| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 29th Apr, 2013
31819 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
1664 results found for R
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| update | X | r00t.exe | Added by the RBOT-ACO WORM! | No |
| MSFTP Service Config | X | r3grun.exe | Detected by Trend Micro as WORM_RBOT.CVI | No |
| Fellowes Proxy | U | R3proxy.exe | Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice | No |
| [random name] | X | r?gedit.exe | PurityScan adware | No |
| [random name] | X | r?gsvr32.exe | PurityScan adware | No |
| [random name] | X | r?ndll.exe | PurityScan adware | No |
| [random name] | X | r?ndll32.exe | PurityScan adware | No |
| f~a | X | ra32.exe | Added by the CAY BACKDOOR! | No |
| WebExRemoteAccessAgent | U | raagtapp.exe | Related to Web Meetings from WebEx Communications, Inc. Share and present online with anyone, anywhere | No |
| RabbitWannaHome | X | rabbit.exe | Added by the MIMAIL.S WORM! | No |
| Rabo Session Monitor | Y | RaboSessionMon.exe | Related to RaboBank electronic banking software | No |
| Rapdatae | X | rabseuser.exe | Added by the QQPASS-S TROJAN! | No |
| Racl | X | RaclSvc.exe | Detected by McAfee as Generic.tfr and by Malwarebytes Anti-Malware as Adware.K.RightClick | No |
| RaConfig2500 | N | RaConfig2500.exe | RaLink wireless LAN configuration utility | No |
| RadarSync | N | RadarSync.exe | Radarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically | No |
| RadBoot | U | RadBoot.exe | RadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings | No |
| RadialpointServicepoint.exe | Y | RadialpointServicepoint.exe | Servicepoint tool installed when you install internet security suitea sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | No |
| Radio online | U | radio online.exe | Radio Online by Nend Software - "is very nice Radio/TV/MP3/WMA player with many options. Everything works with an icon in your systray (right bottom icon next to your clock)" | No |
| Radio365Agent | U | Radio365TrayAgent.exe | Radio365 - create playlists and broadcast live straight from your PC! | No |
| RadioSvr | U | RadioSvr.EXE | Used to configure wire less networks. Windows automatically detects the Wireless network and it configures the network | No |
| Microsoft | X | radnom.exe | Added by the RBOT-GHO WORM! | No |
| Windows Update | X | rage.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Eragbot. The file is located in %CommonFiles%\System | No |
| OrigRage128Tweaker | U | RAGE128TWEAK.EXE | Third party tweaker for ATI Rage 128 Video cards from http://www.rageunderground.com | No |
| RagesCamera | X | Ragesn.exe | Added by the SDBOT.AHJ WORM! | No |
| Desktop Authority GUI | U | ragui.exe | Desktop Authority by Quest Software (was ScriptLogic) - remote access and management software which allows you to "proactively target, secure, manage and support desktops from a central location" | No |
| LogMeIn GUI | U | ragui.exe | LogMeIn remote access and management software which allows you to connect to a computer or device at any time, from anywhere there is an Internet connection and configure, monitor, diagnose and support multiple remote computers | No |
| RemotelyAnywhere GUI | U | ragui.exe | RemotelyAnywhere by LogMeIn, Inc - "Experience fast, secure system administration from anywhere. RemotelyAnywhere offers industry-leading security and performance for remote administration" | No |
| System RAID Manager | X | raid64.exe | Added by the AGENT-NNZ TROJAN! | No |
| RaidCall | N | raidcall.exe | "RaidCall is a free, elegant and simple tool that allows you to instantly communicate with groups of people. It brings together elements of instant messaging, group communication and voice chat into a professional group communication software" | No |
| raidhost | X | raidhost.exe | Added by the AGENT-LID TROJAN! | No |
| HighPoint ATA RAID Management Software | Y | raidman.exe | HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID | No |
| RaidTool | U | raid_tool.exe | VIA V-RAID Tool - hard disk striping/mirroring utility for increased performance and reliability | No |
| VIA RAID TOOL | U | raid_tool.exe | VIA V-RAID Tool - hard disk striping/mirroring utility for increased performance and reliability | No |
| Rainlendar | U | Rainlendar.exe | Rainlendar is a customizable calendar that displays the current month | No |
| Rainlendar2 | U | Rainlendar2.exe | Rainlendar is a customizable calendar that displays the current month | No |
| Rainmeter | N | Rainmeter.exe | Rainmeter is a customizable performance meter, which can display the CPU load, memory utilization, etc | No |
| Bron-Spizaetus | X | RakyatKelaparan.exe | Added by the BRONTOK-J or BRONTOK-L WORMS! | No |
| Msn Service | X | raloded.exe | Added by the MYTOB-DY WORM! | No |
| RAMASST | U | RAMASST.exe | Optionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP's CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs | No |
| RamBooster | U | Rambooster.exe | RamBooster memory manager | No |
| RAMBooster.Net | U | RAMBooster.exe | RAM Booster .Net is "a smart memory management program that will keep your computer (PC) running better, faster, and longer" | No |
| RAMConnectionChecker | ? | RAMConnChecker.exe | Part of Remote Access Manager (RAM) for Nortel Networks - which "combines an intuitive, user-friendly remote access interface for dialup, cable, LAN, wireless, and DSL users with state-of-the-art phonebook, dialing, and seamless software distribution and update capabilities". Is it required? | No |
| RAMGINAConnWatch | ? | RAMConnWatcher.exe | Part of Remote Access Manager (RAM) for Nortel Networks - which "combines an intuitive, user-friendly remote access interface for dialup, cable, LAN, wireless, and DSL users with state-of-the-art phonebook, dialing, and seamless software distribution and update capabilities". Is it required? | No |
| RAMDef | U | ramdef.exe | Ram Def memory manager - monitors and defragments your system RAM to improve reliability and speed. No longer supported or available from the author | No |
| RamIdle | U | ramidle.exe | RAM Idle memory manager from TweakNow which is also included in the PowerPack | No |
| RAMpage | U | RAMpage.exe | Small Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source | No |
| ftweak_RAMRush | U | RAMRush.exe | RAMRush by FTweak Inc - "is a free memory management and optimization tool. It can efficiently optimize memory usages of your Windows system, free up physical RAM and make your system work better" | Yes |
| RAMRush | U | RAMRush.exe | RAMRush by FTweak Inc - "is a free memory management and optimization tool. It can efficiently optimize memory usages of your Windows system, free up physical RAM and make your system work better" | Yes |
| run= | U | ramsys.exe | Advanced Startup Manager from Rays Lab | No |
| RAM Idle Professional | U | RAM_XP.exe | RAM Idle memory manager from TweakNow which is also included in the PowerPack | No |
| random | X | random.exe | Added by the DLOADER-KM TROJAN! | No |
| Service Noits | X | ranga.exe | Added by the BOOM-A MALWARE! | No |
| rant | X | rant.exe | Added by the RBOT-ZB WORM! | No |
| raome | X | raome.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| RapApp | Y | RAPAPP.EXE | Application protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch | No |
| Rapid Antivirus | X | Rapid Antivirus.exe | Rapid Antivirus rogue security software - not recommended, removal instructions here | No |
| RaptorDefence | X | RaptorDefence.exe | RaptorDefence rogue security software - not recommended, removal instructions here | No |
| raqkesibxici | X | raqkesibxici.exe | Detected by McAfee as Downloader.a!dcl and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| Rarupdate | X | rarupdates.exe | Detected by Symantec as Backdoor.Optix. The file is located in %System% | No |
| Macromedia Critical Updater | X | rarww.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| cifxljac | X | rasctrnm6.exe | Detected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System% | No |
| rasctrs | X | rasctrs.exe | Hijacker, also detected as the ADWAHECK TROJAN! | No |
| RasMan.exe | X | RasMan.exe | Added by the FEUTEL-H TROJAN! | No |
| rasman | X | rasman32.exe | Added by the BCKDR-QGN BACKDOOR! | No |
| Microsoft DirectX | X | rasmngr.exe | Detected by Trend Micro as WORM_SDBOT.AU | No |
| RasCon Remote Access Service Manager | X | rasmngr.exe | Added by the SPYBOT.EM WORM! | No |
| Remote Access Service Manager | X | rasmngr.exe | Detected by Trend Micro as WORM_AGOBOT.KU | No |
| aRato | X | Rato.vbs | Added by the RABFU-A VIRUS! | No |
| Rato | X | Ratoii.vbs | Added by the RABFU-A VIRUS! | No |
| RemoteAgent | Y | RAUAgent.exe | Trend Micro's Office Scan Client, see here - "Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates" | No |
| 802.11g MIMO Wireless Utility | U | RaUI.exe | Wireless configuration utility for Ralink 802.11g MIMO based products | No |
| Airlink101 Wireless Monitor | U | RaUI.exe | Wireless configuration utility for AirLink 101 networking products based upon Ralink chipsets | No |
| Edimax Wireless Utility | U | RaUI.exe | Wireless configuration utility for Edimax networking products based upon Ralink chipsets | No |
| Ralink Wireless Utility | U | RaUI.exe | Wireless configuration utility for Ralink based products | No |
| Rosewill Wireless Utility | U | RaUI.exe | Wireless configuration utility for Rosewill networking products based upon Ralink chipsets | No |
| Tenda Wireless Utility | U | RaUI.exe | Wireless configuration utility for Tenda networking products based upon Ralink chipsets | No |
| Wireless Utility | U | RaUI.exe | Wireless configuration utility for networking products based upon Ralink chipsets | No |
| UpDate | X | RAuth.exe | Added by the DLOADER-UL TROJAN! | No |
| Microsoft Autorun9 | X | Ravasktao.exe | Detected by Symantec as W32.Ogleon.A | No |
| RtHDVBg | ? | RAVBg64.exe | Installed with the 64-bit 7/Vista drivers for on-board Realtek HD audio codecs. The exact purpose is unknown at present | No |
| HD Audio Control Panel | U | RAVCpl64.exe | Realtek HD Audio Manager, installed with the 64-bit 7/Vista drivers for on-board Realtek HD audio codecs. Provides a default (but optional) System Tray icon which allows you to manage audio device settings and gives you access to the Sound Manager and other multimedia functions. You will also receive notifications when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | No |
| Realtek HD Audio Manager | U | RAVCpl64.exe | Realtek HD Audio Manager, installed with the 64-bit 7/Vista drivers for on-board Realtek HD audio codecs. Provides a default (but optional) System Tray icon which allows you to manage audio device settings and gives you access to the Sound Manager and other multimedia functions. You will also receive notifications when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | No |
| RtHDVCpl | U | RAVCpl64.exe | Realtek HD Audio Manager, installed with the 64-bit 7/Vista drivers for on-board Realtek HD audio codecs. Provides a default (but optional) System Tray icon which allows you to manage audio device settings and gives you access to the Sound Manager and other multimedia functions. You will also receive notifications when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | No |
| RAVEN_VLZS.EXE | X | RAVEN_VLZS.EXE | DownloadReceiver parasite - no longer in existence | No |
| RavMon | Y | RavMon.exe | Rising antivirus | No |
| run= | X | RAVMOND.exe | Added by the LOVGATE-F WORM! | No |
| RavAv | X | RavMonE.exe | Added by the RJUMPF-F WORM! | No |
| Rapdata | X | ravsecs.exe | Added by the QQPASS-V TROJAN! | No |
| RavUptpe | X | ravsesur.exe | Added by the QQPASS-T TROJAN! | No |
| Rapdatybs | X | ravseteyns.exe | Added by the PWS-ACP TROJAN! | No |
| Update.exe | X | ravseuper.exe | Added by the QQPASS-P TROJAN! | No |
| Raptelnet | X | ravspeger.exe | Added by the QQPASS-AA TROJAN! | No |
| Raptelt | X | ravspegtl.exe | Added by the QQPASS-AB TROJAN! | No |
| RavStub | Y | ravstub.exe | Rising antivirus | No |
| RavTask | Y | RavTask.exe | Rising antivirus | No |
| RavTimer | Y | RavTimer.exe | Rising antivirus | No |
| RAV8Tray | Y | ravtray8.exe | RAV Antivirus Desktop by GeCAD Software - acquired by Microsoft in 2003 | No |
| rav_finder | X | rav_finder.exe | Detected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as PasswordStealer.Tibia. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| rav_temp.exe | ? | rav_temp.exe | ?? | No |
| raxlufpyvyxu | X | raxlufpyvyxu.exe | Detected by Sophos as Troj/Cutwail-AE and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| Shell | X | ray.exe | Homepage hijacker re-directing browsers to adult content websites | No |
| Razer Anansi Driver | U | RazerAnansiSysTray.exe | Razer Anansi gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
| Abyssus | U | razerhid.exe | Razer Abyssus gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Arctosa | U | razerhid.exe | Razer Arctosa gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
| Copperhead | U | razerhid.exe | Razer Copperhead gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| DeathAdder | U | razerhid.exe | Razer DeathAdder gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| DeathAdderBlackEdition | U | razerhid.exe | Razer DeathAdderBlackEdition gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Diamondback | U | razerhid.exe | Razer Diamondback 3G gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Habu | U | razerhid.exe | Microsoft Habu (by Razer) gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| HP Gaming Keyboard | U | razerhid.exe | HP VoodooDNA Gaming Keyboard (powered by Razer) driver - required if you use the additional features and programmed keys/macros | No |
