 |
R
Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
RA Server
Added by the RA TROJAN! |
 |
RabbitWannaHome
Added by the MIMAIL.S WORM! |
 |
Rabo Session Monitor
Related to RaboBank electronic banking software |
 |
RaConfig2500
RaLink wireless LAN configuration utility |
 |
RadarSync
Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically |
 |
RadBoot
RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings |
 |
Radio365Agent
Radio365 - create playlists and broadcast live straight from your PC! |
 |
RadioSvr
Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network |
 |
RAID Event Monitor
IAA Event Monitor User Notification Tool - part of Intel? Application Accelerator - "a performance software package for desktop PCs using select Intel? chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed |
 |
RaidTool
VIA V-RAID Tool - hard disk striping/mirroring utility for increased performance and reliability |
 |
Rainlendar
Rainlendar is a customizable calendar that displays the current month |
 |
Rainlendar2
Rainlendar is a customizable calendar that displays the current month |
 |
Rainmeter
Rainmeter is a customizable performance meter, which can display the CPU load, memory utilization, etc |
 |
RAM Idle Professional
RAM Idle LE - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
RAMASST
Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs |
 |
RamBooster2
Added by the AKAK TROJAN! |
 |
RAMDef
Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
RAMDrive
Virtual Hard Drive (Ram Drive) from Farstone - takes a portion of your system memory (RAM) and uses it to simulate a hard disk drive |
 |
RamIdle
RAM Idle LE - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
RAMpage
Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source |
 |
Randex virus built for IRBMe
Added by the RANDEX.RH WORM! |
 |
random
Added by the DLOADER-KM TROJAN! |
 |
Random Interface Network
Added by the DELBOT-P WORM! |
 |
Random Interface Network Manager
Added by the DELBOT-L WORM! |
 |
Random Unique ID
Added by the XROVE-A WORM! |
 |
RandomWin32
Added by the SDBOT-DV WORM! |
 |
rant
Added by the RBOT-ZB WORM! |
 |
RapApp
Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch |
 |
Rapdata
Added by the QQPASS-V TROJAN! |
 |
Rapdatae
Added by the QQPASS-S TROJAN! |
 |
Rapdatybs
Added by the PWS-ACP TROJAN! |
 |
Rapid Restore
XPoint "Rapid Restore PC" - a "Managed Recovery? solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user" |
 |
RapidBlaster
RapidBlaster parasite. Recommended you use RapidBlaster Killer to uninstall - see here |
 |
Raptelnet
Added by the QQPASS-AA TROJAN! |
 |
Raptelt
Added by the QQPASS-AB TROJAN! |
 |
Raptor Mobile
Symantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking |
 |
RasCon Remote Access Service Manager
Added by the SPYBOT.EM WORM! |
 |
rasctrs
Hijacker, also detected as the ADWAHECK TROJAN! |
 |
Rase
PurityScan/Clickspring adware |
 |
rasman
Added by the BCKDR-QGN TROJAN! |
 |
RasMan.exe
Added by the FEUTEL-H TROJAN! |
 |
rate.exe
Added by the BEAGLE.E WORM and variants! |
 |
rate.exe
Unidentified adware |
 |
RAV8Tray
RAV anti-virus related |
 |
RavAv
Added by the BDOOR-DIJ TROJAN! Note - this file is located in the %WinDir% directory, and must NOT be confused with the legitimate RAV antivirus file of the same name! |
 |
RavAv
Added by the RJUMPF-F WORM! |
 |
RavAv
Added by the RJUMP.D WORM! |
 |
RAVEN_VLZS.EXE
DownloadReceiver parasite - no longer in existence |
 |
RavMon
RAV AntiVirus |
 |
ravshell
Added by the DLOADER.MAR TROJAN! |
 |
Ravshell
Added by the PAKES.HZ TROJAN! |
 |
Ravshell
Added by the AGENT.URZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
Ravshell
Added by the AGENT.OKZ TROJAN! |
 |
Ravshell
Added by the NSPM.PU TROJAN! |
 |
ravshell
Added by the DLOADER.MJF TROJAN! |
 |
RavStub
Rising antivirus |
 |
ravtask
Added by the DLOADER.IYT TROJAN! |
 |
ravtask
Added by the LINEAG-AIN TROJAN! |
 |
RavTask
Rising antivirus |
 |
RavTime
Added by the WUKILL.A WORM! |
 |
RavTimer
RAV AntiVirus |
 |
RavTimer
Added by the HOMEY-A TROJAN! |
 |
RavTimeXP
Added by the WULLIK.B WORM! |
 |
RavTimeXP
Added by the CAGER.A WORM! |
 |
RavTimXP
Added by the WULLIK.B WORM! |
 |
RavUptets
Added by the QQPASS-AK TROJAN! |
 |
RavUptkt
Added by the QQPASS-AJ TROJAN! |
 |
RavUptpe
Added by the QQPASS-T TROJAN! |
 |
rav_temp.exe
?? |
 |
rawload
Added by the DARKIRC.QZ TROJAN! |
 |
RAX SYSTEM
Added by the MYTOB.KR WORM! |
 |
Ray Process Killer
Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL+ALT+DEL instead |
 |
Raymond present
Added by the RUBBLE-C WORM! |
 |
razer
Razer mouse driver |
 |
rb32 lptt01
RapidBlaster variant (in a "RapidBlaster" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
rb32 ml097e
RapidBlaster variant (in a "RapidBlaster" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
rbenh ml***e
RapidBlaster variant (in a "RBEnhance" folder in Program Files) where *** represents random digits. Recommended you use RapidBlaster Killer to uninstall - see here |
 |
RBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Server
Added by the VANEBOT-J WORM! |
 |
Rcf Driver
Added by the RANDEX.BLD WORM! |
 |
rcimlby.exe
Added by the SDBOT-DHK WORM! |
 |
rCron
"Switch" premium rate adult content dialler variant |
 |
rCron
"Switch" premium rate adult content dialler variant |
 |
RCScheduleCheck
Scheduler for VCOM's Recovery Commander - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running" |
 |
RCSync
PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware |
 |
RCSystem
Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems |
 |
RDClient
Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection |
 |
RDLL
Added by the SDBOT.F TROJAN! |
 |
rdvs
Added by the ULTIMAX WORM! |
 |
Reactor3
Added by the BOFRA.A WORM! |
 |
Reactor5
Added by the BOFRA.D WORM! |
 |
Reactor6
Added by the BOFRA.C WORM! |
 |
Reactor7
Added by the BOFRA.B WORM! |
 |
Reactor8
