment Software. "A background application for Windows XP that makes switching windows faster and easier"
Refresh
(Iomega) Refresh - loads the Iomega desktop icons at startup
Reg
Passon homepage hi-jacker
Reg Check
Related to Supanet ISP software - what does it do and is it required?
reg run
Added by the BANCOS-BS TROJAN!
Reg Service
Added by a variant of the SPYBOT WORM!
Reg Service
Added by the AGOBOT-SC WORM!
Reg Service
Added by the AGOBOT-SO WORM!
Reg Service
Added by the RBOT.ZW WORM!
Reg Service
Added by the AGOBOT-PF WORM!
Reg Service
Added by the AGOBOT.G TROJAN!
Reg Services
Added by the RBOT.PB WORM!
reg1.reg
Added by a variant of the IRCBOT TROJAN!
reg2.0
eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase "o"
Reg32
Hijacker - redirecting to only-virgins.com
reg32
Added by the NOUPDATE.B TROJAN!
Reg32
CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN!
Regcheck
Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!
regcheck
Added by the SERVPAM TROJAN!
RegClean Expert Scheduler
"Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free"
RegClean Expert Scheduler
"Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free"
RegCleaner
Added by an unidentified VIRUS, WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware
RegCompres
Added by the POLDO.B TROJAN!
RegCompres
Added by the DASMIN-E TROJAN!
Regcxdinaf
Added by the BANCOS-BW TROJAN!
Regcxmarq
Added by the BANCOS.DK TROJAN! Note that the filename has a leading space, ie, " REGCXMARQ.EXE"
Regcxn
Added by the COIBOA-D TROJAN!
regdefend
"RegDefend is a configurable, kernel based registry protection system, designed to intercept selected changes before they occur, thus also preventing malicious software like viruses, trojans and worms from using the registry to their advantage"
RegDone
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!
RegDone
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
RegDone Ex
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!
RegDoneEx
Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder
regedit
Added by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in the System (9x/Me) or System32 (NT/2K/XP) folder
REGEDIT
Added by the SOUTHGHOST WORM!
regedit
Added by a variant of the RBOT WORM!
regedit
Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!
regedit
Added by the GANBATE.A WORM! Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in a "securityDatabase" subfolder
RegEdit32
Added by the VOUMIT-A WORM! Note - this is not the legitimate regedit32.exe application which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "mirc32" folder
Regexit
Added by the QQPASS-U TROJAN!
Regexit
Added by the QQPASS-N TROJAN!
RegFreeze
RegFreeze anti-spyware software
reggsdg
Added by the SDBOT-MS WORM!
RegHelp
SpyGraphica spy software - "Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."
reginfo32
??
Register Manager
Added by the SDBOT.AYH WORM!
Register MediaRing Talk
If you don't want to register MediaRing and be reminded about it every bootup disable it
Register SeqChk
??
RegisterDropHandler
Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation
Registration Service
Added by the SDBOT-BB WORM!
Registration Service
Added by the SDBOT-HE TROJAN!
Registration-Studio 8
Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems
Registry
Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ShakiraPics.jpg.vbs" file is located in the Winnt or Windows folder
Registry
Blackbox captures emails and chat logs, and monitors Internet activity - remove if you didn't intentionally install it
Registry Checker
Added by the SDBOT TROJAN!
Registry Checkup
Added by an unidentified WORM or TROJAN!
Registry Checkup System326a Monitor
Added by a variant of the SDBOT WORM!
Registry Cleaner
Registry Cleaner misleading security software - not recommended, see here
Registry Integrity Checker
Added by a variant of the AGOBOT/GAOBOT WORM!
Registry Integritycheck
Added by the AGOBOT-RF WORM!
Registry Loader
Added by the GAOBOT.AO WORM!
Registry Loader
Added by the GAOBOT.AO WORM!
Registry Monitor
Added by the QKH TROJAN!
Registry oidet
Added by the RBOT.BMT WORM!
Registry Protector
Added by the ARIVER.A WORM!
Registry Scanner
Added by a variant of the OPTIX TROJAN!