| Jomantha | U | razerhid.exe | Belkin n52te (powered by Razer) gaming keypad driver - required if you use the additional features and programmed keys/macros | No |
| Krait | U | razerhid.exe | Razer Krait gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Lachesis | U | razerhid.exe | Razer Lachesis gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Lycosa | U | razerhid.exe | Razer Lycosa gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
| razer | U | razerhid.exe | Razer gaming mouse/keyboard driver - required if you use the additional features and programmed keys/macros | No |
| Reclusa | U | razerhid.exe | Microsoft Reclusa (by Razer) gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
| Salmosa | U | razerhid.exe | Razer Salmosa gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Tarantula | U | razerhid.exe | Razer Tarantula gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
| Razer Imperator Driver | U | RazerImperatorSysTray.exe | Razer Imperator gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Razer Imperator Driver | U | RazerImperatorTray.exe | Razer Imperator gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Razer Mamba Elite Driver | U | RazerMambaSysTray.exe | Razer Mamba gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Razer Naga Driver | U | RazerNagaSysTray.exe | Razer Naga gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Razer Nostromo Driver | U | RazerNostromoSysTray.exe | Razer Nostromo gaming controller driver - required if you use the additional features and programmed keys/macros | No |
| Razer StarcraftII Driver | U | RazerStarCraftIISysTray.exe | Razer StarCraft II gaming peripherals driver - required if you use the additional features and programmed keys/macros | No |
| Razer Mamba Driver | U | RazerTray.exe | Razer Mamba gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| Razer TRON Driver | U | RazerTRONSysTray.exe | Razer TRON gaming mouse driver - required if you use the additional features and programmed keys/macros | No |
| RazeSpyware | X | RazeSpyware.exe | RazeSpyware rogue spyware remover - not recommended | No |
| RazeSpyware Monitor | X | RazeSpyware_monitor.exe | RazeSpyware rogue spyware remover - not recommended | No |
| razor.exe | X | razor.exe | Added by the SILLYFDC-AY WORM! | No |
| RamBooster2 | X | rb.exe | Added by the AKAK TROJAN! | No |
| RapidBlaster | X | rb32.exe | RapidBlaster parasite. A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| rb32 lptt01 | X | rb32.exe | RapidBlaster variant (in a "RapidBlaster" or "rb32" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| rb32 ml097e | X | rb32.exe | RapidBlaster variant (in a "RapidBlaster" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| LOCKDOWN | X | rbDyvEH.exe | Added by the GBOT-I TROJAN! | No |
| rbenh lptt01 | X | rbenh.exe | RapidBlaster variant (in a "RBEnhance" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| rbnynkctv | X | rbnynkctv.exe | Detected by Sophos as Troj/Agent-GPA | No |
| sl4 rules | X | rbot32.exe | Added by the SDBOT-QC WORM! | No |
| MicrosoftUpdate | X | RBuilder.exe | Detected by Sophos as Troj/Dloadr-BMV and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Remote Control | N | Rc.exe | Hinet Hi-Five ISP software | No |
| ElsaCapiCtl | Y | Rcapi.exe | Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem | No |
| Windows Servce Agent | X | rcccgtwv.exe | Detected by Kaspersky as Backdoor.Win32.Rbot.bll and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| Soot | ? | rcea.exe | ?? | No |
| Ring Central Fax | U | rcenterrll.exe | Only needed if you want a PC to answer faxes automatically | No |
| Rcf Driver | X | rcf.exe | Added by the RANDEX.BLD WORM! | No |
| RegClean Expert Scheduler | U | RCHelper.exe | "Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free" | No |
| .norton | X | rchost.exe | Added by the BOXED-H TROJAN! | No |
| RCHotKey | U | RCHotKey.exe | Part of RingCentral Call Controller which "turns your PC into your personal business command center. It brings you real time control of your calls, and immediate access to faxing, your account, Microsoft Outlook® contacts, and many powerful business efficiency tools" | No |
| rcimlby.exe | X | rcimlby.exe | Added by the SDBOT-DHK WORM! | No |
| LTCISI | X | rckit.exe | Added by the IRCBOT-YJ BACKDOOR! | No |
| Inters Configuration Loader | X | RCL0ADERS.exe | Added by the SDBOT-KX WORM! | No |
| RCleanMain | X | RCleanT.exe | Detected by Malwarebytes Anti-Malware as Rogue.Agent.K. The file is located in %ProgramFiles%\RClean | No |
| RemoteCenter | U | RcMan.exe | Remote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats | No |
| rCron | X | rcron.exe | PageOn1 - Switch dialer and hijacker variant, see here | No |
| RCScheduleCheck | U | RCSCHED.EXE | Scheduler for Recovery Commander by Avanquest (was VCOM) - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running" | No |
| RegClean Expert Scheduler | U | RCScheduler.exe | "Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free" | No |
| RCSync | X | RCSync.exe | PrizeSurfer parasite | No |
| BuzMe | U | RCUI.exe | Display Client for the BuzMe Internet Call Waiting Service | No |
| svchost | X | rcv.exe | Detected by Malwarebytes Anti-Malware as Trojan.FkFox. The file is located in %AppData% | No |
| rcwinHyper | U | rcwinHyper.exe | Allows you to select a word or phrase within a document, application, web-page, etc and search for it within an older version the "Le Grand Robert & Collins" French/English dictionary from Le Robert. See here for more information | No |
| RDAgent | X | RDAgent.exe | RegDefense rogue registry cleaner - not recommended | No |
| RDClient | U | RDCLIENT.EXE | Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection | No |
| RDListener | X | RDListener.exe | RegDefense rogue registry cleaner - not recommended | No |
| rdmouw | X | rdmouw.exe | Detected by Dr.Web as Trojan.DownLoader7.32785 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| RDM+ Control Panel | U | rdmpserv_cpanel.exe | Remote Desktop for Mobiles - "Access remotely your computer even through NAT and Firewall from mobile. You can send and receive emails, edit word documents, surf web, manage files and folders and do hundreds of other things that you usually do sitting in front of your home or office computer" | No |
| ucquwf | X | rdpclipi.exe | Detected by Dr.Web as Trojan.DownLoader8.37095 | No |
| RDPlatinum v5 | X | RDPlatinumv5.exe | Registry Defender Platinum rogue registry cleaner - not recommended, removal instructions here | No |
| RAMDrive | U | RDTask.exe | Virtual Hard Drive Pro from Farstone - "takes a portion of your system memory and creates a RAM disk drive, which functions like a physical hard drive, only with much better access rates." No longer available | No |
| RE.exe | U | RE.exe | RegistryEasy registry cleaner - regarded by Symantec as a potentially unwanted application, see here | No |
| RealP1ayer | X | rea1p1ayer.exe | Added by the RPLAY.A TROJAN! Note that the name has a number "1" in place of the second lower case "L". The filename has a number "1" in place of both lower case "L" | No |
| vmware | X | read.exe | Detected by Dr.Web as Trojan.DownLoader8.17512 and by Malwarebytes Anti-Malware as Trojan.Agent.VM | No |
| WinReader | X | read.exe | Added by the DELBOT-V WORM! | No |
| Microsoftz turn Control | X | read.pif | Added by the RBOT-AFS WORM! | No |
| User32 | X | Read101.exe | Added by the CYN BACKDOOR! | No |
| Windows Update System | X | reader.exe | Detected by Sophos as W32/SillyFDC-GB and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| readericon10 | ? | readericon10.exe | Related to a multimedia card reader - possibly based upon an Alcor Micro chipset. What does it do and is it required? | No |
| readericon | U | readericon45G.exe | Tray icon to set various configuration settings for Sunkist (and maybe other) media card readers | No |
| Mobipocket Reader Notifications | U | readernotify.exe | Part of Mobipocket Reader - "Store all your eBooks, eNews & self-published eDocs on your PC. Download eBooks in Mobi format from your favorite ebookstores to read on your smartphone, PDA, laptop or on your desktop PC" | No |
| reader_s | X | reader_s.exe | Detected by Sophos as Troj/Agent-IUT | No |
| Adobe Acrobat | N | Reader_sl.exe | Speeds up the time it takes to load the free Adobe Reader PDF file viewer. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Adobe Reader to function properly | Yes |
| Adobe Reader Speed Launch | X | reader_sl.exe | Detected by Kaspersky as Trojan.Win32.Scar.cezj. Note - this is not the valid Adobe file which uses the same "Name" and filename and normally resides in a sub-directory of %ProgramFiles%\Adobe. This one is found in %UserTemp% | No |
| Adobe Reader Speed Launch | N | reader_sl.exe | Speeds up the time it takes to load older versions of the free Adobe Reader PDF file viewer. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Adobe Reader to function properly | Yes |
| Adobe Reader Speed Launcher | X | reader_sl.exe | Added by the VB-EUV TROJAN! Note - this is not the valid Adobe file which uses the same "Name" and filename and normally resides in a sub-directory of %ProgramFiles%\Adobe. This one is found in %Windir% and %System% | No |
| Adobe Reader Speed Launcher | N | Reader_sl.exe | Speeds up the time it takes to load the free Adobe Reader PDF file viewer. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Adobe Reader to function properly | Yes |
| Lancement rapide d'Adobe Reader | N | reader_sl.exe | Speeds up the time it takes to load the free Adobe Reader PDF file viewer. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Adobe Reader to function properly. French version | No |
| Reader_sl | N | Reader_sl.exe | Speeds up the time it takes to load the free Adobe Reader PDF file viewer. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Adobe Reader to function properly | Yes |
| Adobe Acrobat | N | READER~1.EXE | Speeds up the time it takes to load older versions of the free Adobe Reader PDF file viewer. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Adobe Reader to function properly | Yes |
| Adobe Reader Speed Launch | N | READER~1.EXE | Speeds up the time it takes to load older versions of the free Adobe Reader PDF file viewer. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Adobe Reader to function properly | Yes |
| Firewall config | X | ReadMe.exe | Added by the SILLYFDC.BBT WORM! | No |
| gouday.exe | X | readme.exe | Added by the BEAGLE.C WORM! | No |
| winlogin | X | ReadMe.exe | Added by the SILLYFDC.BBT WORM! | No |
| army logo | U | readmename.exe | Torrent101 potentially unwanted torrent client application that installs a Browser Helper Object and displays advertisements | No |
| DevconDefaultDB | ? | READREG | Appears to be related to older Creative Soundblaster soundcards | No |
| Real Internet Player | X | Reaiplay.exe | Added by a variant of the SPYBOT WORM! | No |
| atidriver | X | reaIplayer.exe | Added by the WARPIGS-E WORM! Note the uppercase "I" in the filename, rather than a lower case "L" | No |
| Real-Tens | X | Real-Tens.exe | DownloadWare adware | No |
| Run | X | real.exe | Detected by Trend Micro as WORM_LOVGATE.E | No |
| windows update | X | real.exe | Detected by Sophos as Troj/LegMir-AU and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| real scheduler.hta | X | RealAudio.exe | Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player | No |
| RealAudio | X | RealAudio.exe | Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player | No |
| Realaudio Player | X | realaudio32.exe | Detected by Trend Micro as WORM_AGOBOT.AFR | No |
| RealAV.exe | X | RealAV.exe | Real Antivirus rogue security suite - not recommended, removal instructions here | No |
| realcleaner main | X | realcleaneru.exe | RealCleaner rogue security software - not recommended, removal instructions here | No |
| Windows Pc Driver | X | Realhost.exe | Added by the ESION BACKDOOR! | No |
| REAL | N | realjbox.exe | Real Jukebox - MP3 and music files player | No |
| eTrust Realtime Monitor | X | realmon.exe | Added by the LAZAR.B TROJAN! Note - this is not the legitimate CA eTrust Antivirus file of the same name which is located in %ProgramFiles%\CA\eTrust\Antivirus. This one is located in %System% | No |
| Realtime Monitor | Y | realmon.exe | Real-time scanner part of the now discontinued eTrust Antivirus/InoculateIT version 6 virus scanners from CA | No |
| Real One Player | X | realone.exe | Added by the RBOT.APE WORM! | No |
| MsgCenterExe | N | RealOneMessageCenter.exe | RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way | No |
| RealP1ayer | X | realp1ayer.exe | Added by the RPLAY.A TROJAN! Note that both the name and filename have a number "1" in place of the second lower case "L" | No |
| KEY NAME REAL | X | realplay.exe | Detected by McAfee as PWS-Zbot.gen.asg and by Malwarebytes Anti-Malware as Backdoor.Agent.KNRGen. Note that the legitimate RealPlayer is located in %ProgramFiles%\Real\RealPlayer whereas this one is located in %AppData%\FolderName@OFF@ | No |
| RealDownload | N | RealPlay.exe | Download manager. Available via Start → Programs | No |
| realplay | N | realplay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences | No |
| realplay lptt01 | X | realplay.exe | RapidBlaster variant (in a "realPlay" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note that the legitimate RealPlayer is located in %ProgramFiles%\Real\RealPlayer | No |
| realplay ml097e | X | realplay.exe | RapidBlaster variant (in a "realPlay" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note that the legitimate RealPlayer is located in %ProgramFiles%\Real\RealPlayer | No |