Added by the BOFRA.E WORM! |
 |
Reactor9
Added by the BOFRA.E WORM! |
 |
readdb40
LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "readdb40.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
readericon
Tray icon to set various configuration settings for Sunkist (and maybe other) media card readers |
 |
REAL
Real Jukebox - MP3 and music files player |
 |
Real Internet Player
Added by a variant of the SPYBOT WORM! |
 |
Real Media Player
Added by a variant of the RBOT WORM! |
 |
Real player updater
Added by the PARLAY TROJAN! |
 |
real scheduler.hta
Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player |
 |
Real Spy Monitor
Realspy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
Real Statics Agent
Added by a variant of the RBOT WORM! |
 |
Real-Tens
DownloadWare adware |
 |
RealAudio
Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player |
 |
Realaudio Player
Added by the AGOBOT.AFR WORM! |
 |
RealDownload
Download manager. Available via Start -> Programs |
 |
RealDownload Express
Advertising spyware |
 |
Reality Fusion GameCam SE
Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs |
 |
RealJukeboxSystray
System Tray icon for RealJukebox |
 |
realone_nt2003
Added by the SNONE.A WORM! |
 |
RealP1ayer
Added by the RPLAY.A TROJAN! Note that the name has a number "1" in place of the second lower case "L" |
 |
realplay
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
 |
realplay lptt01
RapidBlaster variant (in a "RealPlay" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name |
 |
realplay ml097e
RapidBlaster variant (in a "RealPlay" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name |
 |
RealPlayer
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
 |
RealPlayer Ath Check
Added by the MYTOB.AG WORM! |
 |
Realplayer Codec Support
Added by the AGOBOT-AAD WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
 |
Realplayer One
Added by the RBOT-NK WORM! |
 |
Realplayer Video
Added by a variant of the RBOT WORM! |
 |
Realplayer.exe
Added by the DELF.CNV TROJAN! |
 |
RealPlayer2
RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way |
 |
RealPlayerUpdater
Added by the LOHAV-T TROJAN! |
 |
Realpopup
RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor" |
 |
Realsched
Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry |
 |
RealSPEED
RealSPEED - tweaking utility to speed-up your internet connection |
 |
Realtek Sound Manager
Added by a variant of the IRCBOT BACKDOOR! |
 |
Realtime Audio Engine
Associated with ALCATech BPM Studio |
 |
Realtime Monitor
Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates |
 |
RealTimeUpdate
Product description in properties is "InternetExplorerCommunicationAgent Module" ? |
 |
realtpsk
Chinese originated adware - detected by Panda antivirus as NewWeb. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
 |
RealTray
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
 |
RealUpdater
Added by the PARLAY or MITGLIEDER.I TROJANS! |
 |
RebateNation0
RebateNation adware |
 |
Reboot
MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards |
 |
Receiver
Incorporated on multifunction digital copiers (such as the MX-3500NM), Sharp's innovative PC fax driver enables users to send fax documents right from their desktop |
 |
Recguard
On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense |
 |
Reclip
Reclip Popup Clipboard manager |
 |
Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B}
SmartPops search hijacker |
 |
Recover
Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete |
 |
recover.bmp.exe
Added by the ANAFTP-01 TROJAN! Note - this is NOT the Windows system file of the same name as described here |
 |
RecoverFromReboo
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
 |
RecoverFromReboo
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
 |
RecoverFromReboot
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
 |
RecoverFromReboot
Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
 |
Recoveru system
Added by a variant of the LINEAGE-AV TROJAN! |
 |
Recoveru systems
Added by a variant of the SDBOT WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! ! This file is located in the "temp" folder |
 |
RecShe
Recording scheduler for WatchTV Capture Card (TV Tuner card) |
 |
Recycle Bin Handler
Added by the SHUCKBOT-A TROJAN! |
 |
Recycle Bin Handler 2005
Added by the HO TROJAN! |
 |
Recycler DO NOT MODIFY
Added by the RBOT.DDA WORM! |
 |
RecycleSTR
Added by the RBOT-TC WORM! |
 |
Red Flag
PMS prediction program with modes for guys and girls - no longer available |
 |
Red Swoosh EDN Client
Red_Swoosh distributed networking software - a desktop client that enables users to download and stream files from each other, rather than from webservers |
 |
redirect
Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit |
 |
Redline Taskbar
Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards |
 |
REEGRUN
Added by the SECDROP.AI TROJAN |
 |
Reek 32 Server
Added by the RANDEX.AL WORM! |
 |
Referee
MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run |
 |
Reflex Vision
Reflex Vision from Increment Software. "A background application for Windows XP that makes switching windows faster and easier" |
 |
Refresh
(Iomega) Refresh - loads the Iomega desktop icons at startup |
 |
Reg
Passon homepage hi-jacker |
 |
Reg Check
Related to Supanet ISP software - what does it do and is it required? |
 |
reg run
Added by the BANCOS-BS TROJAN! |
 |
Reg Service
Added by a variant of the SPYBOT WORM! |
 |
Reg Service
Added by the AGOBOT-SC WORM! |
 |
Reg Service
Added by the AGOBOT-SO WORM! |
 |
Reg Service
Added by the RBOT.ZW WORM! |
 |
Reg Service
Added by the AGOBOT-PF WORM! |
 |
Reg Service
Added by the AGOBOT.G TROJAN! |
 |
Reg Services
Added by the RBOT.PB WORM! |
 |
reg1.reg
Added by a variant of the IRCBOT TROJAN! |
 |
reg2.0
eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase "o" |
 |
Reg32
Hijacker - redirecting to only-virgins.com |