Registry Serv
Added by the WEBMONEY-G TROJAN!
Registry Server
Added by the RBOT-GM WORM!
Registry Server
Added by a variant of the IRCBOT TROJAN! See here
Registry Service
Added by a variant of the RBOT WORM!
Registry Service
Added by the DELBOT-I WORM!
Registry Services
Added by the CILE TROJAN!
Registry Startup Check
Added by the REMLOAD-A or DANMEC-B TROJANS!
Registry System
Added by a variant of the IRCBOT BACKDOOR! See here
Registry System16 Checkup Monitor
Added by a variant of the RBOT WORM!
Registry System166 Checkup Monitor
Added by a variant of the RBOT WORM!
Registry Value Name
Added by the RBOT-AFT WORM!
Registry Value Name
Added by the RBOT-AHT WORM!
Registry Value Name
Added by a variant of the RBOT WORM!
Registry Value Name
Added by the RBOT.BTZWORM!
Registry Value Name Start
Added by a variant of the SDBOT WORM!
RegistryCheck
Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
RegistryChk
Added by the MERTIAN WORM!
RegistryCleanFixMFC
RegistryCleanFix misleading security program - not recommended, see here
RegistryMechanic
Registry Mechanic - "you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages"
RegistryMonitor
Affilred adware
RegistryMonitor
Added by the SYSFADE TROJAN!
RegistryMonitor1
Added by the SPAMBOT TROJAN!
REGIST~1
Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation
Regkey for autostart
Added by the RBOT-NU WORM!
RegKillTray
DVD region killer part of CloneDVD from Elaborate Bytes AG. Copies the main movie, Special Features and/or the original menu onto a DVD Recordable or onto your harddisk
Regmonitor
Added by the BEAGLE.DO WORM!
REGMSYS
Added by the LOWZONE-AX TROJAN!
RegMutex
Added by the MSNOPT-A TROJAN!
RegPowerClean
RegistryPowerCleaner misleading secuirty software - not recommended, see here
RegProt
RegistryProt from Diamond Computer Systems - protects the system registry against changes
Regptmens
Added by the BANCOS-ED TROJAN!
Regro
Added by the OKARAG TROJAN!
RegRun
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!
REGRUN
Added by the LOWZONE-AH TROJAN!
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!
RegRun WinBait
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different..
Regrun2
Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc
REGRUNM
Added by an unidentified WORM or TROJAN!
Regrx
Added by the WAYIC-A TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). The file is located in C:Windows
Regscan
Added by the OPTIX-SE TROJAN!
RegScan
Added by the AGOBOT.AEW WORM!
RegScan
Added by the TALEX TROJAN!
RegServer
Related to XGI Technology's Volari graphics cards - what does it do and is it required?
regservices.exe
Added by an unidentified VIRUS, WORM or TROJAN!
RegShave
Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly
regsrv
Added by the OPTIXPRO.11 TROJAN!
regsrv
Added by the AGOBOT.E WORM!
RegSrv64D
Added by the WINKO.AO WORM!
regsrvc
Added by the STOPED-A TROJAN!
Regsv
Search hijacker - redirecting to scheo.com
Regsvc
Added by an unidentified TROJAN!
regsvc32
Homepage hijacker that changes your homepage to an adult content site
regsvr
Added by the WEBMONEY-G TROJAN!
REGSVR32
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
RegSvr32
Added by the ZLOB.B TROJAN!
regsync
SafeSurfing adware
regtmlp
??
RegTweak
Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface
RegVer
Added by the LATINUS.16 TROJAN!
RegVfy32
Added by the SYGYP.A WORM!
RegWrite
Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%Media
Regx10EXE
ATI Remote Wonder? - PC wireless remote control driver. Required if you use it
reg_key
Added by the BEAGLE.AH WORM!
reg_key
Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!
Reg_WFT
Added by the WILSEF VIRUS!
Reg_WFT
Added by the SENNASPY-F TROJAN!
ReleaseRAM
"Release RAM allows your computer to run faster and uses your computer's RAM more efficiently". MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
relinson
Added by the DROPPER-PS TROJAN!
reload
Added by the LOVELETTER.AS VIRUS!