| RealPlayer | N | realplay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences | No |
| Realplayer One | X | realplay.exe | Detected by Sophos as W32/Rbot-NK. Note that the legitimate RealPlayer is located in %ProgramFiles%\Real\RealPlayer whereas this one is located in %System% | No |
| Realplayer Video | X | RealPlay.exe | Added by a variant of Win32/Rbot. Note that the legitimate RealPlayer is located in %ProgramFiles%\Real\RealPlayer whereas this one is located in %System% | No |
| RealTray | N | RealPlay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences | No |
| Realplayer.exe | X | Realplayer.exe | Added by the DELF.CNV TROJAN! | No |
| Windows SYSTEM32 | X | Realplayer.exe | Added by the SPYBOT.ZH WORM! | No |
| Real Media Player | X | realplayer2.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| MS Real Player | X | RealPlyr.exe | Added by the RBOT.MR WORM! | No |
| Realpopup | ? | Realpopup.exe | RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor" | No |
| gcasServ | X | realsched.exe | Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name | No |
| MSService_v1.0 | X | realsched.exe | EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name which is normally located in %CommonFiles%\Real\Update_OB. This one is located in %System% or %Temp% | No |
| Realplayer Codec Support | X | realsched.exe | Added by the AGOBOT-AAD WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name which is normally located in %CommonFiles%\Real\Update_OB. This one is located in %System% | No |
| Realsched | N | realsched.exe | Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry | No |
| realtpsk | X | realsched.exe | Chinese originated adware. Detected by Panda as NewWeb. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name and this file is located in %System% | No |
| TkBell.Exe | N | realsched.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools → Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK | No |
| TkBellExe | N | realsched.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools → Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK | No |
| WinHelp | X | realsched.exe | Added by the LOVGATE-F WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name which is normally located in %CommonFiles%\Real\Update_OB. This one is located in %System% | No |
| RealSPEED | U | RealSPEED.Exe | RealSPEED - tweaking utility to speed-up your internet connection | No |
| Realtek A-350 Adapter | X | realtek-a350.exe | Detected by Dr.Web as Trojan.PWS.Siggen.35890 and by Malwarebytes Anti-Malware as Backdoor.MSIL.P | No |
| Realtek | X | Realtek.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Xtrat. Note that this is not a valid Realtek process and the file is located in %Windir%\Realtek | No |
| Realtek HD Audio | X | Realtek.exe | Detected by Kaspersky as Trojan.Win32.Buzus.ckyb. Note that this is not a valid Realtek process | No |
| Realtek_Audio | X | Realtek.exe | Detected by Kaspersky as Backdoor.Win32.VanBot.oc. Note that this is not a valid Realtek process and the file is located in %System% | No |
| Windows Network Service | X | Realteks.exe | Added by the RBOT-GTG WORM! | No |
| Univers | X | Realtim.exe | Detected by Dr.Web as Trojan.PWS.Siggen1.893 | No |
| PCDRealtime | X | realtime.exe | Real time monitoring for PC Doctor Online anti-virus - not recommended, see here | No |
| eTrust | X | RealTimeMon.exe | Added by the DELF-EPG TROJAN! | No |
| RealTimeUpdate | ? | RealTimeUpdate.exe | Product description in properties is "InternetExplorerCommunicationAgent Module" ? | No |
| Real player updater | X | realupd.exe | Detected by McAfee as Parlay | No |
| RealUpdater | X | realupd.exe | Detected by Symantec as Trojan.Mitglieder.I and by Malwarebytes Anti-Malware as Trojan.Passwords | No |
| RealPlayerUpdater | X | realupd32.exe | Added by the LOHAV-T TROJAN! | No |
| updatereal | X | realupdate.exe | Chinese originated adware | No |
| RealVaccineMain | X | RealVaccine.exe | RealVaccine rogue security software - not recommended, removal instructions here | No |
| Real Windows Value | X | RealWin.exe.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\Real Windows Folder | No |
| REAnti.exe | X | REAnti.exe | REAnti rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| RebateNation0 | X | RebateNation0.exe | RebateNation adware | No |
| MSConfig | X | reblslze.exe | Detected by Sophos as Troj/Tofsee-L and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Reboot | N | Reboot.exe | MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards | No |
| System Reboot | X | rebootsys.exe | Added by the RBOT-WU WORM! | No |
| Diesel | X | Recalculate.exe | Added by the LAZAR TROJAN! | No |
| netservices | X | recall.exe | Detected by Trend Micro as WORM_WOOTBOT.D | No |
| Recguard | X | recguard.exe | Added by the LAZAR.B TROJAN! Note - this is not the legitimate HP recovery partition utility with the same filename which is located in %Windir%\SMINST. This one is located in %ProgramFiles%\HP | No |
| Recguard | Y | recguard.exe | On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense | No |
| winldr | X | Rechnung.pdf.exe | Detected by McAfee as Downloader-ACS | No |
| Reclip | N | reclip.exe | Reclip Popup Clipboard manager | No |
| IBM RecordNow! | N | RecordNow.exe | IBM customized version of the RecordNow! CD-writing utility from Sonic Solutions | Yes |
| RecordNow | N | RecordNow.exe | RecordNow! CD-writing utility from Sonic Solutions | Yes |
| mmsys | ? | recover.exe | ?? | No |
| RecoverFromReboo | N | RecoverFromReboot.exe | Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry | No |
| RecoverFromReboot | N | RecoverFromReboot.exe | Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry | No |
| IERecovery | X | Recovery.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.IEC. Note - this is not a legitimate Internet Explorer process and the file is located in %AppData%\Microsoft\Internet Explorer\Recovery - see here | No |
| Windows Recovery Console | X | recovery.exe | Added by the RANSOM.FD WORM! | No |
| RecoverFromReboo | N | RECOVE~1.EXE | Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry | No |
| RecoverFromReboot | N | RECOVE~1.EXE | Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry | No |
| Internet | X | recruit.exe | Added by the RBOT-AJG WORM! | No |
| RecShe | N | RecSche.exe | Recording scheduler for WatchTV Capture Card (TV Tuner card) | No |
| mysvcig38 | X | recsl.exe | Added by a variant of W32/Rbot-FOU | No |
| real-con | X | recstart.exe | Detected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %AppData%\real-con | No |
| Time jugs | X | Rect Bike.exe | Memini adware | No |
| Recycle | X | Recycle.exe | Added by the SCAR.BTHF TROJAN! | No |
| Taskman | X | recycle.exe | Added by the PALEVO.KK WORM! | No |
| CurrentVersion | X | recyclebin.exe | Added by the AUTORUN-AZX WORM! | No |
| Taskman | X | recyclebin.exe | Added by the AUTORUN-AZX WORM! | No |
| ftweak_recyclebinex | U | RecycleBinEx.exe | RecycleBinEx by FTweak Inc - "a powerful and easy to use recycle bin manager for Windows Operating System. It extends and enhances the Windows recycle bin, and let you use many extra features in it" | Yes |
| RecycleBinEx | U | RecycleBinEx.exe | RecycleBinEx by FTweak Inc - "a powerful and easy to use recycle bin manager for Windows Operating System. It extends and enhances the Windows recycle bin, and let you use many extra features in it" | Yes |
| Recycler DO NOT MODIFY | X | recyclecl.exe | Added by the RBOT.DDA WORM! | No |
| Recycle Bin Handler | X | recycler.exe | Added by the SHUCKBOT-A TROJAN! | No |
| LantronixRedirector | ? | red32.exe | Related to either the Secure Com Port Redirector or Com Port Redirector from Latronix. What does it do and is it required? | No |
| Red Flag | N | redflag.exe | PMS prediction program with modes for guys and girls - no longer available | No |
| Red Gate | X | RedGate.exe | Detected by Malwarebytes Anti-Malware as Trojan.Clicker. The file is located in %AppData% | No |
| Bol IM | N | RediffMessenger.exe | Rediff Bol instant messenger | No |
| redirect | X | redirect*.exe | Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit | No |
| Reek 32 Server | X | reek32.exe | Detected by Symantec as W32.Randex.gen | No |
| Referee | U | referee.exe | MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run | No |
| Reflex Vision | U | ReflexVision.exe | Reflex Vision from Increment Software. "A background application for Windows XP that makes switching windows faster and easier" | No |
| Refresh | N | Refresh.exe | (Iomega) Refresh - loads the Iomega desktop icons at startup | No |
| Reg Tool | X | Reg Tool.exe | RegTool rogue registry cleaner - not recommended, removal instructions here | No |
| Reg | X | Reg.hta | Passon homepage hi-jacker | No |
| Ereg | N | reg32.exe | EReg is a software registration tool incorporated on products such as those by Broderbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it | No |
| Microsoft System Firewall 2006.2 | X | reg32.exe | Added by a variant of W32/Sdbot.worm | No |
| reg32 | X | reg32.exe | Added by the NOUPDATE.B TROJAN! | No |
| Reg32 | X | Reg32.exe | Hijacker - redirecting to only-virgins.com | No |
| Reg32 | X | reg33.exe | CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN! | No |
| Explore | X | RegCheck.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Windir%\SystemEntry | No |
| RegClean | X | RegClean.exe | RegClean rogue registry cleaner - not recommended | No |
| Registry Cleaner | X | Regclean.exe | Registry Cleaner misleading security software - not recommended, see here | No |
| Card Monitor | N | REGCNT09.exe | For the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start → Programs | No |
| SAClient | N | RegCon.exe | AT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you're immediately notified by e-mail, pager, or text messaging | No |
| RegCompres | X | REGCPM32.EXE | Detected by Sophos as Troj/Dasmin-Fam | No |
| Regcxdinaf | X | REGCXDINAF.EXE | Detected by Sophos as Troj/Bancos-BW | No |
| Regcxn | X | Regcxn.exe | Added by the COIBOA-D TROJAN! | No |
| regdefend | U | regdefend.exe | "RegDefend is a configurable, kernel based registry protection system, designed to intercept selected changes before they occur, thus also preventing malicious software like viruses, trojans and worms from using the registry to their advantage" | No |
| Optim1 | X | regdtopt.exe | Detected by Symantec as Trojan.Ramvicrype and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Optim2 | X | regdtopt.exe | Detected by Symantec as Trojan.Ramvicrype and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Optim3 | X | regdtopt.exe | Detected by Symantec as Trojan.Ramvicrype and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Optim4 | X | regdtopt.exe | Detected by Symantec as Trojan.Ramvicrype and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| RegEasy.exe | X | RegEasy.exe | RegistryEasy bogus registry cleaning utility - not recommended, see here and here | No |
| sp | X | regedit -s sp.dll | Malicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix. The "sp.dll" is located in %Windir% | No |
| spp | X | regedit -s spp.reg | IE search hijacker - changes the default search to h**p://www.hotsearchbox.com/ie/. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "spp.reg" file is located in %Root% | No |
| system | X | regedit -s system.dll | Homepage hijacker | No |
| @ | X | regedit -s win.dll | Detected by Symantec as JS.Seeker.K. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "win.dll" file is located in %Windir% | No |
| win | X | regedit -s win.dll | Detected by Symantec as JS.Seeker.K. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "win.dll" file is located in %Windir% | No |
| tour | N | regedit ..tour.reg | Edits registry values to keep the WinMe tour in Task Scheduler | No |
| DJRegFix | N | regedit /s c:\hp\djregfix.reg | DJRegFix showed up first in WinME as a "clever" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This "utility" adds the functionality and compatibility HP forgot to add in its WinME drivers | No |
| sys | X | regedit /s sys.reg | Detected by Symantec as Adware.Raxums. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "sys.reg" file is located in %Windir% | No |
| tourpath | N | regedit /s [path] tour.reg | Edits registry values to keep the Win 2000 "tour" in Task Scheduler | No |
| sys | X | regedit sysdllwm.reg | CoolWebSearch parasite variant - also detected as the FEMAD-L TROJAN! | No |
| [random name] | X | regedit.exe | PurityScan adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup! | No |
| Ccao | X | regedit.exe | Probably a variant of MediaTickets adware. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup! This version resides in a "mduu" subfolder, which may change | No |
| Microsoft Regestry Edit Manager | X | regedit.exe | Added by the SHEUR.HC TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System% | No |
| NeroCheck | X | regedit.exe | Added by the DOOMJUICE.B WORM! Note - this is not the valid Ahead Nero CD/DVD burning program. Also, it is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System% | No |
| regedit | X | regedit.exe | Detected by Symantec as W32.Brid.A@mm. Note - this is not the legitimate Windows registry editor (regedit.exe) which is located in %Windir%. This one is located in %System% | No |
| regedit | X | regedit.exe | Detected by Symantec as W32.Ganbate.A. Note - this is not the legitimate Windows registry editor (regedit.exe) which is located in %Windir%. This one is located in %Windir%\security\Database | No |
| Regedit32 | X | regedit.exe | Detected by Sophos as Troj/Mdrop-CMO and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the valid Windows registry editor which resides in %Windir% and will not figure in Msconfig/Startup! This one is located in %System% | No |
