| Name | Status | Filename | Description |
|---|
| Remote Procedure Call (RPC) Relocator (RpcRelocator) | X | relocater.exe | Added by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ |
| Remote Procedure Call (RPC) Remote (RpcRemotes) | X | remote.exe | Added by the W32/Mytob-EW
WORM! or Troj/Agent-FB
TROJAN! Note: This worm\trojan file is found in the System32 folder. |
| Remote Procedure Call (RPC) Service (RpcSssvc) | X | RpcSs.exe | Added by the W32/Cuebot-J WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Note: The file RpcSs.exe is also a good Microsoft file. Before deleting check the propriatiry of the file. |
| Remote Procedure Call (RPC) Subsystem (RPCS) | X | rpcss.exe | W32/Tilebot-JF Read the link, allows remote access |
| Remote Procedure Call System (RPCS) | X | Win.exe | Troj/Dropper-PT
Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Remote Procedure Call System(RPCS) (RpcS) | X | Rpcs.exe | Added by the Troj/QQRob-ABS TROJAN!
Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) |
| Remote Procedure Call System(RPCS) (RpcSe) | X | Rpcse.exe | Added by the Troj/Mdrop-BMK TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Remote Procedure Call System(RPCSss) (RpcSss) | X | RpcSss.exe | Added by the Troj/QQRob-ACI TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Remote Procedure Call System(RPCSU) (RpcSu) | X | Rpcsu.exe | Added by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) |
| Remote Procedure Call System(RPCSx) (RpcSx) | X | Rpcsx.exe | Added by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) |
| Remote Process Killer | O | RKillSrv.exe | The Windows NT Resource Kits, both NT4 and Windows 2000 Professional, include a remote kill process commandline utility rkill.exe . To be able to kill a process or processes running on a remote server, you must have admin privileges and the rkillsrv.exe service must be installed and running. If this service was not installed by you or an LAN Admin. remove it. Note: Located in \%WINDIR%\System32\ |
| Remote Reader Machine | X | ssmc.exe | Added by the Backdoor.SdBot.avk as detected by ewido. More here |
| Remote Record Service (RemoteRecord) | L | remoterecordclient.exe | Related to MSN_TV Note: Located in c:\program files\microsoft corporation\msn remote record service\ |
| Remote Republic Services | X | svshost.exe | Added by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\ |
| Remote Run Services | X | svshost.exe | Added by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\ |
| Remote Services Manager (RSMSS) | X | (Trojan file name) | Added by the Troj/Bckdr-BBK
TROJAN!
|
| Remote Solver for COSMOSFloWorks 2006 | L | StandAloneSlv.exe | Related to COSMOS_FloWorks From COSMOS. CAD program. Note: Located in C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\ |
| Remote Storage (Rmtstrg) | X | taskmgr.exe | Added by the Troj/Spy-UN TOJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) Read the link, monitors websites visited and report them to a remote site |
| Remote Storage (RS) (Rmtstrg2) | X | taskmgr.exe | Added by a varian the Troj/Spy-UN TOJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) Read the link, monitors websites visited and report them to a remote site |
| Remote Task Manager service (RTM) | L | RTMService.exe | Related to Remote_Task_Manager remote control suite. Note: Located in C:\Program Files\Remote Task Manager\ |
| Remote TCP Services | X | vcmon.exe | Added by the W32/Tilebot-HX WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) disabling the automatic startup of other software. |
| Remote TCPI Services | X | svshost.exe | Added by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Remote Terminal (RemoteTerminal) | X | mscp.exe | Added by the Backdoor.Win32.SdBot.aad TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Remote Time Pluger | X | svshost.exe | Added by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Remote Transfer Manager | X | svshost.exe | W32/Rbot-GQR Read the link, allows remote access |
| Remote Windows Services | X | vcmon.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| RemoteControlService.exe | L | RemoteControlService.exe | Related to ITE_Remote_Control Service from ITE Tech. Inc. Note: Located in \%WINDIR%\System32\ |
| Remotely Possible/32 (RP32Service) | L | rp32serv.exe | Related to Avalan now owned by Computer Associates International, Inc. http://ca.com/products/ |
| RemotelyAnywhere | L | RemotelyAnywhere.exe | Related to RemotelyAnywhere
Made by 3am Labs Inc. This file should be found in the Program Files\RemotelyAnywhere folder. |
| RemotelyAnywhere Maintenance Service (RAMaint) | L | RaMaint.exe | Related to RemotelyAnywhere
Made by 3am Labs Inc. This file should be found in the Program Files\RemotelyAnywhere folder. |
| RemoteRegBck | X | regsvc.exe | Added by Backdoor.Win32.SdBot.aad as identified by Kaspersky. TROJAN!
Note: located in C:\WINDOWS\. Not to be confused with the Original Microsoft file in C:\WINDOWS\system32\ |
| Removale Sorage (RemovaleSorage) | X | G_Server.exe | Added by the Troj/Feutel-AT
TROJAN!
Note: This trojan file is found in the System32 folder. |
| Required Service Drivers | X | micront.exe | Added by the W32/Rbot-ABD WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) terminate threads and processes read the information |
| Reset 5 | O | srvany.exe | Unknown owner: Location C:\Windows\System32\srvany.exe
In this case srvany.exe is loading resetservice.exe as a service.
May be found in the company of
O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll
Windows XP Product Activation Bypass
So as to avoid the registration process on boot-up.
Typically used on a pirated Operating System.
|
| Resource Manager Mail (ResourceManagerMail) | L | MailService.exe | Related to Citrix Systems, Inc. |
| restore (restore) | X | restore.exe | Added by the SDBOT.CFD
WORM!
Read the link, rootkit type stealth involved.
|
| Retrospect Client | L | RemotSvc.exe | Related to Dantz Development Corporation |
| Retrospect Express HD Launcher (RetroExpLauncher) | L | retrorun.exe | Related to Dantz Development Corporation |
| Retrospect Express HD Restore Helper (RetroExp Helper) | L | rthlpsvc.exe | Related to Dantz Development Corporation |
| Retrospect Helper | L | rthlpsvc.exe | Related to Dantz Development Corporation |
| Retrospect Launcher (RetroLauncher) | L | retrorun.exe | Related to Dantz Development Corporation |
| Retrospect WD Service (RetroWDSvc) | L | wdsvc.exe | Related to Dantz Development Corporation |
| Reuters XMS Sync (RXMSSync) | L | rxmssync.exe | Related to Reuters_XMS_Sync routers. Note: Located in http://www.routers.com/ |
| RevUDFService | L | RevUDF.exe | Related to Iomega_Corp provider of a number of backup data solutions |
| Rio MSC Manager (RioMSC) | L | RioMSC.exe | Related to Digital Networks North America. |
| Rising Personal Firewall Service (RfwService) | L | rfwsrv.exe | Related to Rising_Personal_Firewall, Rising Personal Firewall from Beijing Rising Tech., Corp. service. Note: Located in \%Program Files%\rising\rfw\ |
| Rll enhanced drive (mfm) | X | msrll.exe | Added by the Troj/Jtram-E
TROJAN!
Note: This trojan file is found in the System32\mfm folder. |
| RoamMgr | L | RoamMgr.exe | Intel PROset |
| Rockwell Application Services (RsvcHost) | L | RsvcHost.exe | Related to Rockwell_Automation Inc. FactoryTalk suite |
| Rockwell Directory Multiplexer (RNADirMultiplexor) | L | RNADirMultiplexor.exe | Related to Rockwell_Automation Inc. FactoryTalk suite |