Reload
Added by the LAZAR TROJAN!
RemHelp
BT Voyager ADSL Modem Help related
Reminder
From MS Money. Reminds you of your bills
Reminder
HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
Reminder
Registration reminder for the PC Pitstop Optimize 2.0 system optimizatoon utility by CA. Located in %ProgramFiles%\PCPitstop\Optimize2
Reminder-cpqXXXXX
Compaq printer Registration
Reminder-hpcXXXXX
HP CD-Writer Registration
Reminder-ranXXXXX
Registration reminder widget for Rand Mcnally maps
reminder-ScanSoft Product Registration
Registration reminder for ScanSoft products such as PaperPort
RemindMe
Remind-Me - calendar software
Remind_XP
HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list
Remndr
CasinoOnline foistware
Remote
Remote Control driver for LifeView internal and external TV products
Remote Access
Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed
Remote Access Adapter
Detected by PCTools as the IRCBOT.BIF TROJAN! See here
Remote Access Domain
Added by the IRCBOT.BFA TROJAN!
Remote Access Monitor
Added by a variant of the IRCBOT TROJAN! See here
Remote Access Service Manager
Added by the AGOBOT.KU WORM!
Remote Access Slave
Added by the RIPJAC TROJAN!
Remote Access Tool
Added by a variant of the IRCBOT TROJAN! See here
Remote Control
Hinet Hi-Five ISP software
Remote Controller
ProLink PlayTVpro TV tuner software
Remote Data Backups
System Tray access to Remote Data Backups online system/data backup utility
Remote Data Backups
Remote Data Backups online system/data backup utility
Remote Data Backups TaskBar Icon
System Tray access to Remote Data Backups online system/data backup utility
Remote Desktop Computing
Marspc Remote Desktop Computing
Remote Desktop Help Session Manager
Added by a variant of the SDBOT WORM!
Remote Event System
Detected by Trend Micro as the IRCBOT.YF TROJAN! See here
Remote Management Agent
Part of Novell's ZENworks - "Complete End-to-End Directory-enabled Network Management". Installed on a managed workstation fo an administrator to remotely manage the workstation. Required if the PC is a managed workstation
remote master
Required if you want your ASUS Remote control to work at all. Available via Start -> Programs
Remote Procedure Call
Added by the RBOT-KM WORM!
Remote Procedure Call
Added by the SDBOT-PS WORM!
Remote Procedure Call For Windows 32bit
Added by the RBOT-MD WORM!
Remote Procedure Call Locator
Added by the LOVGATE.F WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Remote Procedure Calls
Added by the RBOT.KJ WORM!
Remote Procedure Calls
Added by the RBOT-IT WORM!
Remote Procedure Calls
Added by the SDBOT-QI WORM!
Remote Services Manager
Added by a variant of the IRCBOT TROJAN! See here
Remote Storage Access
Added by a variant of the IRCBOT TROJAN! See here
Remote Terminal Task
Detected by Trend Micro as the IRCBOT.AUZ TROJAN! See here
Remote Update Monitor
Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer
RemoteAgent
Trend Micro's Office Scan Client, see here - "Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates"
RemoteCenter
Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats
RemoteControl
Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
RemoteControl
Remote Control background application for Cyberlink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
RemoteControl8
Remote Control background application for Cyberlink's PowerDVD version 8. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
Remote_Agent
Cyberlink's Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs
REMOVE ME
Added by the SDBOT.EE WORM!
Removecpl
Related to a Belkin 54Mbps Wireless Utility Control Panel applet
Removed.exe
GatorCheat - adware downloader
RemoveIT Pro XT
RemoveIT Pro from InCode Solutions - spyware, virus and malware removal tool
RemStart
Part of McAfee's Remote Desktop 32 Agent application. What does it do and is it required?
renascimento
Detected by Kaspersky as the BANKER.GAX TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "Help" sub-folder of the Winnt or Windows folder
RenolB
??
repl
Added by the YABE.CD TROJAN!
