CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9466.22 of $21422.68
left sidedonated so farneed $11956.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

spacer spacer

O23 List of Windows XP/NT services

Currently 3876 entries and growing...
Last updated on 2008-05-09 18:10:24 Eastern.


This list was originally started at SpywareAid with 730 entries and Matt gave CastleCops permission to host it. CastleCops has since (May 2005) been adding new entries to it here. The new items may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

KEY:
  • "L" = Legitimate
  • "O" = Open to Debate
  • "X" = Malware/Bad
  • "?" - Unknown

  •   

    ABC List: A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z




    Full List

    NameStatusFilenameDescription
    R2d2 Kernel AuthorityLKAuthS.exeRelated to R2D2 Software, a Windows service that manages desktops and programs. Without it, no desktops, no virtual screen, no remote access, no user impersonation, ... If you stop this service, all desktops (except the default one) are destroyed. Virtual Desktop Toolbox is no more than a client application of R2d2 Kernel Authority
    RA ServerXSlave.exeBackdoor.RA virus http://www.avp.ch/avpve/trojan/backdoor/ra.stm Better alternatives are PC Anywhere or VNC
    RA Server (Slave)LSlave.exeRelated to RA_Server from TWD Industries. allows remote desktop administration over a TCP/IP network. Note: Located in C:\%WINDIR%\
    Rabo Comm ServerLRaboCommSrv.exeRelated to the Rabobank, telebanking (Netherlands)
    Radan Licence ServerLradlicence2.exeRadan Sheet Metal CADCAM Software
    RadClockLRadClock.exeATI/Radeon Video Card Setting Tweaking Utility
    Radia Management Agent (rma)Lnvdkit.exeRelated to Radia_Management Agent from Hewlett-Packard Development Co. Note Novadigm is now owned by HP. Note: Located in \%ROOT%\Novadigm\ManagementAgent\
    Radialpoint Service (FWS)Lfws.exeRelated to RadialPoint
    RadioSvrLRadioSvr.exeHP support for managing wireless devices
    raid (raid)Xraid.sysAdded by the Troj/NtRootK-O TROJAN! Read the link, rootkit type stealth involved.
    randomX(5 random letters and two numbers).sys Troj/RKAgen-Fam Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    RapAppLrapapp.exeBlack Ice Firewall related
    RasAt (Remote Connection)Xsvchost.exeAdded by the Troj/Singu-AF TROJAN!
    Rational ClearQuest Mail Service (MailService)Lmailservice.exeRelated to IBM_Rational_ClearQuest
    Rational Cred Manager (cccredmgr)Lcccredmgr.exeRelated to IBM_Rational_ClearCase
    Rational Lock Manager (LockMgr)Llockmgr.exeRelated to IBM_Rational_ClearCase
    Rational Test Agent Service (RationalTestAgentService)Lrtpsvc.exeRelated to IBM_Rational_Software Development Platform
    RaySat85 Server (RaySat85Server)Lraysat85server.exeRelated to mental_ray Standalone from Autodesk. A high-performance rendering engine for generating photorealistic images. Note: Located in \%Program Files%\Autodesk\mentalraysatellite8.5\bin\
    RaySatxsi4_2 Server (RaySatxsi4_2Server)Lraysatxsi4_2server.exeRelated to SOFTIMAGE_XSI server from Softimage. Advanced 3D animation software for games, film and television. Note: Located in \%ROOT%\Softimage\XSI_4.2\Application\bin\
    RaySat_3dsmax8 Server (mi-raysat_3dsmax8)Lraysat_3dsmax8server.exeRelated to Autodesk _3ds_Max
    RdnaoFlSvcLnaofsvc.exeRelated to Naomi an advanced internet filtering program.
    rdriv (rdriv)Xrdriv.sysAdded by the Troj/Rootkit-W TROJAN! Read the link, rootkit type stealth involved.
    ReaConverter scheduler service (rcp_service)Lrcp_scheduler.exeRelated to ReaConverter image editing features make the Lite edition a perfect choice for home users. Note: Located in \%Program Files%\ReaConverter 5.0 Pro\