 |
reg32
Added by the NOUPDATE.B TROJAN! |
 |
Reg32
CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN! |
 |
Regcheck
Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS! |
 |
regcheck
Added by the SERVPAM TROJAN! |
 |
RegClean Expert Scheduler
"Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free" |
 |
RegClean Expert Scheduler
"Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free" |
 |
RegCleaner
Added by an unidentified VIRUS, WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware |
 |
RegCompres
Added by the POLDO.B TROJAN! |
 |
RegCompres
Added by the DASMIN-E TROJAN! |
 |
Regcxdinaf
Added by the BANCOS-BW TROJAN! |
 |
Regcxmarq
Added by the BANCOS.DK TROJAN! Note that the filename has a leading space, ie, " REGCXMARQ.EXE" |
 |
Regcxn
Added by the COIBOA-D TROJAN! |
 |
regdefend
"RegDefend is a configurable, kernel based registry protection system, designed to intercept selected changes before they occur, thus also preventing malicious software like viruses, trojans and worms from using the registry to their advantage" |
 |
RegDone
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
 |
RegDone
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
RegDone Ex
Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
 |
RegDoneEx
Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
 |
regedit
Added by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
REGEDIT
Added by the SOUTHGHOST WORM! |
 |
regedit
Added by a variant of the RBOT WORM! |
 |
regedit
Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
 |
regedit
Added by the GANBATE.A WORM! Note - this is not the valid Windows registry editor which resides in Windows or Winnt and will not figure in Msconfig/Startup! This version resides in a "securityDatabase" subfolder |
 |
RegEdit32
Added by the VOUMIT-A WORM! Note - this is not the legitimate regedit32.exe application which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "mirc32" folder |
 |
Regexit
Added by the QQPASS-U TROJAN! |
 |
Regexit
Added by the QQPASS-N TROJAN! |
 |
RegFreeze
RegFreeze anti-spyware software |
 |
reggsdg
Added by the SDBOT-MS WORM! |
 |
RegHelp
SpyGraphica spy software - "Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world." |
 |
reginfo32
?? |
 |
Register Manager
Added by the SDBOT.AYH WORM! |
 |
Register MediaRing Talk
If you don't want to register MediaRing and be reminded about it every bootup disable it |
 |
Register SeqChk
?? |
 |
RegisterDropHandler
Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
 |
Registration Service
Added by the SDBOT-BB WORM! |
 |
Registration Service
Added by the SDBOT-HE TROJAN! |
 |
Registration-Studio 8
Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems |
 |
Registry
Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ShakiraPics.jpg.vbs" file is located in the Winnt or Windows folder |
 |
Registry
Blackbox captures emails and chat logs, and monitors Internet activity - remove if you didn't intentionally install it |
 |
Registry Checker
Added by the SDBOT TROJAN! |
 |
Registry Checkup
Added by an unidentified WORM or TROJAN! |
 |
Registry Checkup System326a Monitor
Added by a variant of the SDBOT WORM! |
 |
Registry Cleaner
Registry Cleaner misleading security software - not recommended, see here |
 |
Registry Integrity Checker
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
Registry Integritycheck
Added by the AGOBOT-RF WORM! |
 |
Registry Loader
Added by the GAOBOT.AO WORM! |
 |
Registry Loader
Added by the GAOBOT.AO WORM! |
 |
Registry Monitor
Added by the QKH TROJAN! |
 |
Registry oidet
Added by the RBOT.BMT WORM! |
 |
Registry Protector
Added by the ARIVER.A WORM! |
 |
Registry Scanner
Added by a variant of the OPTIX TROJAN! |
 |
Registry Serv
Added by the WEBMONEY-G TROJAN! |
 |
Registry Server
Added by the RBOT-GM WORM! |
 |
Registry Server
Added by a variant of the IRCBOT TROJAN! See here |
 |
Registry Service
Added by a variant of the RBOT WORM! |
 |
Registry Service
Added by the DELBOT-I WORM! |
 |
Registry Services
Added by the CILE TROJAN! |
 |
Registry Startup Check
Added by the REMLOAD-A or DANMEC-B TROJANS! |
 |
Registry System
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
Registry System16 Checkup Monitor
Added by a variant of the RBOT WORM! |
 |
Registry System166 Checkup Monitor
Added by a variant of the RBOT WORM! |
 |
Registry Value Name
Added by the RBOT-AFT WORM! |
 |
Registry Value Name
Added by the RBOT-AHT WORM! |
 |
Registry Value Name
Added by a variant of the RBOT WORM! |
 |
Registry Value Name
Added by the RBOT.BTZWORM! |
 |
Registry Value Name Start
Added by a variant of the SDBOT WORM! |
 |
RegistryCheck
Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
RegistryChk
Added by the MERTIAN WORM! |
 |
RegistryCleanFixMFC
RegistryCleanFix misleading security program - not recommended, see here |
 |
RegistryMechanic
Registry Mechanic - "you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages" |
 |
RegistryMonitor
Affilred adware |
 |
RegistryMonitor
Added by the SYSFADE TROJAN! |
 |
RegistryMonitor1
Added by the SPAMBOT TROJAN! |
 |
REGIST~1
Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
 |
Regkey for autostart
Added by the RBOT-NU WORM! |
 |
RegKillTray
DVD region killer part of CloneDVD from Elaborate Bytes AG. Copies the main movie, Special Features and/or the original menu onto a DVD Recordable or onto your harddisk |
 |
Regmonitor
Added by the BEAGLE.DO WORM! |
 |
REGMSYS
Added by the LOWZONE-AX TROJAN! |
 |
RegMutex
Added by the MSNOPT-A TROJAN! |
 |
RegPowerClean
RegistryPowerCleaner misleading secuirty software - not recommended, see here |
 |
RegProt
RegistryProt from Diamond Computer Systems - protects the system registry against changes |
 |
Regptmens
Added by the BANCOS-ED TROJAN! |
 |
Regro
Added by the OKARAG TROJAN! |
 |
RegRun
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! |
 |
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! |