| Symantec Antivirus professional | X | regedit.exe | Added by a variant of the FORBOT WORM! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System% | No |
| SystemSearch | X | regedit.exe -s ie.reg | Installs a Seachxl.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "ie.reg" file is located in %Root% | No |
| SysSearch | X | Regedit.exe -s pcsearch.reg | Detected by McAfee as StartPage-FN. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "pcsearch.reg" file is located in %Windir% | No |
| SystemSearch | X | regedit.exe -s sys.reg | Installs a i--search.com browser page hijack. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "sys.reg" file is located in %Windir% | No |
| SysSearch | X | Regedit.exe -s sysreg.reg | Detected by Sophos as Troj/StartPa-ME. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "sysreg.reg" file is located in %Windir% | No |
| Data789 | X | Regedit.exe ....data789.tmp | Homepage hijacker | No |
| PowerSet | ? | Regedit.exe /s ...PowerSet_8100_CU.REG | Appears to be Toshiba power management related | No |
| OPQFile | X | regedit.exe /s ...rad03FA6.tmp | Unsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit | No |
| (Default) | X | regedit.exe /s appboost.reg | Detected by Symantec as W32.Appix.D.Worm. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKCU\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank. The Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "appboost.reg" file is located in %Windir% | No |
| Internal | X | regedit.exe /s c[month number] | Detected by Symantec as JS.Fortnight.D. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "c[month number]" file is located in %Windir%, ie, C:\Windows\c10 | No |
| setupuser | X | regedit.exe setupuser.log | Regfile in disguise - another CoolWebSearch parasite variant. Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The "setupuser.log" file is located in %Windir% | No |
| start | X | regedit.lnk | Added by the DLOADR-DKH TROJAN! | No |
| Secure64 | X | Regedit32.com StartUp | Added by the BRONTOK-CJ WORM! | No |
| Microsoft Regestry Manager | X | regedit32.exe | Added by a variant of the IRCBOT.ARD WORM! | No |
| RegEdit32 | X | RegEdit32.exe | Detected by Sophos as W32/Voumit-A and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Service Registry NT Save | X | regeditnt.exe | Detected by Sophos as Troj/Bancos-BM | No |
| Regedit | X | regedits.exe | Added by the BANCBAN-QV TROJAN! | No |
| tsx | X | regedlt.exe | Added by the SDBOT-KA BACKDOOR! Note the lower case "L" in place of the lower case "I" in the command | No |
| NOD32 FiX | X | regedt32.exe | NodFix cannot be recommended and is given an (X) status because we do not and will not support Cracks or Warez. Do not delete the regedt32.exe as it is a legitimate Windows application. NodFix interferes with the default settings of the NOD32 AV application allowing users to bypass its free use period and changes the default update server allowing to update NOD32 without password. Note - to avoid interfering with the NOD32 application original settings no full cleanup can be provided | No |
| Windows Registry Express Loader | X | regexpress.exe | Added by the FORBOT-CJ WORM! | No |
| RegFreeze | X | regfreeze.exe | RegFreeze rogue spyware remover - not recommended, removal instructions here | No |
| reghost | X | reghost.exe | SpyPal surveillance software. Uninstall this software unless you put it there yourself | No |
| reginfo32 | ? | reginfo32.exe | ?? | No |
| Registry Integrity Checker | X | regintmon.exe | Added by a variant of the AGOBOT WORM! | No |
| palmOne Registration | N | register.exe | Registration reminder for Palm products | No |
| Register MediaRing Talk | N | register.exe | If you don't want to register MediaRing and be reminded about it every bootup disable it | No |
| WINDOWS REGISTER EDIT | X | registr32.exe | Added by an unidentified WORM or TROJAN! | No |
| CorelDRAW Graphics Suite 11b | N | Registration.exe | Registration wizard for version 11b of the CorelDRAW® Graphics Suite design software | No |
| WordPerfect Office 1215 | N | Registration.exe | Corel WordPerfect Office 12 registration wizard | No |
| Registry Services | X | Registry.exe | Added by the CILE TROJAN! | No |
| RegistryMonitor | X | registry.pif | Affilred adware | No |
| Microsoft Regestry Manager | X | registry32.exe | Added by the IRCBOT.ARD WORM! | No |
| Reg32 | X | Registry32.exe | Detected by Symantec as Backdoor.Crazynet and by Malwarebytes Anti-Malware as Backdoor.Agent.RGGen | No |
| RegistryBooster | N | RegistryBooster.exe | Old version of the RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will "clean, repair and optimize your system." Run manually at regular intervals | Yes |
| Uniblue Registry Booster | N | RegistryBooster.exe | Old version of the RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will "clean, repair and optimize your system." Run manually at regular intervals | Yes |
| Uniblue RegistryBooster 2 | N | RegistryBooster.exe | Old version of the RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will "clean, repair and optimize your system." Run manually at regular intervals | Yes |
| Uniblue RegistryBooster 2009 | N | RegistryBooster.exe | Old version of the RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will "clean, repair and optimize your system." Run manually at regular intervals | Yes |
| RegistryCleanFixMFC | X | registrycleanfix.exe | RegistryCleanFix rogue registry cleaner - not recommended | No |
| RegistryClever | X | RegistryClever.exe | RegistryClever rogue registry cleaner - not recommended, removal instructions here | No |
| TrayScan | X | RegistryCleverTray.exe | RegistryClever rogue registry cleaner - not recommended, removal instructions here | No |
| PDF Converter Registry Controller | ? | RegistryController.exe | Part of PDF Converter Professional version 2 from Scansoft (now Nuance). What does it do and is it required? | No |
| PDF3 Registry Controller | ? | RegistryController.exe | Part of PDF Converter Professional version 3 from Scansoft (now Nuance). What does it do and is it required? | No |
| PDF4 Registry Controller | ? | RegistryController.exe | Part of PDF Converter Professional version 4 from Scansoft (now Nuance). What does it do and is it required? | No |
| PDF5 Registry Controller | ? | RegistryController.exe | Part of PDF Converter Professional and PDF Create (both version 5) - from Nuance. What does it do and is it required? | No |
| PDF6 Registry Controller | ? | RegistryController.exe | Part of PDF Converter Professional and PDF Create (both version 6) - from Nuance. What does it do and is it required? | No |
| PDF7 Registry Controller | ? | RegistryController.exe | Part of PDF Converter Professional and PDF Create (both version 7) - from Nuance. What does it do and is it required? | No |
| RegistryDoctor2008 | X | registrydoctor.exe | RegistryDoctor2008 rogue registry cleaner - not recommended, removal instructions here | No |
| RegistryFix.exe | X | registryfix.exe | RegistryFix rogue registry cleaner - not recommended, removal instructions here. The homepage for the tool has a poor reputation | No |
| RegistryGreat.exe | X | RegistryGreat.exe | Registry Great rogue registry cleaner - not recommended | No |
| Register Manager | X | RegistryManage.exe | Added by the SDBOT.AYH WORM! | No |
| run= | X | RegistryReminder.exe | Detected by McAfee as APStrojan.ob | No |
| Windows Registry Repair Pro | U | RegistryRepairPro.exe | Registry Repair Pro. "Scans the Windows Registry for invalid or obsolete information in the registry" | No |
| Registry Reviver | U | RegistryReviver.exe | Registry Reviver from ReviverSoft - is "a utility program designed to scan your computer for registry errors and fix them, to better optimize your computer's performance and stability. It is the perfect tool to perform maintenance and optimize the Windows Registry" | No |
| Regman | X | RegistrySweeperPro.exe | RegistrySweeper rogue registry cleaner - not recommended | No |
| REGIST~1 | U | REGIST~1.EXE | Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation | No |
| RegisterDropHandler | U | REGIST~1.EXE | Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation | No |
| Mircrosoft Technic Help | X | RegKey.exe | Added by a variant of the SPYBOT WORM! See here | No |
| DVD Region Killer | N | RegKillTray.exe | Elaborate Bytes' now discontinued DVD Region Killer utility enables you to play DVD titles made for different regions on your PC, without the hassle to switch the region | Yes |
| RegKillTray | N | RegKillTray.exe | Elaborate Bytes' now discontinued DVD Region Killer utility enables you to play DVD titles made for different regions on your PC, without the hassle to switch the region | Yes |
| CheckScan32 | X | regload16.exe | Detected by Trend Micro as WORM_AEBOT.K | No |
| Registry Loader | X | regloadr.exe | Detected by Symantec as W32.HLLW.Gaobot.AO | No |
| Regmonitor | X | regmaping.exe | Added by the BEAGLE.DO WORM! | No |
| Registry Mechanic | N | RegMech.exe | Part of Registry Mechanic from PC Tools - which "is an advanced registry cleaner for Windows that can safely clean, repair and optimize your registry in a few simple mouse clicks!". This entry is created when Registry Mechanic is installed on XP and loads the System Tray icon and runs a registry scan at startup - if either are enabled. Run manually at regular intervals | Yes |
| RegistryMechanic | N | RegMech.exe | Part of Registry Mechanic from PC Tools - which "is an advanced registry cleaner for Windows that can safely clean, repair and optimize your registry in a few simple mouse clicks!". This entry is created when Registry Mechanic is installed on XP and loads the System Tray icon and runs a registry scan at startup - if either are enabled. Run manually at regular intervals | Yes |
| RegMech | N | RegMech.exe | Part of Registry Mechanic from PC Tools - which "is an advanced registry cleaner for Windows that can safely clean, repair and optimize your registry in a few simple mouse clicks!". This entry is created when Registry Mechanic is installed on XP and loads the System Tray icon and runs a registry scan at startup - if either are enabled. Run manually at regular intervals | Yes |
| Registry Monitor | X | regmon.exe | Added by the BCKDR-QKH BACKDOOR! | No |
| CheckRegDefragOnce | Y | regopt.exe | Registry Defragger and Optimizer from the Advanced System Optimizer utility suite by Systweak Inc | No |
| wininet.dll | X | regperf.exe | Detected by Symantec as Trojan.Zlob | No |
| RegPowerClean | X | RegPowerClean.exe | Registry Power Cleaner rogue registry cleaner - not recommended | No |
| AUTOPROP | N | REGPROP.EXE WMPADDIN.DLL | Both the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension | No |
| RegProt | Y | Regprot.exe | RegistryProt from Diamond Computer Systems - protects the system registry against changes | No |
| Registry Protector | X | regprotect.exe | Detected by Trend Micro as WORM_ARIVER.A | No |
| Regptmens | X | REGPTMENS.EXE | Added by the BANCOS-ED TROJAN! | No |
| Registry Checker | X | Regrun.exe | Added by the SDBOT BACKDOOR! | No |
| Windows Services Agant | X | regs32.exe | Added by the SDBOT-DIK WORM! | No |
| RegScan | X | Regscan.exe | Added by the TALEX TROJAN! | No |
| Windows Registry Scan | X | regscan.exe | Added by the RBOT-HA WORM! | No |
| Windows Registry Scan | X | regscan23.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Windows Registry Scan | X | regscan32.exe | Detected by Trend Micro as WORM_RBOT.KE | No |
| Regscan | X | regscanr.exe | Added by the OPTIX-SE TROJAN! | No |
| Server Registry | X | regscr32.exe | Added by the BIFROSE-ZB TROJAN! | No |
| Windows Update Service | X | regscv.exe | Detected by Sophos as W32/Agobot-AM and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Registry Server | X | regserv.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Windows Registry Services | X | regserv.exe | Added by the SLENFBOT.BB WORM! | No |
| WindowsUpdateR | X | regserv.exe | Added by the NURECH TROJAN! | No |
| RegServer | ? | regserve.exe | Related to XGI Technology's Volari graphics cards - what does it do and is it required? | No |
| regservices.exe | X | regservices.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| RegShave | N | regshave.exe | Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly | No |
| regsrv.exe | X | regsrv.exe | Detected by Malwarebytes Anti-Malware as PasswordStealer.Agent. The file is located in %System% | No |
| System Profile | X | regsrv.exe | Detected by Trend Micro as BKDR_OPTIX.12B | No |
| [executed file name] | X | Regsrv32.com | Added by the SOUTHGHOST WORM! | No |
| REGEDIT | X | Regsrv32.com | Added by the SOUTHGHOST WORM! | No |
| Microsoft DLL Registration | X | regsrv32.exe | Detected by Trend Micro as TROJ_VICENOR.AE and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| Reg Service | X | REGSRV32.EXE | Added by the RBOT.ZW WORM! | No |
| Registry Server | X | regsrv32.exe | Added by the RBOT-GM WORM! | No |
| Server Registry | X | regsrv32.exe | Added by the VB-EJD TROJAN! | No |
| Windows Primary Login | X | regsrv32.exe | Detected by Microsoft as Worm:Win32/Pushbot and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%\O-858454-6314-2-64 | No |
| Microsoft DLL Registrations | X | regsrv34.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AQM. The file is located in %AppData% | No |
| Microsoft DLL Registration | X | regsrv64.exe | Detected by Sophos as Troj/VBKrypt-AL and by Malwarebytes Anti-Malware as Worm.Autorun | No |
| RegSrv64D | X | RegSrv64D.exE | Added by the WINKO.AO WORM! | No |
| HControlUser | X | RegSrvc.exe | Detected by Dr.Web as Trojan.MulDrop4.3133 | No |