    Realplus (Realplus)Xsserver.exeAdded by the Troj/Paltus-A TROJAN! Note: This trojan file is found in the System32 folder.
    Reflection Line Printer DaemonLlpdserv.exeRelated to http://www.wrq.com/
    Reflection ServersLrninetd.exeRelated to http://www.wrq.com/
    Reflection TimeSyncLrtsserv.exeRelated to WRQ, Inc. http://www.wrq.com/products/reflection/
    regdefendLregdefend.sysSee Ghostsecurity Location: C:\Program Files\RegDefend\regdefend.sys
    Regedits Helpers (Windows Regedits Help)Xiesetup.exe Troj/Hupigon-KX Note: Located in %windir%\help
    Regedits Helps (Windows Regedit Helps)Xiesetup.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\iis] (Win9x/Me), C:\%WINDIR%\System32\iis\ (XP/WinNT/2K) More here
    Register DLL DriverXregdll.exeAdded by the W32/Sdbot-CXB WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    Register ManagerXregent.exeAdded by the W32/Sdbot-DFJ WORM! Note: This worm is located in \%WINDIR%\ Read the link, allows remote access.
    Registration Host (reghost)Xreghost.exe Added by the W32/Rbot-GKS WORM! Note: This worm is located in C:\Program Files\Common Files\System\
    Registro de sucesos (Eventlog)Lservices.exeSpanish Windows 2000 event logger
    Registros y alertas de rendimiento (SysmonLog)Lsmlogsvc.exeSpanish Windows 2000 performance logs and alerts
    Registry Editor (Regedit)Xregedit.exeAdded by the W32/Codbot-U TROJAN! Note: This is not the regedit application that comes with Windows. (Which is located in the Windows folder) This trojan file is located in the System or System32 folder.
    Registry Management Service (RegManServ)LRegManServ.exeRelated to Complete_PC_Care from WinCleaner. Note: Located in C:\Program Files\Advanced Registry Doctor\
    Registry Manager Service (MS Registry Service)XMSRMS32.exeAdded by the W32/Rbot-AKP WORM!
    RegServiceLRegService.exeRelated to Intel Corp. http://www.intel.com/network/connectivity/trans/xircom.htm
    RegSrvcLRegSrvc.exeIntel PROset
    regstrmonXregstrmon.exeAddeD by the WORM_RBOT.ADA WORM! Note: This worm\trojan is located in C:\%WINDIR%\ folder.
    RelevantKnowledgeXrlservice.exeAdded by the Marketscore.RelevantKnowledge ADWARE! Note: Located in \%WINDIR%\System32\
    remon (remon)Xremon.sysAdded by the Troj/RKFu-A TROJAN! Read the link, rootkit type stealth involved.
    Remote Acces (WindowsDown)Xservet.exe Troj/Dloadr-AYT
    Remote Acces (WindowsFix)Xservet.exe W32/Sekap-A Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows remote access
    Remote Access Controller 4 (RAC) (racsvc)Lracsvc.exeRelated to Dell Open Manage NT Utilities program that allows remote access and control of a computer. This is a common program for hackers to install on a computer, so if it is installed, and you did not install it, it should be removed.
    Remote Account Manager (ramtsvc)Xrasmvc.exeAdded by an Unknown malware Note: Located in \%WINDIR%\System32\mui\
    Remote Administrator Service (r_server)Xsystemram.exeAdded by the Troj/Radnag-B Trojan!
    Remote Administrator Service (r_server)Xr_server.exeAdded by the Troj/Remadm-J TROJAN! Note: This trojan file is found in Program Files\real\RealOne Player\lang folder.
    Remote Administrator Service (r_server)Or_server.exeRelated to r_server.exe part of a remote administrator application that allows a user to work on one or more remote computers. The application contains features such as File Transfer, NT security and Telnet. Note: Located in \%WINDIR%\System32\ If you did not installed this server it is suggested that your remove it
