| Name | Status | Filename | Description |
|---|
| RdnaoFlSvc | L | naofsvc.exe | Related to Naomi an advanced internet filtering program. |
| rdriv (rdriv) | X | rdriv.sys | Added by the Troj/Rootkit-W
TROJAN!
Read the link, rootkit type stealth involved.
|
| ReaConverter scheduler service (rcp_service) | L | rcp_scheduler.exe | Related to ReaConverter image editing features make the Lite edition a perfect choice for home users. Note: Located in \%Program Files%\ReaConverter 5.0 Pro\ |
| Realplus (Realplus) | X | sserver.exe | Added by the Troj/Paltus-A
TROJAN!
Note: This trojan file is found in the System32 folder.
|
| Reflection Line Printer Daemon | L | lpdserv.exe | Related to http://www.wrq.com/ |
| Reflection Servers | L | rninetd.exe | Related to http://www.wrq.com/ |
| Reflection TimeSync | L | rtsserv.exe | Related to WRQ, Inc. http://www.wrq.com/products/reflection/ |
| regdefend | L | regdefend.sys | See Ghostsecurity
Location: C:\Program Files\RegDefend\regdefend.sys
|
| Regedits Helpers (Windows Regedits Help) | X | iesetup.exe | Troj/Hupigon-KX Note: Located in %windir%\help |
| Regedits Helps (Windows Regedit Helps) | X | iesetup.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\iis] (Win9x/Me), C:\%WINDIR%\System32\iis\ (XP/WinNT/2K) More here |
| Register DLL Driver | X | regdll.exe | Added by the W32/Sdbot-CXB WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| Register Manager | X | regent.exe | Added by the W32/Sdbot-DFJ WORM! Note: This worm is located in \%WINDIR%\ Read the link, allows remote access. |
| Registration Host (reghost) | X | reghost.exe | Added by the W32/Rbot-GKS WORM! Note: This worm is located in C:\Program Files\Common Files\System\ |
| Registro de sucesos (Eventlog) | L | services.exe | Spanish Windows 2000 event logger |
| Registros y alertas de rendimiento (SysmonLog) | L | smlogsvc.exe | Spanish Windows 2000 performance logs and alerts |
| Registry Editor (Regedit) | X | regedit.exe | Added by the W32/Codbot-U
TROJAN!
Note: This is not the regedit application that comes with Windows. (Which is located in the Windows folder) This trojan file is located in the System or System32 folder. |
| Registry Management Service (RegManServ) | L | RegManServ.exe | Related to Complete_PC_Care from WinCleaner. Note: Located in C:\Program Files\Advanced Registry Doctor\ |
| Registry Manager Service (MS Registry Service) | X | MSRMS32.exe | Added by the W32/Rbot-AKP
WORM!
|
| RegService | L | RegService.exe | Related to Intel Corp. http://www.intel.com/network/connectivity/trans/xircom.htm |
| RegSrvc | L | RegSrvc.exe | Intel PROset |
| regstrmon | X | regstrmon.exe | AddeD by the WORM_RBOT.ADA WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder. |
| RelevantKnowledge | X | rlservice.exe | Added by the Marketscore.RelevantKnowledge ADWARE! Note: Located in \%WINDIR%\System32\ |
| remon (remon) | X | remon.sys | Added by the Troj/RKFu-A
TROJAN!
Read the link, rootkit type stealth involved.
|
| Remote Acces (WindowsDown) | X | servet.exe | Troj/Dloadr-AYT |
| Remote Acces (WindowsFix) | X | servet.exe | W32/Sekap-A Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
Allows remote access |
| Remote Access Controller 4 (RAC) (racsvc) | L | racsvc.exe | Related to Dell Open Manage NT Utilities program that allows remote access and control of a computer. This is a common program for hackers to install on a computer, so if it is installed, and you did not install it, it should be removed.
|
| Remote Account Manager (ramtsvc) | X | rasmvc.exe | Added by an Unknown malware Note: Located in \%WINDIR%\System32\mui\ |
| Remote Administrator Service (r_server) | X | systemram.exe | Added by the Troj/Radnag-B
Trojan!
|
| Remote Administrator Service (r_server) | X | r_server.exe | Added by the Troj/Remadm-J
TROJAN!
Note: This trojan file is found in Program Files\real\RealOne Player\lang folder. |
| Remote Administrator Service (r_server) | O | r_server.exe | Related to r_server.exe part of a remote administrator application that allows a user to work on one or more remote computers. The application contains features such as File Transfer, NT security and Telnet. Note: Located in \%WINDIR%\System32\ If you did not installed this server it is suggested that your remove it |
| Remote Break Manager | X | svshost.exe | Added by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Remote Desktop Help Session Manager (RDSessMgr) | L | sessmgr.exe | Related to Microsoft's remote assistance windows plugin. This allows an end user to call for assistance when a remote assistance network service is in place. This process shouldn't be terminated if the fore-mentioned service is in place on your local area network. |
| Remote Displays Service | X | svshost.exe | Added by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Remote Help Session Manager (Rasautol) | X | ntsokele.exe | W32/Fujacks-AP Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows others to access the computer |
| Remote HID Service (LvHidSvc) | O | lvhidsvc.exe | Remote access service by Philips Inc. Legitimate, but remote access could be considered dangerous unless monitored carefully. |
| Remote management (Novell WUser Agent) | L | wuser32.exe | Related to Novel, Inc. |
| Remote Map Manager | X | lssc.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Remote Media Player | X | lsscs.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Remote Neon Services | X | svshost.exe | Added by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Remote NetBIOS Manager | X | svshost.exe | Added by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
|
| Remote NTstat Services | X | svshost.exe | Added A variant of the Backdoor.Sdbot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
Remote Packet Capture Protocol v.0 (experimental) (rpcapd) | L | rpcapd.exe | Related to Winpcap (Windows Packet Capture Library) |
| Remote Print Spooler (RPSGV) | X | gcsvc.exe | Added by a variant of the Win32.SdBot.aad a TROJAN! identified by F-Secure. Note: This trojan is located in C:\%WINDIR%\ |
| Remote Procadure Call (RPC) (RpeSs) | X | svchost.exe | Troj/Hupigo-UN Read the link, steals information Note: Located in %windir% |
| Remote Procedure Call (RPC) Client (RpcClient) | X | rpcclient.exe | Added by the W32/Codbot-L
WORM!
|
| Remote Procedure Call (RPC) Helper | X | random | CoolWebSearch malware |
| Remote Procedure Call (RPC) Helper ( 6Q'8) | X | ipjp32.exe | Added by the Trojan.Win32.Agent.bi TROJAN! Note: located in \%WINDIR%\ |
| Remote Procedure Call (RPC) Locator (Locator) | X | rpclocator.exe | Added by the W32/Codbot-Q
WORM!
|
| Remote Procedure Call (RPC) Monitoring (Rpcmon) | X | Rpcmon.exe | Added by the W32/Codbot-T
WORM!
|
| Remote Procedure Call (RPC) Net (Rpcnet) | L | Rpcnet.exe | Related to Laptop_Retriever |