Replay Center
Replay Radio - "makes it easy to automatically record your favorite radio shows, so you can listen wherever and whenever you like"
Replicator
Replicator from Karen's powertools. "Automatically backup files, directories, even entire drives!"
RepliGo Assistant
Cerience RepliGo software - "any document you have on your PC can be transferred to your mobile device"
ReproPRD
Thrustmaster Corporation Presets application - a game controller driver, presumably necessary for certain functions to work
requester
Added by a variant of the MUQUEST.A trojan - NOTE: the * stands for a digit, examples: requester.5.exe, requester.10.exe
Requester
Added by the MUQUEST TROJAN!
Required Service Drivers
Added by the RBOT-ABD WORM!
resagnt
Adware downloader, identified by Panda antivirus as Trojan.Downloader.ALQ
ResChanger2004
EVGA graphic card utility providing easy access to display settings
reseurce
Added by the LINEAGE-AI TROJAN!
reseurce
Added by the LINEAGE-FV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
Resolution Assistant
Dell Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decide
Resource Meter
Windows Resource Meter. Available via Start -> Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes
Restart Watch
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required?
Restart WSC Setting
WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes
Restart_VS
Could be a left-over from the installation of a Viewsonic flat panel display
Restore Operation
Added by a variant of the RBOT WORM!
RestoreDesktop
Softwarium Restore Desktop "is a Windows Context Menu addition that automatically saves and restores the icons' positions on the Windows desktop after a resolution change"
RestoreIT!
RestoreIT! from FarStone "allows you to recover instantly your files, system configuration, and even your operating system, to any point in time prior to the data loss or system failure"
restory
Added by the RETSAM TROJAN!
Resume Copy
Part of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that function
ResumeFixClocks
Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards
reszrv
Added by a variant of the SDBOT WORM! See here
retime
Added by the GIPMA TROJAN!
RetrieverScheduler
80-20 Retriever from 80-20 - "80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information". Real-time scheduler - shortcut available
RetroExpress
EMC (was Dantz) Retrospect Express - backup software for external hardware storage devices
RevoTaskbarApp
Control Application for M-Audio Revolution 7.1 sound card. The sound card will function without it - but changes to speaker setup and sound modification (Bass/Treble etc) will not be available
RexSyMon
Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC
RF
Added by the LINEAGE-U TROJAN!
rfagent
Registry First Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders
rforce
Added by the DROPPER.KN TROJAN! Note the number "1" in the filename rather than letter "L". It also drops another file named DEVICEMAP.SYS which is the ROOTKIT.O TROJAN!
RFTray
Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs
rfw
RAV AntiVirus
RfwMain
Rising antivirus
rfwydg
??
RFX_auto_upgrade
A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade
Rg2catbd
Added by a variant of the BANLOAD family of TROJANS!
RH
EuroFonts - adds Euro symbols to pre-Euro computers
Rhino
Added by the BOFRA.A WORM!
RhinoBlocker
RhinoBlocker - pop-up stopper
RHPTray
System tray access to Red Hot Pawn - online chess
RHSI SHS
Rogers Hi-Speed Internet software. "Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash"
RichMedia
HenBang adware
RichMedia
Henbang adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
richup
SafeSurfing adware
RightFAX Print-to-Fax Driver
Part of RightFAX from Captaris - "the proven market leader in fax server and document delivery software"
Ring Central Fax
Only needed if you want a PC to answer faxes automatically
rIOphosIs
Added by the RIOSYS MACRO!
Riorad Manager
"Riorad Explorer is hands-down the most advanced Windows software companion for your Rio MP3 player"
RivaTuner
RivaTuner for tweaking nVidia graphics cards. Required if you make any changes
RivaTunerStartupDaemon
RivaTuner for tweaking nVidia graphics cards. Required if you make any changes
RjLyraInstaller
??