    Remote Break ManagerXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Desktop Help Session Manager (RDSessMgr)Lsessmgr.exeRelated to Microsoft's remote assistance windows plugin. This allows an end user to call for assistance when a remote assistance network service is in place. This process shouldn't be terminated if the fore-mentioned service is in place on your local area network.
    Remote Displays ServiceXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Help Session Manager (Rasautol)Xntsokele.exe W32/Fujacks-AP Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Allows others to access the computer
    Remote HID Service (LvHidSvc)Olvhidsvc.exeRemote access service by Philips Inc. Legitimate, but remote access could be considered dangerous unless monitored carefully.
    Remote management (Novell WUser Agent)Lwuser32.exeRelated to Novel, Inc.
    Remote Map ManagerXlssc.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Media PlayerXlsscs.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Neon ServicesXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote NetBIOS ManagerXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote NTstat ServicesXsvshost.exeAdded A variant of the Backdoor.Sdbot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Packet Capture Protocol v.0 (experimental)
    (rpcapd)
    Lrpcapd.exeRelated to Winpcap (Windows Packet Capture Library)
    Remote Print Spooler (RPSGV)Xgcsvc.exeAdded by a variant of the Win32.SdBot.aad a TROJAN! identified by F-Secure. Note: This trojan is located in C:\%WINDIR%\
    Remote Procadure Call (RPC) (RpeSs) Xsvchost.exe Troj/Hupigo-UN Read the link, steals information Note: Located in %windir%
    Remote Procedure Call (RPC) Client (RpcClient)Xrpcclient.exeAdded by the W32/Codbot-L WORM!
    Remote Procedure Call (RPC) HelperXrandomCoolWebSearch malware
    Remote Procedure Call (RPC) Helper ( 6Q'8)Xipjp32.exeAdded by the Trojan.Win32.Agent.bi TROJAN! Note: located in \%WINDIR%\
    Remote Procedure Call (RPC) Locator (Locator)Xrpclocator.exeAdded by the W32/Codbot-Q WORM!
    Remote Procedure Call (RPC) Monitoring (Rpcmon)XRpcmon.exeAdded by the W32/Codbot-T WORM!
    Remote Procedure Call (RPC) Net (Rpcnet)LRpcnet.exeRelated to Laptop_Retriever
    Remote Procedure Call (RPC) Relocator (RpcRelocator)Xrelocater.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    Remote Procedure Call (RPC) Remote (RpcRemotes)Xremote.exeAdded by the W32/Mytob-EW WORM! or Troj/Agent-FB TROJAN! Note: This worm\trojan file is found in the System32 folder.
    Remote Procedure Call (RPC) Service (RpcSssvc)XRpcSs.exeAdded by the W32/Cuebot-J WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Note: The file RpcSs.exe is also a good Microsoft file. Before deleting check the propriatiry of the file.
    Remote Procedure Call (RPC) Subsystem (RPCS)Xrpcss.exe W32/Tilebot-JF Read the link, allows remote access
    Remote Procedure Call System (RPCS)XWin.exe Troj/Dropper-PT Note:Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Procedure Call System(RPCS) (RpcS)XRpcs.exeAdded by the Troj/QQRob-ABS TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Remote Procedure Call System(RPCS) (RpcSe)XRpcse.exeAdded by the Troj/Mdrop-BMK TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Procedure Call System(RPCSss) (RpcSss)XRpcSss.exeAdded by the Troj/QQRob-ACI TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Procedure Call System(RPCSU) (RpcSu)XRpcsu.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Remote Procedure Call System(RPCSx) (RpcSx)XRpcsx.exeAdded by a variant of the W32/SDBOT WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K)