 |
REGRUN
Added by the LOWZONE-AH TROJAN! |
 |
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! |
 |
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! |
 |
REGRUN
Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS! |
 |
RegRun WinBait
Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.. |
 |
Regrun2
Greatis Software's RegRun security suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc |
 |
REGRUNM
Added by an unidentified WORM or TROJAN! |
 |
Regrx
Added by the WAYIC-A TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). The file is located in C:Windows |
 |
Regscan
Added by the OPTIX-SE TROJAN! |
 |
RegScan
Added by the AGOBOT.AEW WORM! |
 |
RegScan
Added by the TALEX TROJAN! |
 |
RegServer
Related to XGI Technology's Volari graphics cards - what does it do and is it required? |
 |
regservices.exe
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
RegShave
Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly |
 |
regsrv
Added by the OPTIXPRO.11 TROJAN! |
 |
regsrv
Added by the AGOBOT.E WORM! |
 |
RegSrv64D
Added by the WINKO.AO WORM! |
 |
regsrvc
Added by the STOPED-A TROJAN! |
 |
Regsv
Search hijacker - redirecting to scheo.com |
 |
Regsvc
Added by an unidentified TROJAN! |
 |
regsvc32
Homepage hijacker that changes your homepage to an adult content site |
 |
regsvr
Added by the WEBMONEY-G TROJAN! |
 |
REGSVR32
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
 |
RegSvr32
Added by the ZLOB.B TROJAN! |
 |
regsync
SafeSurfing adware |
 |
regtmlp
?? |
 |
RegTweak
Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface |
 |
RegVer
Added by the LATINUS.16 TROJAN! |
 |
RegVfy32
Added by the SYGYP.A WORM! |
 |
RegWrite
Added by the SOKACAPS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%Media |
 |
Regx10EXE
ATI Remote Wonder? - PC wireless remote control driver. Required if you use it |
 |
reg_key
Added by the BEAGLE.AH WORM! |
 |
reg_key
Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS! |
 |
Reg_WFT
Added by the WILSEF VIRUS! |
 |
Reg_WFT
Added by the SENNASPY-F TROJAN! |
 |
ReleaseRAM
"Release RAM allows your computer to run faster and uses your computer's RAM more efficiently". MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind |
 |
relinson
Added by the DROPPER-PS TROJAN! |
 |
reload
Added by the LOVELETTER.AS VIRUS! |
 |
Reload
Added by the LAZAR TROJAN! |
 |
RemHelp
BT Voyager ADSL Modem Help related |
 |
Reminder
From MS Money. Reminds you of your bills |
 |
Reminder
HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list |
 |
Reminder
Registration reminder for the PC Pitstop Optimize 2.0 system optimizatoon utility by CA. Located in %ProgramFiles%\PCPitstop\Optimize2 |
 |
Reminder-cpqXXXXX
Compaq printer Registration |
 |
Reminder-hpcXXXXX
HP CD-Writer Registration |
 |
Reminder-ranXXXXX
Registration reminder widget for Rand Mcnally maps |
 |
reminder-ScanSoft Product Registration
Registration reminder for ScanSoft products such as PaperPort |
 |
RemindMe
Remind-Me - calendar software |
 |
Remind_XP
HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start -> PC Help & Tools -> Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list |
 |
Remndr
CasinoOnline foistware |
 |
Remote
Remote Control driver for LifeView internal and external TV products |
 |
Remote Access
Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed |
 |
Remote Access Adapter
Detected by PCTools as the IRCBOT.BIF TROJAN! See here |
 |
Remote Access Domain
Added by the IRCBOT.BFA TROJAN! |
 |
Remote Access Monitor
Added by a variant of the IRCBOT TROJAN! See here |
 |
Remote Access Service Manager
Added by the AGOBOT.KU WORM! |
 |
Remote Access Slave
Added by the RIPJAC TROJAN! |
 |
Remote Access Tool
Added by a variant of the IRCBOT TROJAN! See here |
 |
Remote Control
Hinet Hi-Five ISP software |
 |
Remote Controller
ProLink PlayTVpro TV tuner software |
 |
Remote Data Backups
System Tray access to Remote Data Backups online system/data backup utility |
 |
Remote Data Backups
Remote Data Backups online system/data backup utility |
 |
Remote Data Backups TaskBar Icon
System Tray access to Remote Data Backups online system/data backup utility |
 |
Remote Desktop Computing
Marspc Remote Desktop Computing |
 |
Remote Desktop Help Session Manager
Added by a variant of the SDBOT WORM! |
 |
Remote Event System
Detected by Trend Micro as the IRCBOT.YF TROJAN! See here |
 |
Remote Management Agent
Part of Novell's ZENworks - "Complete End-to-End Directory-enabled Network Management". Installed on a managed workstation fo an administrator to remotely manage the workstation. Required if the PC is a managed workstation |
 |
remote master
Required if you want your ASUS Remote control to work at all. Available via Start -> Programs |
 |
Remote Procedure Call
Added by the RBOT-KM WORM! |
 |
Remote Procedure Call
Added by the SDBOT-PS WORM! |
 |
Remote Procedure Call For Windows 32bit
Added by the RBOT-MD WORM! |
 |
Remote Procedure Call Locator
Added by the LOVGATE.F WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Remote Procedure Calls
Added by the RBOT.KJ WORM! |
 |
Remote Procedure Calls
Added by the RBOT-IT WORM! |
 |
Remote Procedure Calls
Added by the SDBOT-QI WORM! |
 |
Remote Services Manager
Added by a variant of the IRCBOT TROJAN! See here |
 |
Remote Storage Access
Added by a variant of the IRCBOT TROJAN! See here |
 |
Remote Terminal Task
Detected by Trend Micro as the IRCBOT.AUZ TROJAN! See here |
 |
Remote Update Monitor
Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer |
 |
RemoteAgent
Trend Micro's Office Scan Client, see here - "Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates" |
 |
RemoteCenter
Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats |
 |
RemoteControl
Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
 |
RemoteControl
Remote Control background application for Cyberlink's PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