RK Launcher
RK Launcher by RaduKing - "is a free application that will allow the user to have a visually pleasing bar at the side of the screen that is used to quickly launch shortcuts"
rmalt
Added by the CLICKER-CS TROJAN! Filenames spotted inlcude Setup.exe, Keygen.exe, Keygen-Serial.exe, Photoshop.CS2.KeyGen.exe and more
rmctrl
Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
rmdrfje.dll
Added by the DLOADR-ANM TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "rmdrfje.dll" file is located in the Winnt or Windows folder
rmmon
Resource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card
rmoc3260.dll OCX
A module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The "rmoc3260.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
RMremote
Remote control driver for REALmagic Xcard. Is it required?
rn4d
Added by the MAROON.A TROJAN!
Rnaomflt
Naomi internet filtering software
RNBc Test
Added by the RBOT-AGR WORM!
RNBc Test
Added by the RBOT-AJF WORM!
RNBOStart
Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools
RNBz Test
Added by the RBOT-AEY WORM!
RNDc Test
Added by a variant of the SDBOT WORM!
rndll2
May be related to the DivX program as a *.dat file in the same directory had "DivXPro505Bundle.exe" mentioned within?
rngmf
Added by the RANKY.C TROJAN!
Rnudll32
Added by the QQPASS-O TROJAN!
rnxqh
??
Roam04
Added by the ROAMER-A TROJAN!
RoboForm
Roboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin
RoboFormWatcher
Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs
Rocket.Time
Rocket.Time - time synchronization software from Rocket Software
RocketDock
"RocketDock is a smoothly animated, alpha blended application launcher. It provides a nice clean interface to drop shortcuts on for easy access and organization"
Roflcopteur
Added by an unidentified WORM or TROJAN!
RogueMonitor
Rogue Remover PRO - utility to detect and remove misleading security programs masqerading as virus scanners, spyware removers, etc that lure people into buying them with false positives
roketpipe
??
Rollback
Added by the RollBack Rx system restore program
rollbk
Added by the SERFLOG.B WORM!
rollbk
Added by the SERFLOG.B WORM!
rollbk
Added by the SERFLOG.B WORM!
rollbk
Added by the SERFLOG.B WORM!
romahere
SuperSpider hijacker - a CoolWebSearch parasite variant
romahere2
SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!
romahere3
SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN!
Root_Machine
Added by the BANCBAN-DI TROJAN!
ROOT_Machine
Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Windowsinf or Winntinf folder
ROUTD
??
Router
Detected by Kaspersky as the AGENT.FJN TROJAN! See here
RoxAssist
Roxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use "Add Remove Programs" in "Control Panel"). Can be run manually
Roxio Engine
Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN!
RoxioAudioCentral
Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. "Includes a player, media manager, ripper, tag and sound editor - integrated in a single application". Not required for Roxio to work properly.
RoxioDragToDisc
Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
RoxioEngineUtility
Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking
RoxWatchTray
System Tray icon installed by Roxio Easy Media Creator 8 and which allows you to configure your watched folders or to turn the ?Watched Folders? feature of Roxio ON or OFF
RP32
Unicenter Remote Control (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems
RPC
Added by a variant of the GAOBOT/AGOBOT WORM!
RPC Drivers
Detected by Trend Micro as the SDBOT.FLY WORM! See here
RPC Patcher
Added by the BOLGI WORM!
RPC Service
Added by the AAD TROJAN!
rpc Win32
Added by the RBOT-ABL WORM!
rpc Win32
Added by a variant of the RBOT WORM!
RPCall_WIN2K
Added by the BHARAT.A WORM!
RPCall_[ComputerName]
Added by the REDPLUT-B TROJAN!
rpcc
Added by the SPAMMIT-E TROJAN!
rpcda Win32
Added by the RBOT-AE WORM!
RPCser32g
Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
RPCser32g1
Added by the PREXOT.D TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
RPCser32g3
Added by the PREXOT.D TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
RPCser32g4
Added by the PREXOT.E TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
RPCserr32g
Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
RPCserv32
Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
RPCserv32g
Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder
RPCserv32g
Added by the BOBAX.AD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
RPCserv32g
Added by the BOBAX.AD WORM!
RPCserv32g
Added by the BOBAX.AD WORM!
RPCserv32g
Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder
RPCSS.exe
Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here
RpcxWindows Extensions
Added by the RBOT.ACP WORM!