    Remote Process KillerORKillSrv.exeThe Windows NT Resource Kits, both NT4 and Windows 2000 Professional, include a remote kill process commandline utility rkill.exe . To be able to kill a process or processes running on a remote server, you must have admin privileges and the rkillsrv.exe service must be installed and running. If this service was not installed by you or an LAN Admin. remove it. Note: Located in \%WINDIR%\System32\
    Remote Reader MachineXssmc.exeAdded by the Backdoor.SdBot.avk as detected by ewido. More here
    Remote Record Service (RemoteRecord)Lremoterecordclient.exeRelated to MSN_TV Note: Located in c:\program files\microsoft corporation\msn remote record service\
    Remote Republic ServicesXsvshost.exeAdded by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\
    Remote Run ServicesXsvshost.exeAdded by a varian of the Backdoor.Sdbot family of trojan. Note: Located in \%WINDIR%\System32\
    Remote Services Manager (RSMSS)X(Trojan file name)Added by the Troj/Bckdr-BBK TROJAN!
    Remote Solver for COSMOSFloWorks 2006LStandAloneSlv.exeRelated to COSMOS_FloWorks From COSMOS. CAD program. Note: Located in C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\
    Remote Storage (Rmtstrg)Xtaskmgr.exeAdded by the Troj/Spy-UN TOJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) Read the link, monitors websites visited and report them to a remote site
    Remote Storage (RS) (Rmtstrg2)Xtaskmgr.exeAdded by a varian the Troj/Spy-UN TOJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\drivers\ (XP/WinNT/2K) Read the link, monitors websites visited and report them to a remote site
    Remote Task Manager service (RTM)LRTMService.exeRelated to Remote_Task_Manager remote control suite. Note: Located in C:\Program Files\Remote Task Manager\
    Remote TCP ServicesXvcmon.exeAdded by the W32/Tilebot-HX WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) disabling the automatic startup of other software.
    Remote TCPI ServicesXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Terminal (RemoteTerminal)Xmscp.exeAdded by the Backdoor.Win32.SdBot.aad TROJAN! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    Remote Time PlugerXsvshost.exeAdded by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\
    Remote Transfer ManagerXsvshost.exe W32/Rbot-GQR Read the link, allows remote access
    Remote Windows ServicesXvcmon.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    RemoteControlService.exeLRemoteControlService.exeRelated to ITE_Remote_Control Service from ITE Tech. Inc. Note: Located in \%WINDIR%\System32\
    Remotely Possible/32 (RP32Service)Lrp32serv.exeRelated to Avalan now owned by Computer Associates International, Inc. http://ca.com/products/
    RemotelyAnywhereLRemotelyAnywhere.exeRelated to RemotelyAnywhere Made by 3am Labs Inc. This file should be found in the Program Files\RemotelyAnywhere folder.
    RemotelyAnywhere Maintenance Service (RAMaint)LRaMaint.exeRelated to RemotelyAnywhere Made by 3am Labs Inc. This file should be found in the Program Files\RemotelyAnywhere folder.
    RemoteRegBckXregsvc.exeAdded by Backdoor.Win32.SdBot.aad as identified by Kaspersky. TROJAN! Note: located in C:\WINDOWS\. Not to be confused with the Original Microsoft file in C:\WINDOWS\system32\
    Removale Sorage (RemovaleSorage)XG_Server.exeAdded by the Troj/Feutel-AT TROJAN! Note: This trojan file is found in the System32 folder.
    Required Service DriversXmicront.exeAdded by the W32/Rbot-ABD WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) terminate threads and processes read the information