 |
RemoteControl8
Remote Control background application for Cyberlink's PowerDVD version 8. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
 |
Remote_Agent
Cyberlink's Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs |
 |
REMOVE ME
Added by the SDBOT.EE WORM! |
 |
Removecpl
Related to a Belkin 54Mbps Wireless Utility Control Panel applet |
 |
Removed.exe
GatorCheat - adware downloader |
 |
RemoveIT Pro XT
RemoveIT Pro from InCode Solutions - spyware, virus and malware removal tool |
 |
RemStart
Part of McAfee's Remote Desktop 32 Agent application. What does it do and is it required? |
 |
renascimento
Detected by Kaspersky as the BANKER.GAX TROJAN! See here. Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the "Help" sub-folder of the Winnt or Windows folder |
 |
RenolB
?? |
 |
repl
Added by the YABE.CD TROJAN! |
 |
Replay Center
Replay Radio - "makes it easy to automatically record your favorite radio shows, so you can listen wherever and whenever you like" |
 |
Replicator
Replicator from Karen's powertools. "Automatically backup files, directories, even entire drives!" |
 |
RepliGo Assistant
Cerience RepliGo software - "any document you have on your PC can be transferred to your mobile device" |
 |
ReproPRD
Thrustmaster Corporation Presets application - a game controller driver, presumably necessary for certain functions to work |
 |
requester
Added by a variant of the MUQUEST.A trojan - NOTE: the * stands for a digit, examples: requester.5.exe, requester.10.exe |
 |
Requester
Added by the MUQUEST TROJAN! |
 |
Required Service Drivers
Added by the RBOT-ABD WORM! |
 |
resagnt
Adware downloader, identified by Panda antivirus as Trojan.Downloader.ALQ |
 |
ResChanger2004
EVGA graphic card utility providing easy access to display settings |
 |
reseurce
Added by the LINEAGE-AI TROJAN! |
 |
reseurce
Added by the LINEAGE-FV TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
Resolution Assistant
Dell Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decide |
 |
Resource Meter
Windows Resource Meter. Available via Start -> Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes |
 |
Restart Watch
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required? |
 |
Restart WSC Setting
WinStart Commander - part of Ultra WinCleaner Utility Suite. Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes |
 |
Restart_VS
Could be a left-over from the installation of a Viewsonic flat panel display |
 |
Restore Operation
Added by a variant of the RBOT WORM! |
 |
RestoreDesktop
Softwarium Restore Desktop "is a Windows Context Menu addition that automatically saves and restores the icons' positions on the Windows desktop after a resolution change" |
 |
RestoreIT!
RestoreIT! from FarStone "allows you to recover instantly your files, system configuration, and even your operating system, to any point in time prior to the data loss or system failure" |
 |
restory
Added by the RETSAM TROJAN! |
 |
Resume Copy
Part of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that function |
 |
ResumeFixClocks
Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards |
 |
reszrv
Added by a variant of the SDBOT WORM! See here |
 |
retime
Added by the GIPMA TROJAN! |
 |
RetrieverScheduler
80-20 Retriever from 80-20 - "80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information". Real-time scheduler - shortcut available |
 |
RetroExpress
EMC (was Dantz) Retrospect Express - backup software for external hardware storage devices |
 |
RevoTaskbarApp
Control Application for M-Audio Revolution 7.1 sound card. The sound card will function without it - but changes to speaker setup and sound modification (Bass/Treble etc) will not be available |
 |
RexSyMon
Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC |
 |
RF
Added by the LINEAGE-U TROJAN! |
 |
rfagent
Registry First Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders |
 |
rforce
Added by the DROPPER.KN TROJAN! Note the number "1" in the filename rather than letter "L". It also drops another file named DEVICEMAP.SYS which is the ROOTKIT.O TROJAN! |
 |
RFTray
Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs |
 |
rfw
RAV AntiVirus |
 |
RfwMain
Rising antivirus |
 |
rfwydg
?? |
 |
RFX_auto_upgrade
A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade |
 |
Rg2catbd
Added by a variant of the BANLOAD family of TROJANS! |
 |
RH
EuroFonts - adds Euro symbols to pre-Euro computers |
 |
Rhino
Added by the BOFRA.A WORM! |
 |
RhinoBlocker
RhinoBlocker - pop-up stopper |
 |
RHPTray
System tray access to Red Hot Pawn - online chess |
 |
RHSI SHS
Rogers Hi-Speed Internet software. "Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash" |
 |
RichMedia
HenBang adware |
 |
RichMedia
Henbang adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
richup
SafeSurfing adware |
 |
RightFAX Print-to-Fax Driver
Part of RightFAX from Captaris - "the proven market leader in fax server and document delivery software" |
 |
Ring Central Fax
Only needed if you want a PC to answer faxes automatically |
 |
rIOphosIs
Added by the RIOSYS MACRO! |
 |
Riorad Manager
"Riorad Explorer is hands-down the most advanced Windows software companion for your Rio MP3 player" |
 |
RivaTuner
RivaTuner for tweaking nVidia graphics cards. Required if you make any changes |
 |
RivaTunerStartupDaemon
RivaTuner for tweaking nVidia graphics cards. Required if you make any changes |
 |
RjLyraInstaller
?? |
 |
RK Launcher
RK Launcher by RaduKing - "is a free application that will allow the user to have a visually pleasing bar at the side of the screen that is used to quickly launch shortcuts" |
 |
rmalt
Added by the CLICKER-CS TROJAN! Filenames spotted inlcude Setup.exe, Keygen.exe, Keygen-Serial.exe, Photoshop.CS2.KeyGen.exe and more |
 |
rmctrl
Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one |
 |
rmdrfje.dll
Added by the DLOADR-ANM TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "rmdrfje.dll" file is located in the Winnt or Windows folder |
