| Name | Status | Filename | Description |
|---|
| RealTray | N | RealPlay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
| run= | X | Autoexec.com | Added by the HOLCAS.A WORM! |
| RandomWin32 | X | mgnwin32.exe | Added by the W32/SDBOT-DV WORM! |
| rtasks | X | rtasks.exe | WinAntiVirus_Pro_2007 - fake "security software"- also see here Note: Located in C:\Program Files\WinAntiVirus Pro 2007\ see here |
| Referee | U | referee.exe | MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run |
| RecoverFromReboo | ? | RecoverFromReboot.exe | Unknown |
| regservices.exe | X | regservices.exe | Added by a W32/Rbot-MN worm infection |
| RegistryMonitor | X | sysfade.exe | Added by Trojan.Sysfade Note: located in \%WINDIR%\ |
| RfwMain | Y | rfwmain.exe | Rising antivirus |
| RegVfy32 | X | Regverif32.exe | Added by the W32.Sygyp.A
WORM!
Note: Drops multiple files, read the link.
|
| RegistryCleanFixMFC | X | registrycleanfix.exe | Added by RegistryCleanFix ROGUE! program. Once the scan is completed, it reports false or exaggerated system errors on the computer. Note: Located in \%Program Files%\RegistryCleanFix\ |
| Rase | X | boln.exe | PurityScan/Clickspring Adware |
| regsrvc | X | regsrvc.exe | Added by the TROJ/STOPED-A TROJAN! |
| Remote Update Monitor | Y | imonitor.exe | Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer. |
| Run Services as Application | X | spoolsvc.exe | Added by the Troj/Dloader-NY
TROJAN!
Note: Spoolsvc.exe is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (spoolsv.exe) is located in the System32 folder. |
| Reg Service | X | ipcfg.exe | Added by the W32/Agobot-SO
Worm!
|
| run= | X | svhost.exe | Added by the ADMINCASH.B TROJAN! |
| run= | X | RegistryReminder.exe | Added by the APSTROJAN.OB TROJAN! |
| RealDownload Express | X | npnzdad.exe | Advertising spyware |
| RepliGo Assistant | U | RepliGoMon.exe | Cerience RepliGo software - "any document you have on your PC can be transferred to your mobile device" |
| RegSvr32 | X | msmsgs.exe | Added by the Trojan.Zlob.B
or Troj/Zlob-M
TROJAN!
|
| Regcheck | X | ~CAB001.EXE | Added by the CYBERSPY VIRUS! |
| run= | X | mdm.exe | Added by the TROJ/PROXY-GG TROJAN! |
| Rnudll32 | X | tadxtr.exe | Added by the TROJ/QQPASS-O TROJAN! |
| rdvs | X | (worm filename) | Added by the ULTIMAX VIRUS! <filename.exe> is the worm filename created |
| Reg Service | X | REGSRV32.EXE | Added by the RBOT.ZW WORM! |
| RunNarrator | U | Narrator.exe | Related to Narrator_accessibility feature on Windows XP. It is used to convert text to speech. Should not be disabled, required for essential applications to work properly. Note: Located in C:\%WINDIR%\System32\ |
| run= | X | ptlseq.cpl | PhoenixNet BIOS adware. See here |
| run | X | Autoexec.com | Added by the HOLCAS.A WORM!
|
| run= | N | pcfix2k.exe | pcfix2k splash screen |
| Reminder | N | reminder.exe | From MS Money. Reminds you of your bills |
| RPC | X | MSschost.exe | Added by a variant of the GAOBOT/AGOBOT WORM! |
| RoxioDragToDisc | N | DrgToDsc.exe | Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly |
| rsrvmon.exe | X | rsrvmon.exe | Identyfied as a variant of the Trojan-Clicker.Win32.Agent Note: Located in \%WINDIR%\System32\drivers\ Note: Use SDFix under supervision. |
| RadioSvr | U | RadioSvr.EXE | Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network |
| run= | U | ramsys.exe | Advanced Startup Manager from Rays Lab |
| Rupsw32 | U | Rupsw32.exe | MegaTec Rups, UPS monitoring software - monitor and control DB9 UPS running on either Windows & Novell NetWare (with RUPS 2000) or Unix (with RUPS for Unix / Plus) operating systems. |
| Reg Service | X | winslogon.exe | Added by the W32/AGOBOT-SC
or W32/Agobot-SY
WORM!
|
| RegMutex | X | lexplore_.exe | Added by the Troj/MSNOpt-A
TROJAN!
Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| Regrx | X | rundll32.exe | Added by the TROJ/WAYIC-A TROJAN! - NOTE: this file is found in the C:\Windows folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!
|
| rIOphosIs | X | rIOPHosIs.vBS | Added by the RIOSYS VIRUS! |
| Remote Services Manager | X | msrmsvc.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| run= | X | mouse_configurator.win | Added by the VBS.GAGGLE.E WORM! |
| ravshell | X | expl0rer.exe | Troj/Nofere-E |
| RPC Drivers | X | rpcall.exe | Added by a variant of the W32/IRCbot.BGA.worm family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\inetsrv\ |
| RecShe | N | RecSche.exe | Recording scheduler for WatchTV Capture Card (TV Tuner card) |
| R | X | [path],rundll32.exe,msprt.dll | Browser hijacker of Chinese origin, redirecting to 4199.com |
| RunOnce | U | RUNONCE.EXE | Part of MS Data Access Components - only required if you use these |
| Reminder-ranXXXXX | N | remind32.exe | Registration reminder widget for Rand Mcnally maps |
| rant | X | rant.exe | Added by the W32/RBOT-ZB WORM! |
| Recycler DO NOT MODIFY | X | recyclecl.exe | Added by the WORM_RBOT.DDA WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) Read the link, allows remote access |
| run= | X | Celine.scr | Added by the TROJ/CELINE-A TROJAN! |
| RemindMe | U | RemindMe.exe | Remind-Me - calendar software |
| run= | ? | LXBTppls.exe | Reportedly part of Lexmark printer software - what does it do and is it required? |
| RebateNation0 | X | RebateNation0.exe | WebRebates adware variant |