    Reset 5Osrvany.exeUnknown owner: Location C:\Windows\System32\srvany.exe In this case srvany.exe is loading resetservice.exe as a service. May be found in the company of O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll Windows XP Product Activation Bypass So as to avoid the registration process on boot-up. Typically used on a pirated Operating System.
    Resource Manager Mail (ResourceManagerMail)LMailService.exeRelated to Citrix Systems, Inc.
    restore (restore)Xrestore.exeAdded by the SDBOT.CFD WORM! Read the link, rootkit type stealth involved.
    Retrospect ClientLRemotSvc.exeRelated to Dantz Development Corporation
    Retrospect Express HD Launcher (RetroExpLauncher)Lretrorun.exeRelated to Dantz Development Corporation
    Retrospect Express HD Restore Helper (RetroExp Helper)Lrthlpsvc.exeRelated to Dantz Development Corporation
    Retrospect HelperLrthlpsvc.exeRelated to Dantz Development Corporation
    Retrospect Launcher (RetroLauncher)Lretrorun.exeRelated to Dantz Development Corporation
    Retrospect WD Service (RetroWDSvc)Lwdsvc.exeRelated to Dantz Development Corporation
    Reuters XMS Sync (RXMSSync)Lrxmssync.exeRelated to Reuters_XMS_Sync routers. Note: Located in http://www.routers.com/
    RevUDFServiceLRevUDF.exeRelated to Iomega_Corp provider of a number of backup data solutions
    Rio MSC Manager (RioMSC)LRioMSC.exeRelated to Digital Networks North America.
    Rising Personal Firewall Service (RfwService)Lrfwsrv.exeRelated to Rising_Personal_Firewall, Rising Personal Firewall from Beijing Rising Tech., Corp. service. Note: Located in \%Program Files%\rising\rfw\
    Rll enhanced drive (mfm)Xmsrll.exeAdded by the Troj/Jtram-E TROJAN! Note: This trojan file is found in the System32\mfm folder.
    RoamMgrLRoamMgr.exeIntel PROset
    Rockwell Application Services (RsvcHost)LRsvcHost.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell Directory Multiplexer (RNADirMultiplexor)LRNADirMultiplexor.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell Directory Server (RNADirectory)LRnaDirServer.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell Event Multiplexer (EventClientMultiplexer)LEventClientMultiplexer.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell HMI Activity LoggerLRsActivityLogServ.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell HMI DiagnosticsLHMIDIAGNOSTICSLSTADAPT.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    Rockwell Tag ServerLTagSrv.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    rofl (rofl)Xrofl.sysAdded by the Troj/RKPort-Fam TROJAN! This is a rootkit!
    Roger Wilco Base StationLrwbs.exeRelated to IGN_Entertainment Inc. Required to operate the Wilco Base Station.
    Rogers Update Manager (RogersUpdateManager)LRogersUpdateManager.exeSearches for updates for the Rogers Yahoo!_Browser Note: Located in \%Program Files%\Rogers\Update Manager\
    RollbackClientServiceLRollbackClnt.exe Horizon DataSys Rollback Rx
    Routing Service (Routing)Xrouting.exeAdded by an unknown Trojan/Backdoor Note: Located in \%WINDIR%\System32\
    Roxio Hard Drive Watcher (RoxWatch)LRoxWatch.exeRelated to Roxio_Inc
    Roxio Hard Drive Watcher 10 (RoxWatch10)LRoxWatch10.exeRelated to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Common Files\Roxio Shared\10.0\SharedCOM\
    Roxio Hard Drive Watcher 9 (RoxWatch9)LRoxWatch9.exeRelated to Roxio_Inc
    Roxio UPnP Renderer 10LRoxioUPnPRenderer10.exeRelated to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Roxio\Digital Home 10\
    Roxio UPnP Renderer 9LRoxioUPnPRenderer9.exeRelated to Roxio_Inc
    Roxio Upnp Server 10LRoxioUpnpService10.exeRelated to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Roxio\Digital Home 10\
