| Name | Status | Filename | Description |
|---|
| razertra | Y | razertra.exe | razer diamondback mouse driver |
| Run XP Service Pack | X | xpservicepack.exe | Added by a Sdbot.AQA worm infection |
| Run TaskMrg | X | csrss.exe | Added by the TROJ/LDPINCH-W TROJAN! |
| roketpipe | ? | rpclient.exe | ?? |
| ravtask | X | svch0st.exe | Added by the LINEAG-AIN TROJAN!
|
| RegistryMonitor | X | sysfade.exe | Added by Trojan.Sysfade Note: located in \%WINDIR%\ |
| Registry System | X | Regsys.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| Receiver | U | PcfaxRcv.exe | Related to PC_to_Fax driver from Sharp Electronics Corp. Note: Located in \%Program Files%\SHARP\PCFAX2.0\ |
| requester | X | requester.12.exe | Added by the Trojan.Requester.Process Trojan |
| rundll32 | X | rundll32.exe | Added by the Troj/Agent-EZ keylogging TROJAN! Note: This trojan file is found in the System\SHELLEXT (95/98/ME) or System32\SHELLEXT (NT/2000/XP) folder. Do not confuse this with the real rundll32.exe which resides in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| RaConfig2500 | N | RaConfig2500.exe | Related to RaLink_Config_Utility It is used to configure the RaLink Wireless LAN cards. This is a non-essential program. *Disabling or enabling it is down to your preference. Note: located in C:\WINDOWS\system32\ |
| run32 | X | run32dll.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) More here |
| rollbk | X | msmpatch.exe | Added by the W32.Serflog.B WORM |
| Reactor6 | X | [random,name]32.exe | Added by the W32.Mydoom.AK WORM!
|
| Real Statics Agent | X | ccreal.exe | Added by a variant of the WIN32.RBOT WORM!
|
| Retrospect WD Service | U | WDSVC.EXE | Related to Retrospect_WD_Service Dantz Retrospect backup application. Note: Located in C:\PROGRAM FILES\DANTZ\RETROSPECT\ |
| RPCserv32g | X | NB32EXT2.EXE | Added by the BOBAX.AD WORM! |
| Rnudll32 | X | tadxtr.exe | Added by the TROJ/QQPASS-O TROJAN! |
| RegDone | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process |
| Registry Serv | X | regsvr.exe | Added by the WEBMONEY-G TROJAN! Note: Located in \%WINDIR%\System32\ |
| RtlMon.exe | N | RtlMon.exe | Monitor for RealTek network card |
| REGMSYS | X | (Path of,Executable) | Added by the Troj/LowZone-AX TROJAN! |
| RAX SYSTEM | X | scrigz.exe | Added by the MYTOB.KR WORM! |
| Root_Machine | X | (Pathname of,the Trojan exe) | Added by the Troj/Bancban-DI
TROJAN!
|
| Realsched | N | realsched.exe | Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry |
| rbenh ml***e | X | rbenh.exe | RapidBlaster Variant |
| Regscan | X | regscanr.exe | Added by the TROJ/OPTIX-SE TROJAN! |
| Run Services as Application | X | localsvc.exe | Added by the Troj/Dloader-NY
Trojan!
|
| RoxAssist | N | RoxAssist.exe | Roxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder.
After running this program you should receive the message "Engine initialized successfully with full recorder support".
If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use "Add Remove Programs" in "Control Panel".) .Can be run manually
|
| rundll64 | X | (path to worm) | Added by the AUTEX VIRUS! |
| Registry Startup Check | X | checkreg.exe | Added by the Troj/RemLoad-A or Troj/Danmec-B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| Rapdatae | X | rabseuser.exe | Added by the TROJ/QQPASS-S TROJAN! |
| run= | X | msxmidi.exe | CoolWebSearch parasite variant -recognized by Kaspersky antivirus as TrojanDropper.Win32.Small.cw
|
| rreg | X | rreg.exe | Unidentified adware |
| Run POPFile in background | U | perl.exewperl.exe | POPFile - E-mail spam blocker |
| Rapdata | X | ravsecs.exe | Added by the Troj/QQPass-V
TROJAN!
|
| Realaudio Player | X | realaudio32.exe | Added by the Worm.AGOBOT-VA.Process WORM! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| RUSBHOLoader | ? | rundll32.exe,RUSBHOLoader.dll, AutoRegister | ?? |
| reg32 | X | reg32.exe | Added by the NOUPDATE.B VIRUS! |
| RPCserv32g | X | services.exe | Added by the W32.BOBAX.AA WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
|
| RegRun | X | mActiveX.exe | Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN! |
| RegCompres | X | REGCPM32.EXE | Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return |
| Rapdatybs | X | ravseteyns.exe | Troj/PWS-ACP Read the link, steals information |
| runapp | X | icqchk.exe | Added by the Bomka
TROJAN!
|
| Registry Scanner | X | regscanr.exe | Added by the OPTIX LITE FIREWALL BYPASS VIRUS! |
| RegistryCleanFixMFC | X | registrycleanfix.exe | Added by RegistryCleanFix ROGUE! program. Once the scan is completed, it reports false or exaggerated system errors on the computer. Note: Located in \%Program Files%\RegistryCleanFix\ |
| RavMon | Y | RavMon.exe | RAV AntiVirus |
| run= | X | services.exe | Krepper-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup! |
| RAID Event Monitor | U | iaanotif.exe | IAA Event Monitor User Notification Tool - part of Intel® Application Accelerator - "a performance software package for desktop PCs using select Intel® chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
|
| RecoverFromReboot | ? | RecoverFromReboot.exe | Unknown |
| RAMDef | U | ramdef.exe | Ram Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind |
| RegRun WinBait | U | winbait.exe | Part of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different.. |
| RegHelp | U | svchosts.exe | SpyGraphica spy software - "Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."
|
| run= | X | DRDOOM.EXE | Added by the W32/SEMAPI-A WORM |
| Run Google Web Accelerator | U | GoogleWebAccWarden.exe | Related to Web_Accelerator from Google. Note: Located in \%Program Files%\Google\Web Accelerator\ |