Rr2
Added by the LINEAG-ADI TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in an "addins" sub-folder
RRMedic
Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection
rscmpt
Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status
rsmb
Added by the WAREZOV.C WORM!
rsMenu
Synchronizes a Casio PDA with MS Outlook
RSPC Driver
Added by the RBOT-SN WORM!
RSPC Driver D
Added by a variant of the RBOT WORM!
RSRCMTZ
??
rsrvmon.exe
Detected by Kaspersky as the AGENT.NY TROJAN! See here
RSS
"Related Sites" toolbar - SearchAndClick hijacker variant
RssReader
RssReader - a free RSS reader able to display any RSS and Atom news feed (XML)
RsWin
Added by the SILLY.BR WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "4350" sub-folder
RSync
SafeSurfing adware
rtasks
Misleading security software such as AntiSpywareSuite, AntivirusPCSuite, SpyGuardPro, WinAntiVirus Pro 2006 - not recommended, see here
rtcdll
RTCDLL is "Real Time Communication" and is associated with Windows Messenger (the IM application, not messenger service). It is only necessary if you use Windows Messenger. Most people use MSN Messenger instead, so it is not required in those cases
RTHDCPL
Realtek HD Audio Sound Effect Manager
RtHDVCpl
High definition audio codec driver from Realtek Semiconductor
rtkernsw
Added by a variant of the SLAPER TROJAN!
rtl.exe
Added by the TIOTUA-J TROJAN!
RtlMon.exe
Monitor for RealTek network card
RTMonitor
Cheyenne (now eTrust) antivirus
rtos
IRC trojan
RTStartMute
??
rtvscn95
Real-time virus scanner component of Norton Anti-Virus Corporate Edition
RtWLan
Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port"
RubeL
Added by the RUBY-B TROJAN!
Ruby13
Added by the MEXER.E WORM!
Ruby14
Added by the FIGHTRUB-A WORM!
ruin
Added by the DELF-JM TROJAN!
RuLaunch
Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis
Run
Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
run
Added by the HOLCAS.A WORM!
run
Added by the BINGHE TROJAN!
Run
Identified as the DELF.LF by Ewido Security Suite
run
Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
run
Added by the SQUATBOT-C TROJAN!
run
Added by the IMONI-E TROJAN!
run
Added by the BCKDR-QHR TROJAN!
Run Google Web Accelerator
Google Web Accelerator
Run Msn Messenger
Added by the AGOBOT.HA WORM!
Run MSupdt32
Added by the CASER WORM!
Run Nintendo Wi-Fi USB Connector Registration Tool
Related to Wi-Fi USB Connector from Nintendo
Run POPFile in background
POPFile - E-mail spam blocker
Run POPFile in background
POPFile - E-mail spam blocker
Run Services as Application
Added by the DLOADER-NY TROJAN!
Run Services as Application
Added by the DLOADER-NY TROJAN!
Run Services as Application
Added by the DLOADER-NY TROJAN!
Run Services as Application
Added by the DLOADER-NY TROJAN!
Run Services as Application
Added by the DLOADER-NY TROJAN!
Run Services as Application
Added by the DLOADER-NY TROJAN!
Run Services as Application
Added by the DLOADER-NY TROJAN!
Run Services as Application
Added by the DLOADER-NY TROJAN!
Run StartupMonitor
Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu
run windows
Added by the REBOOT-AP TROJAN!
Run XP Service Pack
Added by the SDBOT.AQA WORM!
Run05
Added by the BANCOS-DT TROJAN!
run32
Added by the SDBOT-CWB WORM!
run32dll
Added by an unidentified VIRUS, WORM or TROJAN!
run32dll
Added by an unidentified VIRUS, WORM or TROJAN!