 |
rmmon
Resource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card |
 |
rmoc3260.dll OCX
A module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The "rmoc3260.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
RMremote
Remote control driver for REALmagic Xcard. Is it required? |
 |
rn4d
Added by the MAROON.A TROJAN! |
 |
Rnaomflt
Naomi internet filtering software |
 |
RNBc Test
Added by the RBOT-AGR WORM! |
 |
RNBc Test
Added by the RBOT-AJF WORM! |
 |
RNBOStart
Program used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools |
 |
RNBz Test
Added by the RBOT-AEY WORM! |
 |
RNDc Test
Added by a variant of the SDBOT WORM! |
 |
rndll2
May be related to the DivX program as a *.dat file in the same directory had "DivXPro505Bundle.exe" mentioned within? |
 |
rngmf
Added by the RANKY.C TROJAN! |
 |
Rnudll32
Added by the QQPASS-O TROJAN! |
 |
rnxqh
?? |
 |
Roam04
Added by the ROAMER-A TROJAN! |
 |
RoboForm
Roboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin |
 |
RoboFormWatcher
Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs |
 |
Rocket.Time
Rocket.Time - time synchronization software from Rocket Software |
 |
RocketDock
"RocketDock is a smoothly animated, alpha blended application launcher. It provides a nice clean interface to drop shortcuts on for easy access and organization" |
 |
Roflcopteur
Added by an unidentified WORM or TROJAN! |
 |
RogueMonitor
Rogue Remover PRO - utility to detect and remove misleading security programs masqerading as virus scanners, spyware removers, etc that lure people into buying them with false positives |
 |
roketpipe
?? |
 |
Rollback
Added by the RollBack Rx system restore program |
 |
rollbk
Added by the SERFLOG.B WORM! |
 |
rollbk
Added by the SERFLOG.B WORM! |
 |
rollbk
Added by the SERFLOG.B WORM! |
 |
rollbk
Added by the SERFLOG.B WORM! |
 |
romahere
SuperSpider hijacker - a CoolWebSearch parasite variant |
 |
romahere2
SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN! |
 |
romahere3
SuperSpider hijacker - a CoolWebSearch parasite variant. Also detected as the KREPPER-AE TROJAN! |
 |
Root_Machine
Added by the BANCBAN-DI TROJAN! |
 |
ROOT_Machine
Added by the BANKER-FI TROJAN! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This worm file is placed in the Windowsinf or Winntinf folder |
 |
ROUTD
?? |
 |
Router
Detected by Kaspersky as the AGENT.FJN TROJAN! See here |
 |
RoxAssist
Roxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use "Add Remove Programs" in "Control Panel"). Can be run manually |
 |
Roxio Engine
Not believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A TROJAN! |
 |
RoxioAudioCentral
Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. "Includes a player, media manager, ripper, tag and sound editor - integrated in a single application". Not required for Roxio to work properly. |
 |
RoxioDragToDisc
Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly |
 |
RoxioEngineUtility
Part of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking |
 |
RoxWatchTray
System Tray icon installed by Roxio Easy Media Creator 8 and which allows you to configure your watched folders or to turn the ?Watched Folders? feature of Roxio ON or OFF |
 |
RP32
Unicenter Remote Control (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems |
 |
RPC
Added by a variant of the GAOBOT/AGOBOT WORM! |
 |
RPC Drivers
Detected by Trend Micro as the SDBOT.FLY WORM! See here |
 |
RPC Patcher
Added by the BOLGI WORM! |
 |
RPC Service
Added by the AAD TROJAN! |
 |
rpc Win32
Added by the RBOT-ABL WORM! |
 |
rpc Win32
Added by a variant of the RBOT WORM! |
 |
RPCall_WIN2K
Added by the BHARAT.A WORM! |
 |
RPCall_[ComputerName]
Added by the REDPLUT-B TROJAN! |
 |
rpcc
Added by the SPAMMIT-E TROJAN! |
 |
rpcda Win32
Added by the RBOT-AE WORM! |
 |
RPCser32g
Added by the RITDOOR-C WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
RPCser32g1
Added by the PREXOT.D TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
RPCser32g3
Added by the PREXOT.D TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
RPCser32g4
Added by the PREXOT.E TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
RPCserr32g
Added by the RITDOOR-B WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
RPCserv32
Added by the MYDOOM.AL WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
RPCserv32g
Added by the BOBAX.AA WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder |
 |
RPCserv32g
Added by the BOBAX.AD WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
RPCserv32g
Added by the BOBAX.AD WORM! |
 |
RPCserv32g
Added by the BOBAX.AD WORM! |
 |
RPCserv32g
Added by the BOBAX.AD WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
 |
RPCSS.exe
Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here |
 |
RpcxWindows Extensions
Added by the RBOT.ACP WORM! |
 |
Rr2
Added by the LINEAG-ADI TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is located in an "addins" sub-folder |
 |
RRMedic
Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection |
 |
rscmpt
Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status |
 |
rsmb
Added by the WAREZOV.C WORM! |
 |
rsMenu
Synchronizes a Casio PDA with MS Outlook |
 |
RSPC Driver
Added by the RBOT-SN WORM! |
 |
RSPC Driver D
Added by a variant of the RBOT WORM! |
 |
RSRCMTZ
?? |
 |
rsrvmon.exe
Detected by Kaspersky as the AGENT.NY TROJAN! See here |
 |
RSS
"Related Sites" toolbar - SearchAndClick hijacker variant |
 |
RssReader
RssReader - a free RSS reader able to display any RSS and Atom news feed (XML) |
 |
RsWin
Added by the SILLY.BR WORM! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "4350" sub-folder |
 |
RSync
SafeSurfing adware |
 |
rtasks
Misleading security software such as AntiSpywareSuite, AntivirusPCSuite, SpyGuardPro, WinAntiVirus Pro 2006 - not recommended, see here |
 |
rtcdll