    Roxio Upnp Server 9LRoxioUpnpService9.exeRelated to Roxio_Inc
    RoxMediaDBLRoxMediaDB.exeRelated to Roxio_Inc
    RoxMediaDB10LRoxMediaDB10.exeRelated to Roxio_Inc Easy Media Creator 10. Note: Located in \%Program Files%\Common Files\Roxio Shared\10.0\SharedCOM\
    RoxMediaDB9LRoxMediaDB9.exeRelated to Roxio_Inc
    RoxUpnpRenderer (RoxUPnPRenderer)LRoxUpnpRenderer.exeRelated to Roxio_Inc
    RoxUpnpServerLRoxUpnpServer.exeRelated to Roxio_Inc
    RPAServiceLRPAService.exeRelated to Gilat Satellite Networks Ltd. Note: Located in \%Program Files%\GILAT\Internet Page Accelerator\
    RPC Debug Control (RPCDB)Xcsts.exeAdded by the Backdoor.Win32.SdBot.aad as identified by Kaspersky TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    RPC+ Service Provider (RPCSS+)Xrpcss_pl.exeTrojan. - http://www.what-process.com/process-info.aspx?p=rpcss_pl.exe
    RpcRemotesXremote.exeAdded by the W32/Fanbot-J WORM! Note: This worm file is found in the System32 folder. Be sure to check the link on this one. Copies it's self to various folders and file names.
    RSLinxLRSLINX.EXERelated to Rockwell_Automation Inc. FactoryTalk suite
    RSLinx Enterprise (RSLinxNG)LRSLinxNG.exeRelated to Rockwell_Automation Inc. FactoryTalk suite
    RtkitXRtkit.exeAdded by the Backdoor.Rtkit TROJAN! Read the link, rootkit type stealth involved.
    rtvscanXrtvscan.exeAdded by a variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans. Note: located in \%WINDIR%\ This infection should not be confused with the legitimate Note: Note: Located in \%Program Files%\Symantec\SAV\Rtvscan.exe file.
    rudllXrudll.exe Troj/Hupigon-CF Note: Located in %windir% Read the link, allows remote access
    RUMBA AS/400 Shared Folders (Wdworkstation)Lwdnpsvc.exeRelated to RUMBA which provides connectivity from Microsoft Windows desktops to virtually any host system with mission critical reliability. From NetManage Inc. Note: Located in \%WINDIR%\System32\
    Run RunOnceLShipUPS.EXE, RunOnce.exeRelated to UPS WorldShip shipping software
    rundll.exeXmsn93.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    rundll.exeXmsngrsm.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    rundll.exeXrundll.exeAdded by an unknown variant of a backdoor TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\
    rundll32 (rundll32)Xrundll32.exeAdded by the Troj/Feutel-Q TROJAN!
    rundll32.exeXlsass.exeAdded by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\
    RuntimeXruntime.sys Troj/Agent-ECZ Note: Located in %windir%\system32
    RuntimeXruntime.sys Troj/Pushu-Gen Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K) May also have an additional services installed. Read link
    runtime2Xruntim2.sys Troj/DropRk-A Note:Located in C:\Windows\System\Drivers (Win9x/Me), C:\%WINDIR%\System32\Drivers (XP/WinNT/2K)
    RupsdLRupsd.exeRelated to Mega_System Technologies Inc.
    RupsmonLRupsMon.exeRelated to Mega System Technologies, Inc.
    RVS CommCenter (RvsCC)LRVSCC.EXELegit Fax/Digital Answering Machine/Telephony service. Owner Unknown . Located in C:\Program Files\Teledat\WCOM\SYSTEM\
    RVS Installer (RVSINST)LRVSINST.EXELegit Fax/Digital Answering Machine/Telephony service. Owner: RVS Datentechnik GmbH, Mnchen. Located in: C:\Program Files\Teledat\WCOM\SYSTEM\
    Rwx (Rwx2005)Xsvhosts.exeAdded by the Troj/Subzero-B Trojan!
    r_serverXservice.exeAdded by the Troj/Remadm-G TROJAN! Note: This is not the legitimate Windows process services.exe (Notice the difference in the spelling.) This trojan file (service.exe) is also found in the System32 folder.

    Engine Version 2.0 by CastleCops

    spacer spacer