| regsrvc | X | regsrvc.exe | Added by the STOPED-A TROJAN! | No |
| Regsv | X | regsv.exe | Search hijacker - redirecting to scheo.com | No |
| Regsvc | X | regsv.exe | Added by unidentified malware. The file is located in %Windir%\system | No |
| Registry Service | X | regsvc.exe | Added by the IRCBOT-ZM BACKDOOR! | No |
| Generic Service Process | X | regsvc32.exe | Detected by Symantec as W32.Gaobot.UJ or W32.Gaobot.UL | No |
| MSRegSvc | X | regsvc32.exe | Homepage hijacker that changes your homepage to an adult content site | No |
| regsvc32 | X | regsvc32.exe | Homepage hijacker that changes your homepage to an adult content site | No |
| Task Commander | X | regsvc32.exe | Added by the AGOBOT-RX WORM! | No |
| regsvcdll | U | regsvcdll.exe | Power Spy surveillance software. Uninstall this software unless you put it there yourself | No |
| DHCP Server | X | regsvr.exe | Added by the RBOT-PR WORM! | No |
| Msn Messsenger | X | regsvr.exe | Detected by Sophos as Troj/Agent-GXM and by Malwarebytes Anti-Malware as Trojan.IMWorm | No |
| Registry Serv | X | regsvr.exe | Added by the WEBMONEY-G TROJAN! | No |
| regsvr | X | regsvr.exe | Added by the WEBMONEY-G TROJAN! | No |
| Yahoo Messengger | X | regsvr.exe | Added by the IMAUT.CN WORM! | No |
| evx | X | regsvr32 /s evx.r3x | Detected by Sophos as Troj/Agent-ZIY and by Malwarebytes Anti-Malware as Trojan.Banker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "evx.r3x" file is found in %AppData% | No |
| MsmqIntCert | ? | regsvr32 /s mqrt.dll | Microsoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required? | No |
| uninstal | X | regsvr32 image.dll | CoolWebSearch parasite variant. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "image.dll" file is found in %System% | No |
| Kazaa Download Accelerator Updater (required) | X | regsvr32 kdp****.dll [* = random char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% | No |
| SafeGuard Popup Updater (required) | X | regsvr32 PDF****.dll [* = random char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% | No |
| Popup Defence Updater | X | regsvr32 pdfupd.dll | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% | No |
| SafeGuard Popup Blocker Updater (required) | X | regsvr32 sfg****.dll [* = ramdom char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% | No |
| SafeGuard Popup Updater (required) | X | regsvr32 sfg****.dll [* = random char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% | No |
| SafeGuard Popup Blocker Updater | X | regsvr32 sfgupd.dll | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% | No |
| PCShield | X | regsvr32 sfg_****.dll [* = random char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% | No |
| Popup Blocker Updater | X | regsvr32 veev****.dll [* = random char] | SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% | No |
| Generic Service Process | X | regsvr32.exe | Added by the AGOBOT-AGD WORM! | No |
| Windows Desktop Update | X | regsvr32.exe | Detected by McAfee as RDN/Ransom and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. Note - this is not the legitimate regsvr32.exe process, which is found in %System%. This one is located in %LocalAppData%\Google | No |
| WUx_RegSvr | ? | RegSvr32.exe | x is any number?? | No |
| HREF.OCX | U | regsvr32.exe ....HREF.OCX | HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller | No |
| Register SeqChk | ? | regsvr32.exe ..csseqchk.dll | ?? | No |
| supdate2.dll | X | regsvr32.exe /s supdate2.dll | Added by the ZLOB-VL TROJAN! Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "supdate2.dll" file is found in %System% | No |
| RegBar | U | regsvr32.exe bocaitoolbar.dll | BocaiToolbar adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "bocaitoolbar.dll" file is found in %ProgramFiles%\blogmark | No |
| AsioReg | U | regsvr32.exe ctasio.dll | ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality | No |
| AsioThk32Reg | U | regsvr32.exe ctasio.dll | ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality | No |
| mfhsornwnduy | X | regsvr32.exe gisyflngpshcvuakv.dll | Pro AntiSpyware 2009 rogue spyware remover - not recommended, removal instructions here. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "gisyflngpshcvuakv.dll" file is found in %System% | No |
| Ir41_32.ax | U | regsvr32.exe Ir41_32.ax | Intel® Indeo® video 4.4 Decompression Filter related. The "Ir41_32.ax" file is located in %System% | No |
| kvern16.dll | X | regsvr32.exe kvern16.dll | DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "kvern16.dll" file is found in %System% | No |
| rmoc3260.dll OCX | U | regsvr32.exe rmoc3260.dll | A module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The "rmoc3260.dll" file is found in %System% | No |
| vern16.dll | X | regsvr32.exe vernn16.dll | DailyWinner adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "vernn16.dll" file is found in %System% | No |
| xhehjnnlqercber | X | regsvr32.exe [random name].dll | MxliveMedia adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System% | No |
| Compatibility Service Process | X | regsvs.exe | Added by the GAOBOT.YN WORM! | No |
| regsync | X | regsync.exe | Detected by Symantec as Spyware.SafeSurfing | No |
| Registry System | X | Regsys.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Reg_WFT | X | Regsysw.com | Added by the WILSEF VIRUS! | No |
| Reg_WFT | X | Regsysw.exe | Added by the WILSEF.A WORM! | No |
| Registration-INSDVD | N | RegTool.exe | Registration reminder for Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems | No |
| Registration-InstantCopy | N | RegTool.exe | Registration reminder for Pinnacle InstantCopy burning software from Pinnacle Systems | No |
| Registration-Liquid Edition | N | RegTool.exe | Registration reminder for Pinnacle Liquid professional video editing software from Pinnacle Systems. It became Avid Liquid with the acquisition of Pinnacle Systems by Avid Technology, Inc but has since reached End of Life | No |
| Registration-PCTV Deluxe | N | RegTool.exe | Registration reminder for the Pinnacle PCTV Deluxe solution for watching and recording TV on a desktop/laptop from Pinnacle Systems. The Pinnacle PCTV product line has since been sold to Hauppauge Digital | No |
| Registration-PCTV Sat | N | RegTool.exe | Registration reminder for the Pinnacle PCTV Sat solution for watching and recording satellite TV on a desktop/laptop from Pinnacle Systems. The Pinnacle PCTV product line has since been sold to Hauppauge Digital | No |
| Registration-Pinnacle Edition 5 | N | RegTool.exe | Registration reminder for Pinnacle Edition realtime DV editing and authoring solution from Pinnacle Systems | No |
| Registration-Pinnacle Express | N | RegTool.exe | Registration reminder for Pinnacle Express DVD authoring software from Pinnacle Systems | No |
| Registration-Pinnacle Expression | N | RegTool.exe | Registration reminder for Pinnacle Expression DVD authoring software from Pinnacle Systems | No |
| Registration-Pinnacle Systems DV500 | N | RegTool.exe | Registration reminder for Pinnacle DVD500 realtime DV editing solution from Pinnacle Systems | No |
| Registration-Studio 7 | N | RegTool.exe | Registration reminder for Pinnacle Studio 7 home video editing software from Pinnacle Systems | No |
| Registration-Studio 7 SE | N | RegTool.exe | Registration reminder for Pinnacle Studio 7 SE home video editing software from Pinnacle Systems | No |
| Registration-Studio 8 | N | RegTool.exe | Registration reminder for Pinnacle Studio 8 home video editing software from Pinnacle Systems | No |
| Registration-Studio 8 SE | N | RegTool.exe | Registration reminder for Pinnacle Studio 8 SE home video editing software from Pinnacle Systems | No |
| MicrosoftCorp | X | regtray.exe | Added by the POISON.AHNW BACKDOOR! | No |
| MicrosoftNAPC | X | regtray.exe | Added by the POISON.AHNW BACKDOOR! | No |
| RegTweak | U | RegTwk.exe | Rage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface | No |
| RegVer | X | REGVER.EXE | Added by the LATINUS.16 BACKDOOR! | No |
| RegVfy32 | X | Regverif32.exe | Added by the SYGYP.A WORM! | No |
| Kinofilmoff.Net | X | Reklamer.exe | Added by the AGENT-NGX TROJAN! | No |
| Launcher | N | relaunch.exe | Audio Applications Launcher for the Philips Rythmic Edge soundcard (the Philips Rhythmic Edge is the same as the Thunderbird PCI soundcard - see TBtray). Available via Start → Programs | No |
| Reload | X | reload.exe | Added by the LAZAR TROJAN! | No |
| reload | X | reload.vbs | Added by the LOVELETTER.AS VIRUS! | No |
| Memory relocation service | X | reloc32.exe | Added by the RELFEERWORM! | No |
| RemHelp | N | Remhelp.exe | BT Voyager ADSL Modem Help related | No |
| B.Reader | N | remin.exe | Birthday Reminder 5.0 - as the name implies | No |
| Scanner Reminder | ? | remind.exe | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon. What does it do and is it required? | No |
| Corel Registration | N | Remind32.exe | If you don't want to register Corel products and be reminded about it every 2 weeks disable it | No |
| Corel Registration Reminder | N | Remind32.exe | If you don't want to register Corel products and be reminded about it every 2 weeks disable it | No |
| Hewlett Packard Recorder | N | Remind32.exe | HP multifunction registration | No |
| HP-Aio Flight | N | Remind32.exe | HP multifunction registration | No |
| Reminder-cpqXXXXX | N | remind32.exe | Compaq printer Registration | No |
| Reminder-hpcXXXXX | N | remind32.exe | HP CD-Writer Registration | No |
| Reminder-ranXXXXX | N | remind32.exe | Registration reminder widget for Rand Mcnally maps | No |
| reminder-ScanSoft Product Registration | N | remind32.exe | Registration reminder for ScanSoft products such as PaperPort | No |
| PC Pitstop Diskmd3 Reminder | N | Reminder-Diskmd3.exe | Registration reminder for Disk MD 3.0 - a disk defragmenter utility from PC Pitstop LLC | Yes |
| PitFrame Module | N | Reminder-Diskmd3.exe | Registration reminder for Disk MD 3.0 - a disk defragmenter utility from PC Pitstop LLC. This is the Vista/7 MSConfig and Windows Defender entry | Yes |
| Reminder-Diskmd3 | N | Reminder-Diskmd3.exe | Registration reminder for Disk MD 3.0 - a disk defragmenter utility from PC Pitstop LLC | Yes |
| PC Pitstop Optimize Reminder | N | Reminder-Optimize3.exe | Registration reminder for Optimize 3.0 - a system optimization utility from PC Pitstop LLC | Yes |
| PitFrame Module | N | Reminder-Optimize3.exe | Registration reminder for Optimize 3.0 - a system optimization utility from PC Pitstop LLC. This is the Vista/7 MSConfig and Windows Defender entry from an earlier release | Yes |
| Reminder-Optimize3 | N | Reminder-Optimize3.exe | Registration reminder for Optimize 3.0 - a system optimization utility from PC Pitstop LLC | Yes |
| PC Matic | N | Reminder-PCMatic.exe | Registration reminder for the PC Matic utility suite from PC Pitstop LLC | Yes |
| PC Pitstop PC Matic Reminder | N | Reminder-PCMatic.exe | Registration reminder for the PC Matic utility suite from PC Pitstop LLC | Yes |
| Reminder-PCMatic | N | Reminder-PCMatic.exe | Registration reminder for the PC Matic utility suite from PC Pitstop LLC | Yes |
| @loha | N | reminder.exe | Registration reminder for @loha@home E-mail utility | No |
| Acer Tour Reminder | N | Reminder.exe | Popup reminder to take the tour of your new Acer laptop | No |
| CreateCD_Reminder | N | reminder.exe | Reminder to create system recovery CD/DVDs on a Sony Vaio laptop or desktop | No |
| Instant Update Center | N | reminder.exe | Event reminder for calendar dates, etc from Broderbund PrintMaster. Disable using the program's own option (if available) or a startup manager as it will re-instate if disabled via MSConfig | No |
| Kana Reminder | N | Reminder.exe | Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time | No |
| PC Pitstop Disk MD | N | Reminder.exe | Registration reminder for Disk MD 2.0 - a disk defragmenter utility from PC Pitstop LLC. Now superseded by Disk MD 3.0. This is the Vista/7 MSConfig and Windows Defender entry | Yes |
| PC Pitstop Optimize Reminder | N | Reminder.exe | Registration reminder for Optimize 2.0 - a system optimization utility from PC Pitstop LLC. Now superseded by Optimize 3.0 | Yes |
| PCPitstop Disk MD Registration Reminder | N | Reminder.exe | Registration reminder for Disk MD 2.0 - a disk defragmenter utility from PC Pitstop LLC. Now superseded by Disk MD 3.0 | Yes |
| PCPitstop Registration Reminder | N | Reminder.exe | Registration reminder for the Exterminate antimalware package from PC Pitstop | No |
| PitFrame Module | N | Reminder.exe | Registration reminder for Optimize 2.0 - a system optimization utility from PC Pitstop LLC. Now superseded by Optimize 3.0. This is the Vista/7 MSConfig and Windows Defender entry | Yes |
| Reminder | N | reminder.exe | From MS Money. Reminds you of your bills | No |
| Reminder | N | Reminder.exe | Registration reminder for Disk MD 2.0 - a disk defragmenter utility from PC Pitstop LLC. Now superseded by Disk MD 3.0. Located in %Program Files%\PCPitstop\Disk MD | Yes |
| Reminder | N | Reminder.exe | Registration reminder for Optimize 2.0 - a system optimization utility from PC Pitstop LLC. Now superseded by Optimize 3.0. Located in %Program Files%\PCPitstop\Optimize2 | Yes |
| Reminder | X | Reminder.exe | Registration reminder for the Secure Expert Cleaner rogue privacy program - see here. Located in %ProgramFiles%\SecureExpertCleaner | No |
| Vinade Reminder | U | Reminder.exe | Vinade Reminder from Vinade Solutions Inc - "With this easy to use reminder tool you can send your reminder to your screen, cell phone, pager, or email. It has a very user friendly interface with an easy to use wizard for creating your reminders" | No |