Run32dll
Added by an unidentified VIRUS, WORM or TROJAN!
run=
MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI)
run=
HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
run=
Lexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS
run=
pcfix2k splash screen
run=
PhoenixNet BIOS adware. See here
run=
Advanced Startup Manager from Rays Lab
run=
Desktop wallpaper changer?
run=
CoolWebSearch parasite variant
run=
CoolWebSearch Tapicfg parasite variant
run=
Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs
run=
??
run=
Added by the LOVGATE-F WORM!
run=
Added by the ATAK.F WORM!
run=
Reportedly part of Lexmark printer software - what does it do and is it required?
run=
FMedia FaxWorks related - can be run manually
run=
Used with some models of Panasonic, Epson and NEC printers - required for printer to work
run=
Unidentified malware
run=
CoolWebSearch Tapicfg parasite variant
run=
Added by the GAGGLE.E WORM!
run=
Added by the APSTROJAN.OB TROJAN!
run=
Added by the ATAK.G WORM!
run=
CoolWebSearch Smartsearch parasite variant
run=
Added by the HOLCAS.A WORM!
run=
Searchforfree.info browser hijacker
run=
Added by the ADWARELOADER TROJAN! Note - do not confuse with the legitimate Microsoft Office file, which would typically be located in the Program FilesMicrosoft OfficeOffice folder!
run=
Added by the SEMAPI-A WORM!
run=
Added by the ADMINCASH.B TROJAN!
run=
Added by the DUMARU-L TROJAN!
run=
Added by the PROXY-GG TROJAN!
run=
Added by the CELINE-A TROJAN!
run=
Added by the KREPPER-N TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "inet10066" subfolder of the Windows or Winnt folder
RunAlert
MSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you "overclock" your system
runAP
Not required but what is it?
runapp
Added by the BOMKA TROJAN!
Runapp32
Added by the NEODURK TROJAN!
RunCA
Wireless-G USB Wireless Network Adapter related - would appear to be required
Rund11
Added by the MARIO-C WORM!
rund1132
Added by the DOPBOT-A WORM!
Rund1132.exe
Added by the STARTPA-HS TROJAN!
Rund1l32
Added by the MERTIAN WORM!
runddlfile
Added by the DELF.D TROJAN!
Rundil32
Added by the QQPASS-U TROJAN!
Rundil32
Added by the QQPASS-N TROJAN!
rundl332
Added by the DOOMJUICE WORM!
rundli32
Added by the LADE WORM!
RunDLL
Flingstone.com browser hijacker. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "qkoszvd.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
Rundll
Added by the DELF-KT TROJAN!
Rundll
Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder
RunDll
Added by the QQPASS-AH TROJAN! Note - this is NOT the Windows system file of the same name as described here
RunDLL Kernel File Core
Added by a variant of the SLAPER TROJAN!
rundll***
Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
rundll***
Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
rundll***
Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
rundll***
Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
Rundll16
Added by a number of VIRUSES, WORMS and TROJANS!
Rundll32
Added by the DVLDR TROJAN! Note - this is not the valid "Rundll32.exe" as it's in the WindowsFonts directory
RUNDLL32
System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)
RunDLL32
System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
rundll32
Loads default settings for Leadtek Winfast graphics cards
RunDLL32
Added by an unidentified TROJAN! - possibly a BMBOT variant
Rundll32
Added by the QQPASS.E TROJAN!
Rundll32
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. Tells the drivers that the connected Drives should use the "Write Back" Caching. You can disable this if you don't want to use "Write Back" Caching or if you have not connected any driver to your Promise Controller
rundll32
Added by the AUTEX WORM!
rundll32
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller
rundll32
Added by the SANKER WORM! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This one is is located in the Winnt or Windows folder
rundll32
Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
rundll32
Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup
RUNDLL32
Added by the DEMOTRY-A WORM!
rundll32
Added by the AGENT-EZ TROJAN! Note - the real rundll32.exe resides in the System (9x/Me) or System32 (NT/2K/XP) folder whereas this file is found in a "SHELLEXT" subfolder
Rundll32
Added by the STARTPAGE.AXH TROJAN!
rundll32
Added by the STAP-C WORM!
rundll32
Added by the STAP-D WORM!
rundll32
Added by the STAP-E WORM!
rundll32
Added by the ROOKIE-A TROJAN!
rundll32
Added by the DELF.BKC TROJAN!
Rundll32 cmicnfg
System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel
RunDll32 essprops
Associated with a Logitech mouse - required for proper operation
Rundll32 P17
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
Rundll32.exe
Added by the GRUEL WORM!