RTCDLL is "Real Time Communication" and is associated with Windows Messenger (the IM application, not messenger service). It is only necessary if you use Windows Messenger. Most people use MSN Messenger instead, so it is not required in those cases |
 |
RTHDCPL
Realtek HD Audio Sound Effect Manager |
 |
RtHDVCpl
High definition audio codec driver from Realtek Semiconductor |
 |
rtkernsw
Added by a variant of the SLAPER TROJAN! |
 |
rtl.exe
Added by the TIOTUA-J TROJAN! |
 |
RtlMon.exe
Monitor for RealTek network card |
 |
RTMonitor
Cheyenne (now eTrust) antivirus |
 |
rtos
IRC trojan |
 |
RTStartMute
?? |
 |
rtvscn95
Real-time virus scanner component of Norton Anti-Virus Corporate Edition |
 |
RtWLan
Configuration utility for the Netgear WG111 54 Mbps Wireless USB 2.0 Adapter that "provides wireless access to your desktop or notebook PC through the computer's USB port" |
 |
RubeL
Added by the RUBY-B TROJAN! |
 |
Ruby13
Added by the MEXER.E WORM! |
 |
Ruby14
Added by the FIGHTRUB-A WORM! |
 |
ruin
Added by the DELF-JM TROJAN! |
 |
RuLaunch
Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis |
 |
Run
Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
run
Added by the HOLCAS.A WORM! |
 |
run
Added by the BINGHE TROJAN! |
 |
Run
Identified as the DELF.LF by Ewido Security Suite |
 |
run
Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
run
Added by the SQUATBOT-C TROJAN! |
 |
run
Added by the IMONI-E TROJAN! |
 |
run
Added by the BCKDR-QHR TROJAN! |
 |
Run Google Web Accelerator
Google Web Accelerator |
 |
Run Msn Messenger
Added by the AGOBOT.HA WORM! |
 |
Run MSupdt32
Added by the CASER WORM! |
 |
Run Nintendo Wi-Fi USB Connector Registration Tool
Related to Wi-Fi USB Connector from Nintendo |
 |
Run POPFile in background
POPFile - E-mail spam blocker |
 |
Run POPFile in background
POPFile - E-mail spam blocker |
 |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
Run Services as Application
Added by the DLOADER-NY TROJAN! |
 |
Run StartupMonitor
Mike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu |
 |
run windows
Added by the REBOOT-AP TROJAN! |
 |
Run XP Service Pack
Added by the SDBOT.AQA WORM! |
 |
Run05
Added by the BANCOS-DT TROJAN! |
 |
run32
Added by the SDBOT-CWB WORM! |
 |
run32dll
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
run32dll
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
Run32dll
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
run=
MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI) |
 |
run=
HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature |
 |
run=
Lexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS |
 |
run=
pcfix2k splash screen |
 |
run=
PhoenixNet BIOS adware. See here |
 |
run=
Advanced Startup Manager from Rays Lab |
 |
run=
Desktop wallpaper changer? |
 |
run=
CoolWebSearch parasite variant |
 |
run=
CoolWebSearch Tapicfg parasite variant |
 |
run=
Microsoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs |
 |
run=
?? |
 |
run=
Added by the LOVGATE-F WORM! |
 |
run=
Added by the ATAK.F WORM! |
 |
run=
Reportedly part of Lexmark printer software - what does it do and is it required? |
 |
run=
FMedia FaxWorks related - can be run manually |
 |
run=
Used with some models of Panasonic, Epson and NEC printers - required for printer to work |
 |
run=
Unidentified malware |
 |
run=
CoolWebSearch Tapicfg parasite variant |
 |
run=
Added by the GAGGLE.E WORM! |
 |
run=
Added by the APSTROJAN.OB TROJAN! |
 |
run=
Added by the ATAK.G WORM! |
 |
run=
CoolWebSearch Smartsearch parasite variant |
 |
run=
Added by the HOLCAS.A WORM! |
 |
run=
Searchforfree.info browser hijacker |
 |
run=
Added by the ADWARELOADER TROJAN! Note - do not confuse with the legitimate Microsoft Office file, which would typically be located in the Program FilesMicrosoft OfficeOffice folder! |
 |
run=
Added by the SEMAPI-A WORM! |
 |
run=
Added by the ADMINCASH.B TROJAN! |
 |
run=
Added by the DUMARU-L TROJAN! |
 |
run=
Added by the PROXY-GG TROJAN! |
 |
run=
Added by the CELINE-A TROJAN! |
 |
run=
Added by the KREPPER-N TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "inet10066" subfolder of the Windows or Winnt folder |
 |
RunAlert
MSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you "overclock" your system |
 |
runAP
Not required but what is it? |
 |
runapp
Added by the BOMKA TROJAN! |
 |
Runapp32
Added by the NEODURK TROJAN! |
 |
RunCA
Wireless-G USB Wireless Network Adapter related - would appear to be required |
 |
Rund11
Added by the MARIO-C WORM! |
 |
rund1132
Added by the DOPBOT-A WORM! |
 |
Rund1132.exe
Added by the STARTPA-HS TROJAN! |
 |
Rund1l32
Added by the MERTIAN WORM! |
 |
runddlfile
Added by the DELF.D TROJAN! |
 |
Rundil32
Added by the QQPASS-U TROJAN! |
 |
Rundil32
Added by the QQPASS-N TROJAN! |
 |
rundl332
Added by the DOOMJUICE WORM! |
 |
rundli32
Added by the LADE WORM! |
 |
RunDLL
Flingstone.com browser hijacker. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "qkoszvd.dll" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
Rundll
Added by the DELF-KT TROJAN! |
 |
Rundll
Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
RunDll
Added by the QQPASS-AH TROJAN! Note - this is NOT the Windows system file of the same name as described here |
 |
RunDLL Kernel File Core
Added by a variant of the SLAPER TROJAN! |
 |
rundll***
Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
 |
rundll***
Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
 |
rundll***
Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
 |
rundll***
Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946 |
 |
Rundll16
Added by a number of VIRUSES, WORMS and TROJANS! |
 |
Rundll32
Added by the DVLDR TROJAN! Note - this is not the valid "Rundll32.exe" as it's in the WindowsFonts directory |
 |
RUNDLL32
System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here) |
 |
RunDLL32
System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties |
 |
rundll32
