| Name | Status | Filename | Description |
|---|
| RemindMe | U | RemindMe.exe | Remind-Me - calendar software |
| Remote Access Adapter | X | rvasvc.exe | Added by a variant of the Backdoor.Win32.IRCBot.alo family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Rundil32 | X | Updadv.exe | Added by the Troj/QQPass-N
TROJAN!
|
| run= | ? | wallflip.exe | Desktop wallpaper changer? |
| rundll32 | X | rundll32.exe | Added by the SANKER VIRUS! Note that the valid "rundll32.exe" resides in C:\Windows\System32 wheras this version resides in C:\Windows |
| Remote Procedure Calls | X | mswinc.exe | Added by the W32/RBOT-IT WORM! |
| Restart_VS | ? | Viewsonic.exe | Could be a left-over from the installation of a Viewsonic flat panel display |
| Realsched | N | realsched.exe | Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry |
| Rundll | X | Rundll~.exe | Added by the W32/DELF-KT TROJAN!
|
| restory | X | restory.exe | Added by the RETSAM VIRUS! |
| RunOnce | U | RUNONCE.EXE | Part of MS Data Access Components - only required if you use these |
| rundll32 | X | MSDTC.exe | Added by the W32/Stap-E Worm |
| Remote | U | Remote.exe | Related to LifeView_FlyVideo_TVR
Note: Located under C:\Program Files\LifeView TVR |
| RapidBlaster | X | rb32.exe | Homepage hijacker (adult content) - see this newsgroup thread |
| RunDll | X | RunDll.exe | Added by Troj/QQPass-AH TROJAN! |
| regsrvc | X | regsrvc.exe | Added by the TROJ/STOPED-A TROJAN! |
| RUNLOUD | X | loud.exe | Adware related downloader, detected as TrojanDropper.Win32.PurityScan.g |
| Reminder | N | Remind_XP.exe | Subscription reminder to unlock unkimited use for SoftThinks CD Creator CD/DVD rewriting software, usually supplied with HP PC's as a pre-installed package |
| regsvr | X | regsvr.exe | Added by the WEBMONEY-G TROJAN! |
| run= | U | ramsys.exe | Advanced Startup Manager from Rays Lab |
| Run[0] | X | syscnfg.exe | Added as the result of an unidentified VIRUS!. "syscnfg.exe" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside |
| RRMedic | X | rrmedic.exe | Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection |
| RSRCMTZ | ? | RSRCMTZ.exe | ?? |
| RDLL | X | RunDll16.exe | Added by the SDBOT.F WORM! |
| RjLyraInstaller | ? | setup.exe | ?? |
| RSPC Driver D | X | (random,filename) | Added by a variant of the WIN32.RBOT WORM!
|
| run | X | luapvs.dll | Identified as Trojan:Win32/Emurbo.A Note: Located in \%WINDIR%\System32\ or %AppData%\sp1\ Note: Use SDFix under supervision. |
| runing | X | win.exe | Added by the Troj/Delf-LC
TROJAN!
|
| Remote Services Manager | X | msrmsvc.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| RealJukeboxSystray | N | tsystray.exe | System Tray icon for RealJukebox |
| rsrvmon.exe | X | rsrvmon.exe | Identyfied as a variant of the Trojan-Clicker.Win32.Agent Note: Located in \%WINDIR%\System32\drivers\ Note: Use SDFix under supervision. |
| RegDone | X | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process |
| Regcxn | X | Regcxn.exe | Added by the COIBOA-D TROJAN! |
| Recycle Bin Handler | X | recycler.exe | Added by the TROJ/SHUCKBOT-A TROJAN! |
| RegistryChk | X | winbackup.exe | Added by the MERTIAN VIRUS! |
| RPCSS.exe | Y | rpcss.exe | Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here |
| RexSyMon | N | rexsymon.exe | Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC |
| REGRUN | X | (pathname of,the Trojan,executable) | Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN! |
| RSPC Driver | X | (random,filename) | Added by the W32/RBOT-SN WORM! |
| RunCA | Y | InvokeSvc3.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required |
| Remote Control | N | Rc.exe | Hinet Hi-Five ISP software |
| Reg | X | Reg.hta | Homepage hi-jacker. Removal instructions here |
| Regrx | X | rundll32.exe | Added by the TROJ/WAYIC-A TROJAN! - NOTE: this file is found in the C:\Windows folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!
|
| Restore Operation | X | svchots.exe | Added by a variant of the Trojan-Downloader.Win32.Small.ddx family of TROJAN! Note This trojan is located in C:\%WINDIR%\TEMP\ folder. |
| rn4d | X | dirote.exe | Added by the BKDR_MAROON.A TROJAN! |
| run= | X | msxmidi.exe | CoolWebSearch parasite variant -recognized by Kaspersky antivirus as TrojanDropper.Win32.Small.cw
|
| run= | N | fmedia.exe | FMedia FaxWorks related - can be run manually |
| RunAlert | U | AService.exe | MSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you "overclock" your system |
| runwin32 | X | runwin32.exe | Troj/ESearch-A trojan |
| rollbk | X | sysup.exe | Added by the W32.Serflog.B WORM |
| RegCompres | X | REGCPM32.EXE | Adult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return |
| rundl332 | X | math.exe,...pluged.exe | Added by the DOOMJUICE VIRUS! |
| Registry Loader | X | regloadr.exe | Added by the GAOBOT.AO WORM! |
| RP32 | U | rp32.exe | ControlIT (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems. |
| Rundll32.exe | X | Proyecto1.exeRoot.exe | Added by the GRUEL VIRUS! |