Rundll32.exe
Added by the GRUEL WORM!
Rundll32_7
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Rundll32_8
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
Rundll32_8
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted
rundll64
Added by the AUTEX WORM!
RundllSvr
Added by the HUAYU WORM! Note - this is NOT the Windows system file of the same name as described here
Rundllsystem32
Added by the NETDEVIL.B TROJAN!
Rundnm
Added by the DELF-HA TROJAN!
RUNGogoTools
GoGoTools adware
RUNGogoTools
GoGoTools adware
RUNHYPER
PurityScan/Clickspring adware
runing
Added by the DELF-LC TROJAN!
RUNLOAD
PurityScan/Clickspring adware
RUNLOUD
PurityScan/Clickspring adware
Runmarc8mManager
MARC Sound System Manager for the Marc 8 MIDI sound card - allows for easy adjustment of the settings
RunNarrator
Associated with the Narrator accessibility feature on Windows XP. It is used to convert text to speech
Runner
Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located the Winnt or Windows folder
Runner
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
Runner
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
Runner
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder
runner1
Added by the CRYPT.ULPM.GEN TROJAN!
runner1
Added by the AGENT.SLZ TROJAN!
runner1
Added by the AGENT.CZC TROJAN!
runner1
Added by the SMALL.CTV TROJAN!
runner1
Added by the AGENT.ABFQ TROJAN!
RunOnce
Part of MS Data Access Components - only required if you use these
Runonce
Added by the CHIR-B WORM!
RunOnceEx
Identified as the DELF.LF by Ewido Security Suite
RunProg
Added by the OPTIX.04.A TROJAN!
RunProg
Added by the OPTIX.04.D TROJAN!
runreper
Added by the REPER.A VIRUS!
runs
Added by the RBOT-BWF WORM!
RunSearvices
Identified as the DELF.LF by Ewido Security Suite
RunServices
Added by the AGOBOT.QJ WORM!
runservices
Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
runsql
Detected by PCTools as the DELF.ZWK TROJAN! See here
runSubvalues
Added by the DLOADER-QY TROJAN!
runsvc
Added by the SMALL-CF TROJAN!
RunSysd32
DesktopShield2000 by St?phane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within
Runtime Process
Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%
runtime.exe
Added by a variant of the Tibs malware
Runtt1
Added by the LINEAGE-R TROJAN!
Runtt1
Added by the LINEAGE-Q TROJAN!
RunWin
Added by the BANKER-ES TROJAN!
runwin32
Added by the ESEARCH-A TROJAN!
RUNWIN32
Added by the VB-AET TROJAN!
RunWindowsUpdate
BrowserAid/BrowserPal foistware
runwinlogon
Detected by Trend Micro as the AGENT.TQY TROJAN! See here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
Run[0]
Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside
Run_cd
Added by the GHOST.23 TROJAN!
run_pbnext
PBNext is virtual phone system which offers the same functionality as expensive PBX hardware
Rupsw32
MegaTec Rups, UPS monitoring software - monitor and control DB9 UPS running on either Windows & Novell NetWare (with RUPS 2000) or Unix (with RUPS for Unix / Plus) operating systems
RUSBHOLoader
??
RVC6Player
Added by the ZAPCHAS-M TROJAN!
rvde
Related to li-speed****
RVP
Spyware included with the latest version of Grokster
rw service
Added by the LOOPAD.A TROJAN!
rx
Added by the LINEAGE-BP TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is found in the Windows or Winnt folder
rx
Added by the ZHENGTU-A TROJAN!
RxMon
Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail"
RxUser
Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail"
ryan1918
Added by the RBOT-GVR WORM!
rydanmxe.exe
Added by the DLOADR-AZZ TROJAN!
ryy
Added by the PWS-ANA TROJAN!
rzt
Added by the LINEAGE.BDP TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is found in an "Intel" sub-folder of the Windows or Winnt folder
r_server
Radmin - remote admistrator server
r_server
Added by the MULTIDR-CP TROJAN!
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59