| Reminder_MUI | ? | Reminder_MUI.exe | File properties show it's by The TechGuys - a PC support service found in Currys, PC Wolrd and Dixons in the UK. What does it do and is it required? | No |
| RemindMe | U | RemindMe.exe | Remind-Me - calendar software | No |
| Remind_XP | N | Remind_XP.exe | HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start → PC Help & Tools → Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list | No |
| Reminder | N | Remind_XP.exe | HP-specific program that reminds users to create System Recovery CDs. Once they use the Recovery CD Creator (Start → PC Help & Tools → Recovery CD Creator) to make the recovery CDs the entry will remove itself from the startup list | No |
| FM | X | Remittance Copy.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData% | No |
| remote master | U | remote master.exe | Required if you want your ASUS Remote control to work at all. Available via Start → Programs | No |
| hotdlll | X | remote.cmd | Added by the BANKER-EHG TROJAN! | No |
| java | X | remote.cmd | Added by the BANKER-EHG TROJAN! | No |
| Remote | U | remote.exe | Watchdog surveillance software. Uninstall this software unless you put it there yourself. Located in %Windir%\Wdc | No |
| Remote | U | Remote.exe | Remote Control driver for LifeView internal and external TV products from Animation Technologies Inc. Typically located in %ProgramFile%\LifeView TVR or %ProgramFile%\TVR | No |
| TvrRemote | U | Remote.exe | Remote Control driver for LifeView internal and external TV products | No |
| Winshell | X | remote.exe | Detected by Trend Micro as WORM_MYTOB.LJ | No |
| Remote_Agent | N | RemoteAgent.exe | Cyberlink's Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start → Programs | No |
| Sistray32 | X | remotehost.pif | Added by the HOLCAS.A WORM! | No |
| PCTVRemote | U | remoterm.exe | Controls the remote control on some Pinnacle TV tuners | No |
| RemoveCpl | N | RemoveCpl.exe | Related to a Belkin 54Mbps Wireless Utility Control Panel applet | No |
| Removed.exe | X | Removed.exe | GatorCheat - adware downloader | No |
| RemoveIT Pro XT | U | removeit.exe | RemoveIT Pro from InCode Solutions - spyware, virus and malware removal tool | No |
| Zonealarm | X | Removeme.exe | Added by the FORBOT-BG WORM! | No |
| Spyware remover | X | Remove_spyware.exe | Unidentified - but not known to belong to any known spyware remover and strongly suspected to be malware related. The file is located in %Windir% | No |
| Windows Update 32 | X | rempss.exe | Detected by Sophos as W32/Forbot-FW and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| RemStart | ? | remstart.exe | Part of McAfee's Remote Desktop 32 Agent application. What does it do and is it required? | No |
| Agente | ? | Remupd.exe | Part of an older version of the Panda Security range of internet security products. Is this an update reminder (guess because of the name), virus definition update reminder or something similar? | No |
| Reon Kadena | X | Reon Kadena.exe | Detected by Dr.Web as Trojan.Peflog.767 and by Malwarebytes Anti-Malware as Trojan.Agent.RK | No |
| MSN Messenger | X | Reosmsngr.exe | Added by a variant of the SPYBOT WORM! | No |
| reouv | X | reouv.exe | Added by the SILLYFDC-FX WORM! | No |
| Repair Registry Pro | X | RepairRegistryPro.exe | Repair Registry Pro rogue registry cleaner - not recommended, removal instructions here | No |
| LAsIAf32 | X | RePEAtLD.exe | Added by the REPEATLD WORM! | No |
| repl | X | repl.exe | Detected by Trend Micro as TROJ_YABE.CD | No |
| Replay Center | U | ReplayRadio.exe | Replay Radio - "makes it easy to automatically record your favorite radio shows, so you can listen wherever and whenever you like" | No |
| replay_telecorder_skype | N | replay_telecorder_skype.exe | Replay Telecorder from Applian Technologies for the Skype VOIP software - which allows you to "record phone calls, video chats, conference calls, voice mail - anything that you can see or hear within Skype" | No |
| RepliGo Assistant | U | RepliGoMon.exe | Cerience RepliGo software - "any document you have on your PC can be transferred to your mobile device" | No |
| [random hex digits] | X | report.exe | Added by the TATANARG TROJAN! | No |
| Remote Registry Service | X | repsvc.exe | Detected by Kaspersky as Backdoor.Win32.IRCBot.ock | No |
| requester | X | requester.*.exe | Added by a variant of the MUQUEST.A TROAN! NOTE: the * stands for a digit, examples: requester.5.exe, requester.10.exe | No |
| Requester | X | requester.11.exe | Added by the MUQUEST TROJAN! | No |
| *resbootdev.exe | X | resbootdev.exe | Added by the AGENT-TTQ TROJAN! | No |
| *rescatacct.exe | X | rescatacct.exe | Added by the FAKEAV-EQX TROJAN! | No |
| ResChanger2004 | U | ResChanger2004.exe | EVGA graphic card utility providing easy access to display settings | No |
| RescueMe | X | rescueme.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%\My UserPrograms | No |
| TrialReseter | X | resetTrial.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %AppData%\Adobe | No |
| Picture Package VCD Maker | U | Residence.exe | Sony "Picture Package®" software for their range of Digital Handycam video cameras. Used to connect the camcorder via USB and allows the user to burn the content directly to a CD | No |
| Remote Event System | X | resmsvc.exe | Added by the IRCBOT.YF BACKDOOR! | No |
| RESpyWare.exe | X | RESpyWare.exe | RESpyWare rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| LoadService | X | Rest In Peace | Added by the KANGAROO-A WORM! | No |
| Data LifeGuard | ? | Restart.exe | Part of the Data LifeGuard diagnostic tools for Western Digital's series of hard drives | No |
| Restore | X | restore.exe | Antispyware Shield Pro rogue security software - not recommended, removal instructions here | No |
| SvcManager | X | restore3.exe | Added by the AGENT-DSS TROJAN! | No |
| crash0001 | X | restorecrashwin32.bat | Added by the AGENT-ZC TROJAN! | No |
| RestoreDesktop | U | RestoreDesktop.exe | Restore Desktop by Softwarium - "is a Windows Context Menu addition that automatically saves and restores the icons' positions on the Windows desktop after a resolution change." No longer available | No |
| restorer32_a | X | restorer32_a.exe | Added by the AGENT.CQQB TROJAN! | No |
| restorer64_a | X | restorer64_a.exe | Added by the DLDR-BY TROJAN! | No |
| restory | X | restory.exe | Added by the RETSAM TROJAN! | No |
| resagnt | X | restun.exe | Adware downloader. Detected by Panda as Downloader.ALQ | No |
| ResumeFixClocks | U | resumefix.exe | Part of the RadeonTweaker utility for overclocking ATI Radeon graphics cards | No |
| Registry Service | X | resvs.exe | Added by the DELBOT-I WORM! | No |
| Mania Win Restore | N | RESWIN.EXE | Pinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start → Programs | No |
| Systam13 | X | resx.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| runner1 | X | retadpu.exe | Added by the AGENT.SLZ TROJAN! | No |
| runner1 | X | retadpu[random digits].exe | Added by the SMALL.CTV TROJAN! | No |
| Wings Server | U | RetailServer.exe | Multi-user retail version of Wings Accounting software from Wings Infonet Ltd | No |
| Wings | U | RetailSingleUser.exe | Single-user retail version of Wings Accounting software from Wings Infonet Ltd | No |
| retime | X | retime.exe | Added by the GIPMA TROJAN! | No |
| RetrieverScheduler | U | retrieverscheduler.exe | 80-20 Retriever from 80-20 - "80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information". Real-time scheduler - shortcut available | No |
| RetroExpress | U | RetroExpress.exe | Retrospect Express backup and recovery software from Retrospect, Inc (was Dantz) - included with some removable drives from Iomega, Western Digital, Maxtor (Seagate) and maybe others | No |
| UPOFRLNV | X | reukdeof.exe | Detected by McAfee as Generic.dx | No |
| kmmsoft | X | revo.exe | Added by the AUTORUN-QR WORM! | No |
| revo | X | revo.exe | Added by the ONLINEG.AFU WORM! | No |
| RevoTaskbarApp | U | RevoTask.exe | Control Panel for the M-Audio Revolution 7.1 sound card. The sound card will function without it - but changes to speaker setup and sound modification (Bass/Treble etc) will not be available | No |
| RexSyMon | N | rexsymon.exe | Intellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC | No |
| rezoqaraxeab | X | rezoqaraxeab.exe | Detected by Sophos as Troj/Cutwail-AH and by Malwarebytes Anti-Malware as Trojan.Ransom.Gen | No |
| RFAgent | U | rfagent.exe | Registry First Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders | No |
| RFCILHKT | X | RFCILHKT.exe | Added by the AGENT-RGM TROJAN! | No |
| Windows-TCP-IP | X | rfkampig.exe | Added by the GIPMA TROJAN! | No |
| RegiFast | X | RFManager.exe | RegiFast adware | No |
| Reality Fusion GameCam SE | N | RFTRay.exe | Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start → Programs | No |
| RFTray | N | RFTRay.exe | Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start → Programs | No |
| rfw | Y | Rfw.exe | Rising firewall | No |
| RfwMain | Y | rfwmain.exe | Rising firewall | No |
| rfwydg | ? | rfwydg.exe | ?? | No |
| Rg2catbd | X | Rg2catbd.exe | Added by a variant of the BANLOAD family of TROJANS! | No |
| Windows ASN Service | X | rge.exe | Added by the RBOT-AOK WORM! | No |
| RGSC | N | RGSCLauncher.exe | Launcher related to the Rockstar Games Social Club | No |
| RGZCDHTN | X | RGZCDHTN.exe | SafeSearch adware | No |
| Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} | X | RH.DLL | SmartPops search hijacker | No |
| RH | U | rh32.exe | EuroFonts - adds Euro symbols to pre-Euro computers | No |
| RhinoBlocker | U | RhinoBlocker.exe | RhinoBlocker - pop-up stopper | No |
| Microsoft IT Update | X | Rhost32.exe | Added by a variant of the IRCBOT TROJAN! | No |
| Microsoft Windows Update | X | rhost32.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| RHPTray | N | RHPTray.exe | System tray access to Red Hot Pawn - online chess | No |
| XtraRichi | U | Richi_Skype_Com.exe | Richi MP3 Ringback Tones extension for the Skype VOIP software - which adds MP3 ringtones and answering machine capabilities | No |
| richup | X | richup.exe | Detected by Symantec as Spyware.SafeSurfing | No |
| rieysha | X | rieysha.exe | Added by the DELF.KG WORM! | No |
| BlackBerryAutoUpdate | N | RIMAutoUpdate.exe | Automatic updates for BlackBerry smartphones, provided by Research In Motion. Run manually when required | No |
| RIMBBLaunchAgent.exe | U | RIMBBLaunchAgent.exe | Research In Motion USB driver agent used when backing up a Blackberry smart phone | No |
| RIMDeviceManager | U | RIMDeviceManager.exe | Device Manager for BlackBerry smartphones, provided by Research In Motion | No |
| Random Interface Network Manager | X | rinsv.exe | Added by the DELBOT-L WORM! | No |
| Riorad Manager | N | riomgr.exe | "Riorad Explorer is hands-down the most advanced Windows software companion for your Rio MP3 player" | No |
| rIOphosIs | X | rIOPHosIs.vBS | Added by the RIOSYS MACRO! | No |
| RIP 2007 Clock | U | RIP 2007 Clock.exe | Clock gadget included with the Rest In Peace theme for MyColors from Stardock Corporation | No |
| RivaTuner | U | RivaTuner.exe | RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for XP and can appear twice - with registry key names of "RivaTuner" and "RivaTunerStartupDaemon" respectively. The former minimizes it to the System Tray and is primarily required only if you want to use the "Launcher" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information | Yes |
| RivaTuner Application | U | RivaTuner.exe | RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for XP and can appear twice - with registry key names of "RivaTuner" and "RivaTunerStartupDaemon" respectively. The former minimizes it to the System Tray and is primarily required only if you want to use the "Launcher" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information | Yes |
| RivaTunerStartupDaemon | U | RivaTuner.exe | Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for XP and applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information | Yes |
| RivaTuner | U | RivaTunerWrapper.exe | RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Windows 7/Vista and can appear twice - with registry key names of "RivaTuner" and "RivaTunerStartupDaemon" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the "Launcher" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information | Yes |
| RivaTunerStartupDaemon | U | RivaTunerWrapper.exe | Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for Windows 7/Vista and loads the main application (RivaTuner.exe) to apply overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information | Yes |
| RivaTunerWrapper Application | U | RivaTunerWrapper.exe | RivaTuner is a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This startup entry is for Windows 7/Vista and can appear twice - with registry key names of "RivaTuner" and "RivaTunerStartupDaemon" respectively. Both load the main application (RivaTuner.exe). The former minimizes it to the System Tray and is primarily required only if you want to use the "Launcher" or monitoring options. The latter applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information | Yes |
| rjfeud | X | rjfeud.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %UserProfile% | No |
| MSConfig | X | rjmbxagf.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| rjuIB55IgyTB | X | rjuIB55IgyTB.exe | Detected by Dr.Web as Trojan.DownLoader8.22321 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| OSS | X | rk.exe | MarketScore parasite - ActiveX control used to download premium-rate diallers | No |
| WindowsRegKey update | X | rkbuouoxfl.exe | Added by the RBOT-OO WORM! | No |
| rkfree | U | rkfree.exe | Revealer Keylogger Free keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| 65438761234587528 | X | rkgnd.exe | ANG AntiVirus 09 rogue security software - not recommended, removal instructions here | No |
| RK Launcher | U | RKLauncher.exe | RK Launcher by RaduKing - "is a free application that will allow the user to have a visually pleasing bar at the side of the screen that is used to quickly launch shortcuts" | No |
| Key1 | X | Rlid.exe | Added by the LIXY TROJAN! | No |
| rlPympjVAQQ.exe | X | rlPympjVAQQ.exe | Added by the FAKEAV-IK MALWARE! | No |
| OSS | X | rlvknlg.exe | MarketScore parasite - ActiveX control used to download premium-rate diallers | No |
| RelevantKnowledge | X | rlvknlg.exe | Marketscore.RelevantKnowledge adware | No |
| Remote Storage Access | X | rmasvc.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Windows Terminal Manager | X | rmbsvc.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| RightMark CPU Clock Utility | U | RMClock.exe | "RightMark CPU Clock Utility (RMClock) is a small GUI application designed for real-time CPU frequency, throttling and load level monitoring and on-the-fly adjustment of the CPU performance level on supported CPU models via processor's power management model-specific registers (MSRs)" | No |
| RMClock | U | RMClock.exe | "RightMark CPU Clock Utility (RMClock) is a small GUI application designed for real-time CPU frequency, throttling and load level monitoring and on-the-fly adjustment of the CPU performance level on supported CPU models via processor's power management model-specific registers (MSRs)" | No |
| RemoteControl | U | rmctrl.exe | Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one | No |
| rmctrl | U | rmctrl.exe | Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one | No |
| Windows Service Agccnt | X | rmizjgz.exe | Added by the SDBOT-SIM WORM! | No |
| RMremote | ? | RmRemote.exe | Remote control driver for REALmagic Xcard. Is it required? | No |
| MicrosoftUpdate | X | rmsm.exe | Detected by Symantec as W32.Barten@mm and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Extender Resource Monitor | N | RMSysTry.exe | Related to Windows Media Center from Microsoft | No |
| Desktop Maestro Vista Tray | N | RMTray.exe | Part of Desktop Maestro from PC Tools - which "combines the features of our award winning products, Registry Mechanic and Privacy Guardian to ensure that you have the range of tools at your fingertips to ensure optimal system performance, stability and user privacy". This entry is created when Desktop Maestro is installed on Vista and loads the System Tray icon (deskmech.exe) on runs a registry scan at startup - if either are enabled. Run manually at regular intervals | Yes |
| DesktopMaestro | N | RMTray.exe | Part of Desktop Maestro from PC Tools - which "combines the features of our award winning products, Registry Mechanic and Privacy Guardian to ensure that you have the range of tools at your fingertips to ensure optimal system performance, stability and user privacy". This entry is created when Desktop Maestro is installed on Vista and loads the System Tray icon (deskmech.exe) on runs a registry scan at startup - if either are enabled. Run manually at regular intervals | Yes |
| Registry Mechanic Vista Tray | N | RMTray.exe | Part of Registry Mechanic from PC Tools - which "is an advanced registry cleaner for Windows that can safely clean, repair and optimize your registry in a few simple mouse clicks!" This entry is created when Registry Mechanic is installed on Vista and loads the System Tray icon (RegMech.exe) and runs a registry scan at startup - if either are enabled. Run manually at regular intervals | Yes |
| RegistryMechanic | N | RMTray.exe | Part of Registry Mechanic from PC Tools - which "is an advanced registry cleaner for Windows that can safely clean, repair and optimize your registry in a few simple mouse clicks!" This entry is created when Registry Mechanic is installed on Vista and loads the System Tray icon (RegMech.exe) and runs a registry scan at startup - if either are enabled. Run manually at regular intervals | Yes |
| DialUp Network Application | X | Rnaap.exe | Added by a variant of W32/Sdbot.worm | No |
| Remote Access | U | rnaapp.exe | Dial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed | No |
| RealPlayer Ath Check | X | rnathchk.exe | Added by the MYTOB.AG WORM! | No |
| Usrr | X | rncr.exe | PurityScan adware | No |
| file laoder configuration | X | rnd32.exe | Detected by Trend Micro as WORM_RBOT.BQJ | No |
| Firevall Administrating | X | rndll.exe | Added by the PUSHBOT-B WORM! | No |
| rndll2 | ? | rndll2.exe | May be related to the DivX program as a *.dat file in the same directory had "DivXPro505Bundle.exe" mentioned within? | No |
| Run DLL | X | rndll32.exe | Added by the IRCBRUT-A TROJAN! | No |
| setupdata | X | rnll32.exe | Added by the QQPASS-AC TROJAN! | No |
| Kgjg | X | rnnypbw.exe | Added by the QuickLinks/Forethought adware | No |
| Zonesoft Cleaner | X | rnsys.exe | Added by a variant of W32/Sdbot.worm | No |
| rnwabmig | X | rnwabmig.exe | Added by the AGENT-LMI TROJAN! | No |
| hhtnsn | X | rnxntup.exe | Added by a variant of the ORCU.B TROJAN! | No |
| sjduwiwx | X | rnxntup.exe | Added by a variant of the ORCU.B TROJAN! | No |
| xibquxs | X | rnxntup.exe | Added by a variant of the ORCU.B TROJAN! | No |
| xmnfuruwk | X | rnxntup.exe | Added by the ORCU.B TROJAN! | No |
| rnxqh | ? | rnxqh.exe | ?? | No |
| Le Petit Robert V3 Hyperappel | U | RobertHA.exe | Allows you to select a word or phrase within a document, application, web-page, etc and search for it within the "Le Petit Robert" French dictionary from Le Robert. See here for more information | No |
| robmob | X | robmob.exerobmob.exeminer.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\robmob | No |
| robmob | X | robmob.exerobmobslaves.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\robmob | No |
| RoboFormWatcher | N | RoboFormWatcher.exe | Roboform from Siber Systems. Automatically completes web forms. Available via Start → Programs | No |
| RoboForm | N | RoboTaskBarIcon.exe | Roboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin | No |
| robqaddubuzy | X | robqaddubuzy.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| RocketDock | N | RocketDock.exe | "RocketDock is a smoothly animated, alpha blended application launcher. It provides a nice clean interface to drop shortcuts on for easy access and organization" | No |
| Rocket.Time | U | RocketTime.exe | Rocket.Time - time synchronization software from Rocket Software | No |
| RockMelt Update | N | RockMeltUpdate.exe | Automatic updates for the RockMelt browser - which "is providing a fundamentally better Web experience by re-imagining the browser around how you use the internet today" | No |
| ROC_roc_dec12 | Y | ROC_roc_dec12.exe | Part of AVG Secure Search which "alerts you before you visit dangerous webpages to make sure your identity, personal information, and computer are protected" | No |
| ROC_roc_ssl_v12 | Y | ROC_roc_ssl_v12.exe | Part of AVG Secure Search which "alerts you before you visit dangerous webpages to make sure your identity, personal information, and computer are protected" | No |
| RogersAgent | U | rogersagent.exe | "Rogers Self Help Software is a free suite of tools and utilities for your computer that keeps your system running properly, and makes your Hi-Speed Internet experience smooth and trouble-free" | No |
| RogersServicepointAgent.exe | Y | RogersServicepointAgent.exe | Rogers Servicepoint Agent tool installed when you choose to install their Online Protection internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | No |
| Malwarebytes' RogueRemover PRO | Y | RogueRemoverPRO.exe | Part of Malwarebytes' RogueRemover PRO - the realtime "RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs." Now discontinued and the funtionality is included in Malwarebytes Anti-Malware | Yes |
| RogueMonitor | Y | RogueRemoverPRO.exe | Part of Malwarebytes' RogueRemover PRO - the realtime "RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs." Now discontinued and the funtionality is included in Malwarebytes Anti-Malware | Yes |
| RogueRemoverPRO | Y | RogueRemoverPRO.exe | Part of Malwarebytes' RogueRemover PRO - the realtime "RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs." Now discontinued and the funtionality is included in Malwarebytes Anti-Malware | Yes |
| Rollback | U | RollbackTray.exe | Added by the RollBack Rx system restore program | No |
| Ronda | X | Ronda.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Fynloski. The file is located in %AppData% | No |
| rundll32 | X | rookie.vbs | Added by the ROOKIE-A TROJAN! | No |
| DevicePath | X | Root.exe | Added by the GRUEL WORM! | No |
| MediaPath | X | Root.exe | Added by the GRUEL WORM! | No |
| Rundll32.exe | X | Root.exe | Added by the GRUEL WORM! | No |
| Root System Service | X | rootsvc32.exe | Added by the AUTORUN-BGZ WORM! | No |
| Registry Value Name | X | roses.exe | Added by the RBOT-AFT WORM! | No |
| RosTika | X | RosTika.exe | Added by the BRONTOK-BU WORM! | No |
| ROUTD | ? | ROUTD.exe | ?? | No |
| Microsoft Router Manager | X | router.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Router | X | Router.exe | Added by the AGENT.FJN TROJAN! | No |
| CryptLoad | N | RouterClient.exe | CryptLoad download manager | No |
| Easy CD Creator | N | RoxAssist.exe | Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If this doesn't happen you may have to add support for newer drives using Roxio Updater, check for product updates and even re-install the software. See this thread for more information | Yes |
| RoxAssist | N | RoxAssist.exe | Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If this doesn't happen you may have to add support for newer drives using Roxio Updater, check for product updates and even re-install the software. See this thread for more information | Yes |
| RoxAssistant | N | RoxAssist.exe | Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If this doesn't happen you may have to add support for newer drives using Roxio Updater, check for product updates and even re-install the software. See this thread for more information | Yes |
| Desktop Disc Tool | N | RoxioBurnLauncher.exe | Background process installed with Roxio Creator multimedia suites. Monitors your optical drive and launches the main Roxio Burn (Roxio Burn.exe) desktop tool when blank media or media containing data is inserted | Yes |
| Roxio Burn | N | RoxioBurnLauncher.exe | Background process installed with Roxio Creator multimedia suites. Monitors your optical drive and launches the main Roxio Burn (Roxio Burn.exe) desktop tool when blank media or media containing data is inserted | Yes |
| RoxioBurnLauncher | N | RoxioBurnLauncher.exe | Background process installed with Roxio Creator multimedia suites. Monitors your optical drive and launches the main Roxio Burn (Roxio Burn.exe) desktop tool when blank media or media containing data is inserted | Yes |
| RoxWatchTray | N | RoxWatchTray.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 8 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher (RoxWatch)" service as well as the combination has been known to use significant amount of memory and cause other problems | No |
| RoxWatchTray | N | RoxWatchTray10.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 10 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 10 (RoxWatch10)" service as well as the combination has been known to use significant amount of memory and cause other problems | No |
| RoxWatchTray10 | N | RoxWatchTray10.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 10 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 10 (RoxWatch10)" service as well as the combination has been known to use significant amount of memory and cause other problems | No |
| RoxWatchTray | N | RoxWatchTray11.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 2009 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 11 (RoxWatch11)" service as well as the combination has been known to use significant amount of memory and cause other problems | No |
| RoxWatchTray11 | N | RoxWatchTray11.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 2009 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 11 (RoxWatch11)" service as well as the combination has been known to use significant amount of memory and cause other problems | No |
| RoxWatchTray | N | RoxWatchTray12.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Creator multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 12 (RoxWatch12)" service as well as the combination has been known to use significant amount of memory and cause other problems | No |
| RoxWatchTray12 | N | RoxWatchTray12.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Creator multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 12 (RoxWatch12)" service as well as the combination has been known to use significant amount of memory and cause other problems | No |
| CommonSDK | N | RoxWatchTray12OEM.exe | On the full version of the product this provides System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Creator multimedia suite - see the entry for RoxWatchTray (RoxWatchTray12.exe). This is the OEM version installed by various PC manufacturers (also known as Roxio Creator Starter) and these features are not available without an upgrade. Also disable the associated "Roxio Hard Drive Watcher 12 (RoxWatch12)" service as well | Yes |
| RoxWatchTray | N | RoxWatchTray12OEM.exe | On the full version of the product this provides System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Creator multimedia suite - see the entry for RoxWatchTray (RoxWatchTray12.exe). This is the OEM version installed by various PC manufacturers (also known as Roxio Creator Starter) and these features are not available without an upgrade. Also disable the associated "Roxio Hard Drive Watcher 12 (RoxWatch12)" service as well | Yes |