Loads default settings for Leadtek Winfast graphics cards |
 |
RunDLL32
Added by an unidentified TROJAN! - possibly a BMBOT variant |
 |
Rundll32
Added by the QQPASS.E TROJAN! |
 |
Rundll32
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. Tells the drivers that the connected Drives should use the "Write Back" Caching. You can disable this if you don't want to use "Write Back" Caching or if you have not connected any driver to your Promise Controller |
 |
rundll32
Added by the AUTEX WORM! |
 |
rundll32
Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller |
 |
rundll32
Added by the SANKER WORM! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This one is is located in the Winnt or Windows folder |
 |
rundll32
Added by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
rundll32
Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup |
 |
RUNDLL32
Added by the DEMOTRY-A WORM! |
 |
rundll32
Added by the AGENT-EZ TROJAN! Note - the real rundll32.exe resides in the System (9x/Me) or System32 (NT/2K/XP) folder whereas this file is found in a "SHELLEXT" subfolder |
 |
Rundll32
Added by the STARTPAGE.AXH TROJAN! |
 |
rundll32
Added by the STAP-C WORM! |
 |
rundll32
Added by the STAP-D WORM! |
 |
rundll32
Added by the STAP-E WORM! |
 |
rundll32
Added by the ROOKIE-A TROJAN! |
 |
rundll32
Added by the DELF.BKC TROJAN! |
 |
Rundll32 cmicnfg
System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel |
 |
RunDll32 essprops
Associated with a Logitech mouse - required for proper operation |
 |
Rundll32 P17
ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality |
 |
Rundll32.exe
Added by the GRUEL WORM! |
 |
Rundll32.exe
Added by the GRUEL WORM! |
 |
Rundll32_7
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Rundll32_8
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
Rundll32_8
BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
 |
rundll64
Added by the AUTEX WORM! |
 |
RundllSvr
Added by the HUAYU WORM! Note - this is NOT the Windows system file of the same name as described here |
 |
Rundllsystem32
Added by the NETDEVIL.B TROJAN! |
 |
Rundnm
Added by the DELF-HA TROJAN! |
 |
RUNGogoTools
GoGoTools adware |
 |
RUNGogoTools
GoGoTools adware |
 |
RUNHYPER
PurityScan/Clickspring adware |
 |
runing
Added by the DELF-LC TROJAN! |
 |
RUNLOAD
PurityScan/Clickspring adware |
 |
RUNLOUD
PurityScan/Clickspring adware |
 |
Runmarc8mManager
MARC Sound System Manager for the Marc 8 MIDI sound card - allows for easy adjustment of the settings |
 |
RunNarrator
Associated with the Narrator accessibility feature on Windows XP. It is used to convert text to speech |
 |
Runner
Added by the DROWSY-B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located the Winnt or Windows folder |
 |
Runner
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
Runner
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
Runner
Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
 |
runner1
Added by the CRYPT.ULPM.GEN TROJAN! |
 |
runner1
Added by the AGENT.SLZ TROJAN! |
 |
runner1
Added by the AGENT.CZC TROJAN! |
 |
runner1
Added by the SMALL.CTV TROJAN! |
 |
runner1
Added by the AGENT.ABFQ TROJAN! |
 |
RunOnce
Part of MS Data Access Components - only required if you use these |
 |
Runonce
Added by the CHIR-B WORM! |
 |
RunOnceEx
Identified as the DELF.LF by Ewido Security Suite |
 |
RunProg
Added by the OPTIX.04.A TROJAN! |
 |
RunProg
Added by the OPTIX.04.D TROJAN! |
 |
runreper
Added by the REPER.A VIRUS! |
 |
runs
Added by the RBOT-BWF WORM! |
 |
RunSearvices
Identified as the DELF.LF by Ewido Security Suite |
 |
RunServices
Added by the AGOBOT.QJ WORM! |
 |
runservices
Identified as a variant of the SMALL.QO TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
runsql
Detected by PCTools as the DELF.ZWK TROJAN! See here |
 |
runSubvalues
Added by the DLOADER-QY TROJAN! |
 |
runsvc
Added by the SMALL-CF TROJAN! |
 |
RunSysd32
DesktopShield2000 by St?phane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within |
 |
Runtime Process
Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
runtime.exe
Added by a variant of the Tibs malware |
 |
Runtt1
Added by the LINEAGE-R TROJAN! |
 |
Runtt1
Added by the LINEAGE-Q TROJAN! |
 |
RunWin
Added by the BANKER-ES TROJAN! |
 |
runwin32
Added by the ESEARCH-A TROJAN! |
 |
RUNWIN32
Added by the VB-AET TROJAN! |
 |
RunWindowsUpdate
BrowserAid/BrowserPal foistware |
 |
runwinlogon
Detected by Trend Micro as the AGENT.TQY TROJAN! See here. Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
 |
Run[0]
Added by an unidentified VIRUS, WORM or TROJAN! "syscnfg.exe" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside |
 |
Run_cd
Added by the GHOST.23 TROJAN! |
 |
run_pbnext
PBNext is virtual phone system which offers the same functionality as expensive PBX hardware |
 |
Rupsw32
MegaTec Rups, UPS monitoring software - monitor and control DB9 UPS running on either Windows & Novell NetWare (with RUPS 2000) or Unix (with RUPS for Unix / Plus) operating systems |
 |
RUSBHOLoader
?? |
 |
RVC6Player
Added by the ZAPCHAS-M TROJAN! |
 |
rvde
Related to li-speed**** |
 |
RVP
Spyware included with the latest version of Grokster |
 |
rw service
Added by the LOOPAD.A TROJAN! |
 |
rx
Added by the LINEAGE-BP TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is found in the Windows or Winnt folder |
 |
rx
Added by the ZHENGTU-A TROJAN! |
 |
RxMon
Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail" |
 |
RxUser
Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail" |
 |
ryan1918
Added by the RBOT-GVR WORM! |
 |
rydanmxe.exe
Added by the DLOADR-AZZ TROJAN! |
 |
ryy
Added by the PWS-ANA TROJAN! |
 |
rzt
Added by the LINEAGE.BDP TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in the Windows folder (98ME) or the System32 folder(NT2000XP). This file is found in an "Intel" sub-folder of the Windows or Winnt folder |
 |
r_server
Radmin - remote admistrator server |
 |
r_server
Added by the MULTIDR-CP TROJAN! |