| Name | Status | Filename | Description |
|---|
| Registry Integritycheck | X | WCPDT.EXE | Added by the W32/AGOBOT-RF WORM! |
| RegistryMonitor | X | sysfade.exe | Added by Trojan.Sysfade Note: located in \%WINDIR%\ |
| Regptmens | X | REGPTMENS.EXE | Added by the Troj/Bancos-ED TROJAN! Read the link, keylogger/password stealing trojan(s) involved. |
| RCSync | X | RCSync.exe | PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware |
| rmoc3260.dll OCX | U | rmoc3260.dll | rmoc3260.dll A module that contains COM components for media playback used by both RealPlayer and Windows Media Player. Note: Located in \%WINDIR%\System32\ |
| ryan1918 | X | servidevice.exe | Added by the W32/Checkout!0e4a3c52 mass-mailing worm. Note: located in \%WINDIR%\ |
| runwin32 | X | runwin32.exe | Troj/ESearch-A trojan |
| Ray Process Killer | N | Prkill.exe | Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL ALT DEL instead |
| Regkey for autostart | X | winservice.exe | Added by the W32/RBOT-NU WORM! |
| Runmarc8mManager | U | marc8m95.exe | MARC Sound System Manager for the Marc_8_MIDI sound card - allows for easy adjustment of the settings |
| Remote Storage Access | X | rmasvc.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| RavTimer | X | explores.exe | Added by the Troj/Homey-A
TROJAN!
Note: This is not the legitimate Windows process explorer.exe (Notice the difference in the spelling.) This trojan file (explores.exe) is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| RemStart | ? | remstart.exe | Part of McAfee\'s Remote Desktop 32 Agent application. What does it do and is it required? |
| Realtek Sound Manager | X | Tecompntwx.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| regsrv | X | regsrv.exe | Added by the OPTIXPRO.11 VIRUS! |
| RealAudio | X | RealAudio.exe | Added by the CEEGAR TROJAN! |
| RA Server | X | Slave.exe | Added by the RA VIRUS! |
| Remote Access Adapter | X | rvasvc.exe | Added by a variant of the Backdoor.Win32.IRCBot.alo family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Recommended Hotfix - {0421701D-CF13-4E70-ADF0 | X | RH.DLL | SmartPops adware |
| RxMon | N | rxmon9x.exe | Dell Resolution Assistant |
| retime | X | retime.exe | Added by the GIPMA VIRUS! |
| Rundll32 P17 | ? | Rundll32,P17.dll, P17Helper | ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
|
| run | X | dec25.exe | Added by the W32.ATAK.F WORM! |
| rundl332 | X | math.exe,...pluged.exe | Added by the DOOMJUICE VIRUS! |
| Router | X | Router.exe | Identified as a variant of the Trojan.Matcash MALWARE! Note: Located in \%Program Files%\Router\ |
| restory | X | restory.exe | Added by the RETSAM VIRUS! |
| RavTimeXP | X | (worm filename) | Added by the WULLIK.B VIRUS! |
| Rnudll32 | X | tadxtr.exe | Added by the TROJ/QQPASS-O TROJAN! |
| RealSPEED | U | RealSPEED.Exe | Related to Stay_Alive Stay connected even after a period of inactiviry on the net. |
| Remote Procedure Calls | X | mswinc.exe | Added by the W32/RBOT-IT WORM! |
| Reminder-hpcXXXXX | N | remind32.exe | HP CD-Writer Registration |
| Reminder-cpqXXXXX | N | remind32.exe | Compaq printer Registration |
| Real-Tens | X | Real-Tens.exe | DownloadWare Adware. |
| Rundll32_7 | X | rundll32.exe,MSIEFR40.DLL, DllRunServer | BrowserAid/BrowserPal Foistware |
| REGIST~1 | U | REGIST~1.EXE | Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
| RandomWin32 | X | mgnwin32.exe | Added by the W32/SDBOT-DV WORM! |
| reseurce | X | (Path to,Trojan) | Added by the Troj/Lineage-AI
TROJAN!
|
| rfagent | U | rfagent.exe | Registry_First_Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders |
| Restore Operation | X | svchots.exe | Added by a variant of the Trojan-Downloader.Win32.Small.ddx family of TROJAN! Note This trojan is located in C:\%WINDIR%\TEMP\ folder. |
| Reminder | N | reminder.exe | From MS Money. Reminds you of your bills |
| Reg Service | X | REGSRV32.EXE | Added by the RBOT.ZW WORM! |
| runner1 | X | updater.exe | Detected by Antivir as TR/Crypt.ULPM.Gen |
| RAID Event Monitor | U | iaanotif.exe | IAA Event Monitor User Notification Tool - part of Intel® Application Accelerator - "a performance software package for desktop PCs using select Intel® chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
|
| rundll64 | X | (path to worm) | Added by the AUTEX VIRUS! |
| run= | X | winlogon.exe | CoolWebSearch parasite variant - Note - this is NOT the legitimate Windows winlogon.exe process! |
| Registry oidet | X | win32.exe | Added by the RBOT.BMT WORM! |
| regedit | X | svchost.exe,ccRegVfy | Added by the Trojan.Rona
Trojan!
|
| Reg Service | X | winslogon.exe | Added by the W32/AGOBOT-SC
or W32/Agobot-SY
WORM!
|
| Register SeqChk | ? | regsvr32.exe,..csseqchk.dll | ? |
| rtos | X | rtos.exe | IRC trojan |
| RecoverFromReboot | ? | RECOVE~1.EXE | Unknown |
| Rundll32 | X | RUNDDLL32.EXE | Added by a downloader TROJAN! - detected by Panda antivirus as Adware/StartPage.AXH |
| Registry Startup Check | X | checkreg.exe | Added by the Troj/RemLoad-A or Troj/Danmec-B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| RSRCMTZ | ? | RSRCMTZ.exe | ?? |
| ResumeFixClocks | U | resumefix.exe | Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards |