| Name | Status | Filename | Description |
|---|
| Rockwell Directory Server (RNADirectory) | L | RnaDirServer.exe | Related to Rockwell_Automation Inc. FactoryTalk suite |
| Rockwell Event Multiplexer (EventClientMultiplexer) | L | EventClientMultiplexer.exe | Related to Rockwell_Automation Inc. FactoryTalk suite |
| Rockwell HMI Activity Logger | L | RsActivityLogServ.exe | Related to Rockwell_Automation Inc. FactoryTalk suite |
| Rockwell HMI Diagnostics | L | HMIDIAGNOSTICSLSTADAPT.exe | Related to Rockwell_Automation Inc. FactoryTalk suite |
| Rockwell Tag Server | L | TagSrv.exe | Related to Rockwell_Automation Inc. FactoryTalk suite |
| rofl (rofl) | X | rofl.sys | Added by the Troj/RKPort-Fam
TROJAN!
This is a rootkit! |
| Roger Wilco Base Station | L | rwbs.exe | Related to IGN_Entertainment Inc. Required to operate the Wilco Base Station. |
| Rogers Update Manager (RogersUpdateManager) | L | RogersUpdateManager.exe | Searches for updates for the Rogers Yahoo!_Browser Note: Located in \%Program Files%\Rogers\Update Manager\ |
| RollbackClientService | L | RollbackClnt.exe | Horizon DataSys Rollback Rx |
| Routing Service (Routing) | X | routing.exe | Added by an unknown Trojan/Backdoor Note: Located in \%WINDIR%\System32\ |
| Roxio Hard Drive Watcher (RoxWatch) | L | RoxWatch.exe | Related to Roxio_Inc |
| Roxio Hard Drive Watcher 10 (RoxWatch10) | L | RoxWatch10.exe | Related to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Common Files\Roxio Shared\10.0\SharedCOM\ |
| Roxio Hard Drive Watcher 9 (RoxWatch9) | L | RoxWatch9.exe | Related to Roxio_Inc |
| Roxio UPnP Renderer 10 | L | RoxioUPnPRenderer10.exe | Related to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Roxio\Digital Home 10\ |
| Roxio UPnP Renderer 9 | L | RoxioUPnPRenderer9.exe | Related to Roxio_Inc |
| Roxio Upnp Server 10 | L | RoxioUpnpService10.exe | Related to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Roxio\Digital Home 10\ |
| Roxio Upnp Server 9 | L | RoxioUpnpService9.exe | Related to Roxio_Inc |
| RoxMediaDB | L | RoxMediaDB.exe | Related to Roxio_Inc |
| RoxMediaDB10 | L | RoxMediaDB10.exe | Related to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Common Files\Roxio Shared\10.0\SharedCOM\ |
| RoxMediaDB9 | L | RoxMediaDB9.exe | Related to Roxio_Inc |
| RoxUpnpRenderer (RoxUPnPRenderer) | L | RoxUpnpRenderer.exe | Related to Roxio_Inc |
| RoxUpnpServer | L | RoxUpnpServer.exe | Related to Roxio_Inc |
| RPAService | L | RPAService.exe | Related to Gilat Satellite Networks Ltd. Note: Located in \%Program Files%\GILAT\Internet Page Accelerator\ |
| RPC Debug Control (RPCDB) | X | csts.exe | Added by the Backdoor.Win32.SdBot.aad as identified by Kaspersky TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| RPC+ Service Provider (RPCSS+) | X | rpcss_pl.exe | Trojan. - http://www.what-process.com/process-info.aspx?p=rpcss_pl.exe |
| RpcRemotes | X | remote.exe | Added by the W32/Fanbot-J
WORM!
Note: This worm file is found in the System32 folder. Be sure to check the link on this one. Copies it's self to various folders and file names.
|
| RSLinx | L | RSLINX.EXE | Related to Rockwell_Automation Inc. FactoryTalk suite |
| RSLinx Enterprise (RSLinxNG) | L | RSLinxNG.exe | Related to Rockwell_Automation Inc. FactoryTalk suite |
| Rtkit | X | Rtkit.exe | Added by the Backdoor.Rtkit
TROJAN!
Read the link, rootkit type stealth involved.
|
| rtvscan | X | rtvscan.exe | Added by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\ This infection should not be confused with the legitimate Note: Note: Located in \%Program Files%\Symantec\SAV\Rtvscan.exe file. |
| rudll | X | rudll.exe | Troj/Hupigon-CF Note: Located in %windir% Read the link, allows remote access |
| RUMBA AS/400 Shared Folders (Wdworkstation) | L | wdnpsvc.exe | Related to RUMBA which provides connectivity from Microsoft Windows desktops to virtually any host system with mission critical reliability. From NetManage Inc. Note: Located in \%WINDIR%\System32\ |
| Run RunOnce | L | ShipUPS.EXE, RunOnce.exe | Related to UPS WorldShip shipping software |
| rundll.exe | X | msn93.exe | Added by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ |
| rundll.exe | X | msngrsm.exe | Added by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ |
| rundll.exe | X | rundll.exe | Added by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\ |
| rundll32 (rundll32) | X | rundll32.exe | Added by the Troj/Feutel-Q
TROJAN! |
| rundll32.exe | X | lsass.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ |
| Runtime | X | runtime.sys | Troj/Agent-ECZ Note: Located in %windir%\system32 |
| Runtime | X | runtime.sys | Troj/Pushu-Gen
Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) May also have an additional services installed. Read link |
| runtime2 | X | runtim2.sys | Troj/DropRk-A
Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) |
| Rupsd | L | Rupsd.exe | Related to Mega_System Technologies Inc. |
| Rupsmon | L | RupsMon.exe | Related to Mega System Technologies, Inc. |
| RVS CommCenter (RvsCC) | L | RVSCC.EXE | Legit Fax/Digital Answering Machine/Telephony service. Owner Unknown . Located in C:\Program Files\Teledat\WCOM\SYSTEM\ |
| RVS Installer (RVSINST) | L | RVSINST.EXE | Legit Fax/Digital Answering Machine/Telephony service. Owner: RVS Datentechnik GmbH, München. Located in: C:\Program Files\Teledat\WCOM\SYSTEM\ |
| Rwx (Rwx2005) | X | svhosts.exe | Added by the Troj/Subzero-B
Trojan!
|
| r_server | X | service.exe | Added by the Troj/Remadm-G
TROJAN!
Note: This is not the legitimate Windows process services.exe (Notice the difference in the spelling.) This trojan file (service.exe) is also found in the System32 folder.
|
| S3 Graphics Co., Ltd. | X | VTTrayp.exe | W32/Sdbot-DHA Note:Located in C:\Windows (Win9x/Me), C:\%WINDIR% (Vista/XP/WinNT/2K) |
| s3contrl (32-bit) | X | VTTray.exe | Added by a variant of the Backdoor.Win32.SdBot.cep family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\ |
SafeBoot Configuration Manager (SafeBootConfigurationManager) | L | SBMGRNT.EXE | Related to SafeBoot_Configuration Manager. Encryption software. Note: Located in \%Program Files%\SafeBoot\ |