| Name | Status | Filename | Description |
|---|
| Rundll32.exe | X | Proyecto1.exeRoot.exe | Added by the GRUEL VIRUS! |
| Rnudll32 | X | tadxtr.exe | Added by the TROJ/QQPASS-O TROJAN! |
| run= | N | cmmpu.exe | MIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI) |
| REGRUN | X | dialer.exe | Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN! |
| RunDll32 essprops | Y | RunDll32,essprops.cpl,,TaskbarIconWnd | Associated with a Logitech mouse - required for proper operation
|
| Regrx | X | rundll32.exe | Added by the TROJ/WAYIC-A TROJAN! - NOTE: this file is found in the C:\Windows folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!
|
| Rundll32_8 | X | rundll32.exe,inetp60.dll, DllRunServer | BrowserAid/BrowserPal Foistware |
| Regexit | X | runlli32.exe | Added by the Troj/QQPass-U
TROJAN!
Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. |
| RK Launcher | U | RKLauncher.exe | Related to RK_Launcher by RaduKing. Application that will allow the user to have a visually pleasing bar at the side of the screen that is used to quickly launch shortcuts. Note: Located in \%Program Files%\RK_Launcher_04_Beta\ |
| reg2.0 | U | SVCH0ST.EXE | Added by the eSpyNow
surveillance software. Uninstall this software unless you put it there yourself.
Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
|
| Ray Process Killer | N | Prkill.exe | Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL ALT DEL instead |
| RFX_auto_upgrade | N | rundll32.exe,npvpg005.dll | A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade |
| real scheduler | X | real,scheduler.hta | Added by the CEEGAR TROJAN! |
| ReproPRD | U | PrdUsb.exe | Thrustmaster Corporation Presets application - a game controller driver, presumably necessary for certain functions to work |
| RavTimer | Y | RavTimer.exe | RAV AntiVirus |
| RPCserv32g | X | SMSS.EXE | Added by the BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows smss.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup! |
| Regmonitor | X | regmaping.exe | Added by the W32.Beagle.DO
WORM!
Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Drops multiple files in multiple folders. |
| Reload | X | reload.exe,/reloadenterpice | Added by the Lazar TROJAN! |
| Reminder-ranXXXXX | N | remind32.exe | Registration reminder widget for Rand Mcnally maps |
| RegVfy32 | X | Regverif32.exe | Added by the W32.Sygyp.A
WORM!
Note: Drops multiple files, read the link.
|
| rdvs | X | (worm filename) | Added by the ULTIMAX VIRUS! <filename.exe> is the worm filename created |
| RealJukeboxSystray | N | tsystray.exe | System Tray icon for RealJukebox |
| RAMDrive | U | RDTask.exe | Virtual Hard Drive (Ram Drive) takes a portion of your system memory (RAM) and uses it to simulate a hard disk drive. For more information see FarStone
|
| Reek 32 Server | X | reek32.exe | Added by the RANDEX.AL WORM! |
| REGEDIT | X | Regsrv32.com | Added by the SOUTHGHOST VIRUS! |
| runing | X | win.exe | Added by the Troj/Delf-LC
TROJAN!
|
| Remote Access Adapter | X | rvasvc.exe | Added by a variant of the Backdoor.Win32.IRCBot.alo family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| rreg | X | rreg.exe | Unidentified adware |
| rCron | X | rcron.exe | "Switch" adult content dialer |
| Remote Procedure Calls | X | mswinrpc.exe | Added by a RBOT.KJ worm infection |
| Ring Central Fax | U | rcenterrll.exe | Only needed if you want a PC to answer faxes automatically |
| RoxWatchTray | U | RoxWatchTray.exe | Related to Roxio_easy_CD_creater System Tray icon installed by Roxio Easy Media Creator 8 and which allows you to configure your watched folders or to turn the Watched Folders feature of Roxio ON or OFF. Note: located in C:\Program Files\Common Files\Roxio Shared\... |
| run= | X | iexpIore.exe | Added by the OBLIVION-B TROJAN! |
| rmmon | N | mprmmon.exe | Resource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card |
| romahere2 | X | ************.exe,(* = random,char) | SuperSpider hijacker - a CoolWebSearch parasite variant |
| Reclip | N | reclip.exe | Reclip Popup Clipboard manager |
| RPCser32g | X | services.exe | Added by the W32/Ritdoor-F
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder. |
| Run MSupdt32 | X | wscript,MSupdt32.vbs | Added by the CASER VIRUS! |
| Recommended Hotfix - {0421701D-CF13-4E70-ADF0 | X | RH.DLL | SmartPops adware |
| run= | Y | wswpd.exe | Used with some models of Panasonic, Epson and NEC printers - required for printer to work. |
| RCSync | X | RCSync.exe | PrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware |
| Recycler DO NOT MODIFY | X | recyclecl.exe | Added by the WORM_RBOT.DDA WORM! Note: This worm\trojan is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) Read the link, allows remote access |
| Rapid Restore | U | rrpcsb.exe | XPoint "Rapid Restore PC"; a "Managed Recovery™ solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user." |
| RetroExpress | U | RetroExpress.exe | Related to Dantz_Retrospect_Express which allows you to back up and encrypt your confidential files to various media. Note: Located in C:\Program Files\Dantz\RETROS~1\ |
| Reactor9 | X | [random,name]32.exe | Added by the W32.BOFRA.E WORM! |
| Raymond present | X | friska_w32.exe | Added by the W32/Rubble-C Worm |
| Recguard | Y | recguard.exe | On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense |
| RecShe | N | RecSche.exe | Recording scheduler for WatchTV Capture Card (TV Tuner card) |
| Registry Monitor | X | regmon.exe | Added by the Troj/Bckdr-QKH TROJAN Note: Located in \%WINDIR%\System32\drivers\ |
| Rundll32 cmicnfg | N | Rundll32,cmicnfg.cpl, CMICtrlWnd | System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel |
| Rundll32 | X | Rundll32.exe | Added by the DVLDR VIRUS! Note - this is not the valid "Rundll32.exe" as it\'s in the Windows\Fonts directory |
| RealPlayer | U | realplay.exe | Related to RealPlayer which allows the playing of various video files such as MPEG and AVI. Note: Located in \%Program Files%\Real\RealPlayer\ |
| RDLL | X | RunDll16.exe | Added by the SDBOT.F WORM! |
| rtasks | X | rtasks.exe | AntivirusPCSuite - rogue "security software" using false positives as a goad to purchase. A member of the SmitFraud malware family
|
| run= | Y | asistat.exe | Used with some models of Panasonic, Epson and NEC printers - required for printer to work. |