| RoxWatchTray12OEM | N | RoxWatchTray12OEM.exe | On the full version of the product this provides System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Creator multimedia suite - see the entry for RoxWatchTray (RoxWatchTray12.exe). This is the OEM version installed by various PC manufacturers (also known as Roxio Creator Starter) and these features are not available without an upgrade. Also disable the associated "Roxio Hard Drive Watcher 12 (RoxWatch12)" service as well | Yes |
| RoxWatchTray | N | RoxWatchTray13.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Creator multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 13 (RoxWatch13)" service as well as the combination has been known to use significant amount of memory and cause other problems | No |
| RoxWatchTray13 | N | RoxWatchTray13.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Creator multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 13 (RoxWatch13)" service as well as the combination has been known to use significant amount of memory and cause other problems | No |
| CommonSDK | N | RoxWatchTray9.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 9 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 9 (RoxWatch9)" service as well as the combination has been known to use significant amount of memory and cause other problems | Yes |
| RoxWatchTray | N | RoxWatchTray9.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 9 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 9 (RoxWatch9)" service as well as the combination has been known to use significant amount of memory and cause other problems | Yes |
| RoxWatchTray9 | N | RoxWatchTray9.exe | System Tray access to managing the "Watched Folders", "LiveShares" and "MediaSpace" features of the Roxio Easy Media Creator 9 multimedia suite. All of these options are available from the Media Manager utility. The "Watched Folders" feature monitors specified locations for new pictures, songs and videos being added and makes them available to the Media Manager - if you have 512MB of memory or less available it's recommended you also disable the associated "Roxio Hard Drive Watcher 9 (RoxWatch9)" service as well as the combination has been known to use significant amount of memory and cause other problems | Yes |
| startkey | X | royale.exe | Added by a variant of W32/Sdbot.worm | No |
| RP32 | U | rp32.exe | Unicenter Remote Control (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems | No |
| Remote Procedure Call For Windows 32bit | X | rpc.exe | Added by the RBOT-MD WORM! | No |
| RPC Drivers | X | rpcall.exe | Added by the SDBOT.FLY WORM! | No |
| rpcc | X | rpcc.exe | Added by the SPAMMIT-E TROJAN! | No |
| WindowsHive | X | rpcc.exe | Added by the DLENA-A TROJAN! | No |
| rpcda Win32 | X | rpcda.exe | Added by the RBOT-AEE WORM! | No |
| Config Loader | X | rpcfix.exe | Added by the AGOBOT-R BACKDOOR! | No |
| Generic Host Process for Win32 Service | X | rpchost.exe | Added by the IRCBOT.DCN WORM! | No |
| roketpipe | ? | rpclient.exe | ?? | No |
| Sysmon | X | rpcmon.exe | Added by the RANDEX.ATX WORM! | No |
| RPC System Service | X | rpcss.exe | Detected by Malwarebytes Anti-Malware as Trojan.Logger.NR. Note - this should not be confused with the legitimate Remote Procedure Call (RPC) service which uses the svchost.exe process to load RpcSs.dll and the file is located in %System% | No |
| RPCSS.exe | Y | rpcss.exe | Remote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here | No |
| System Setup | X | rpcxcmod.exe | Added by an unidentified WORM or TROJAN! | No |
| MSVsmt | X | rpcxctx.exe | Added by an unidentified WORM or TROJAN! | No |
| Rpcx Intelligent Security | X | rpcxis.exe | Detected by Trend Micro as WORM_AGOBOT.ACN | No |
| WSAConfiguration | X | rpcxmn32.exe | Added by the AGOBOT.ABG WORM! | No |
| Social Security Agency | X | rpcxsocsa.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Microsoft Windows Key | X | rpcxsys.exe | Detected by Trend Micro as WORM_AGOBOT.AAK | No |
| UserInit StartUp | X | rpcxuisu.exe | Added by a variant of W32/Sdbot.worm | No |
| Microsoft Windows Secure Server | X | rpcxWindows.exe | Detected by Sophos as W32/Rbot-LL | No |
| RpcxWindows Extensions | X | rpcxwinex.exe | Detected by Trend Micro as WORM_RBOT.ACP | No |
| Microsoft Windows Secure Update | X | rpcxwinupdt.exe | Added by an unidentified WORM or TROJAN! | No |
| windowsupdate | X | RPC[RANDOM CHARACTERS].exe | Added by the IRCBOT.B TROJAN! | No |
| RpdcServ | X | RpdcServ.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%\Subset | No |
| Usrr | X | rpen.exe | PurityScan adware | No |
| rpga | X | rpgchk.exe | Detected by McAfee as Generic.tfr | No |
| RapidGet | X | RPGManager.exe | Detected by McAfee as Generic.tfr | No |
| Remote Access Monitor | X | rpgsvc.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| rpmvpqbfvfjhgtecquj | X | rpmvpqbfvfjhgtecquj.exe | Detected by Dr.Web as Trojan.DownLoader6.36532 | No |
| Aliant Security Services | Y | Rps.exe | Main program for the Aliant Security Services internet security suite for Bell Aliant ISP customers - sourced by Radialpoint | No |
| AT&T Internet Security Suite | Y | Rps.exe | Main program for the AT&T Internet Security Suite for AT&T ISP customers - sourced by Radialpoint | No |
| Centinela ONO | Y | Rps.exe | Main program for the Centinela ONO Security Services internet security suite for ONO ISP customers - sourced by Radialpoint | No |
| Freedom | Y | Rps.exe | Main program for internet security suites by Radialpoint. Radialpoint also source online security services for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online | No |
| Gestionnaire de sécurité Sympatico | Y | Rps.exe | Main program for the Bell Security Manager internet security suite for Bell Canada ISP customers - sourced by Radialpoint | No |
| ntl Netguard | Y | RPS.exe | Main program for the ntl Netguard internet security package for NTL ISP customers - sourced by Radialpoint. Now superseded by Virgin Media Security - which is also sourced by Radialpoint | No |
| Pcguard | Y | Rps.exe | Main program for the PC Guard internet security package for Virgin Media ISP customers - sourced by Radialpoint. Now superseded by Virgin Media Security - which is also sourced by Radialpoint | Yes |
| Radialpoint Security Services | Y | Rps.exe | Main program for internet security suites by Radialpoint. Radialpoint also source online security services for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online | No |
| Rps | Y | Rps.exe | Main program for internet security suites sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online | Yes |
| Security Manager | Y | Rps.exe | Main program for the Bell Security Manager internet security suite for Bell ISP customers - sourced by Radialpoint | No |
| Services de sécurité Vidéotron | Y | Rps.exe | Main program for the Vidéotron Security Services internet security suite for Vidéotron ISP customers - sourced by Radialpoint | No |
| Sympatico Security Manager | Y | Rps.exe | Main program for the Sympatico Security Manager internet security suite for Bell Canada ISP customers - sourced by Radialpoint | No |
| TELUS eProtect | Y | Rps.exe | Main program for the TELUS eProtect internet security suite for TELUS ISP customers - sourced by Radialpoint | No |
| Verizon Internet Security Suite | Y | Rps.exe | Main program for the Verizon Internet Security Suite for Verizon ISP customers - sourced by Radialpoint | No |
| RPSP | U | Rpsserv32.exe | Red Pill Spy surveillance software. Uninstall this software unless you put it there yourself | No |
| ReleaseRAM | U | RRAM.exe | "Release RAM allows your computer to run faster and uses your computer's RAM more efficiently" | No |
| RRE Start | X | RRE.exe | Detected by Dr.Web as Trojan.Siggen2.46206 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| RRMedic | X | rrmedic.exe | Troubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection | No |
| Windows LoL Layer | X | rrntsbq.exe | Added by the BIFROSE.DPOA BACKDOOR! | No |
| Rapid Restore | U | rrpcsb.exe | XPoint "Rapid Restore PC" - "a Managed Recovery solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user" | No |
| Osus | X | rrup.exe | PurityScan adware | No |
| AdobeReaderPro | X | rruxdkf.exe | Added by the RBOT.ADF BACKDOOR! | No |
| rs32net | X | rs32net.exe | Detected by Sophos as Troj/Agent-IFH | No |
| arjtqhalyp | X | rsacir.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| [random characters] | X | rsbmsc.exe | Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN! | No |
| Rscmpt | U | Rscmpt.exe | Required on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status | No |
| (Default) | X | rsddoser.exe | Detected by Microsoft as PWS:MSIL/Petun.A. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| Red Swoosh EDN Client | U | RSEDNClient.exe | Red Swoosh distributed networking software - a desktop client that enables users to download and stream files from each other, rather than from webservers. Now superseded by the Akamai NetSession Interface download manager which is used by companies such as Adobe and Corel to download and install their online products. Required for the download to start and complete but once finished it can be disabled and re-instated at a later date if needed | No |
| (Default) | X | RSEpicbot2007.exe | Detected by Malwarebytes Anti-Malware as Trojan.Clicker. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %UserProfile%\Start Menu\Programs | No |
| Microsoft Server | X | rserv.exe | Detected by Trend Micro as WORM_AGOBOT.AVS | No |
| Synchronization Manager | X | rservers.exe | Added by the FORBOT-FM WORM! | No |
| rsmb | X | rsmb.exe | Added by the WAREZOV.C WORM! | No |
| rsmb32 | X | rsmb32.exe | Added by the STRATION.AV WORM! | No |
| Enterprise Harmony | U | rsMenu.exe | Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000 | No |
| Enterprise Harmony '99 | U | rsMenu.exe | Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000 | No |
| Randsoft Harmony '98 | U | rsMenu.exe | Randsoft Harmony '98 (superseded by Enterprise Harmony 99) for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000 | No |
| rsMenu | U | rsMenu.exe | Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000. Formally Randsoft Harmony '98 | No |
| Resource Meter | N | rsrcmtr.exe | Windows Resource Meter. Available via Start → Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes | No |
| RSRCMTZ | ? | RSRCMTZ.exe | ?? | No |
| VgaDriver | X | RsrVga32.exe | Added by the KEYLOG-AH TROJAN! | No |
| rsrvmon.exe | X | rsrvmon.exe | Added by the AGENT.NY TROJAN! | No |
| RssReader | U | RssReader.exe | RssReader - a free RSS reader able to display any RSS and Atom news feed (XML) | No |
| WinFix service | X | rsswjzgp.exe | Added by the RBOT-FAE WORM! | No |
| Random Interface Network | X | rst.exe | Added by the DELBOT-P WORM! | No |
| SCISound | X | rstray.exe | Detected by Kaspersky as Trojan-Spy.Win32.KeyLogger.cpn and by Malwarebytes Anti-Malware as Trojan.Keylogger.OL | No |
| *Restore | Y | rstrui.exe | Part of Windows System Restore and added as a RunOnce registry entry. Leave alone | No |
| SystemRestore | X | rstrui_w.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %Windir% | No |
| RSV Start | X | RSV.exe | Detected by Malwarebytes Anti-Malware as Trojan.Ardamax. The file is located in %System%\KIRKSW | No |
| MSN UPDATER | X | RSVC32.EXE | Added by the RBOT-HW WORM! | No |
| Network Administration Service | X | rsvc32.exe | Added by the RBOT.ABH WORM! | No |
| rsvp | X | rsvp.exe /waitservice | Detected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate rsvp.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers | No |
| Remote Access Domain | X | rswsvc.exe | Added by the IRCBOT.BFA TROJAN! | No |
| rtasks | X | rtasks.exe | Part of rogue software including members of the AVSystemCare security suite family (see here for examples), WinAntiVirus Pro 2006 and WinAntiVirus Pro 2007 | No |
| rtcdll | U | rtcdll.exe | RTCDLL is "Real Time Communication" and is associated with Windows Messenger (the IM application, not messenger service). It is only necessary if you use Windows Messenger. Most people use MSN Messenger instead, so it is not required in those cases | No |
| startkey | X | rtfmsv.exe | Added by the EDEPOL-C TROJAN! | No |
| Realtek HD Audio Sound Effect Manager | U | RTHDCPL.EXE | Realtek HD Audio Control Panel, installed with the XP/2K drivers for on-board Realtek HD audio codecs. Provides a default (but optional) System Tray icon which allows you to manage audio device settings and gives you access to the Sound Manager and other multimedia functions. You will also receive notifications when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | Yes |
| RTHDCPL | U | RTHDCPL.EXE | Realtek HD Audio Control Panel, installed with the XP/2K drivers for on-board Realtek HD audio codecs. Provides a default (but optional) System Tray icon which allows you to manage audio device settings and gives you access to the Sound Manager and other multimedia functions. You will also receive notifications when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | Yes |
| RtHDVBg | ? | RtHDVBg.exe | Installed with the 32-bit 7/Vista drivers for on-board Realtek HD audio codecs. The exact purpose is unknown at present | No |
| HD Audio Control Panel | U | RtHDVCpl.exe | Realtek HD Audio Manager, installed with the 32-bit 7/Vista drivers for on-board Realtek HD audio codecs. Provides a default (but optional) System Tray icon which allows you to manage audio device settings and gives you access to the Sound Manager and other multimedia functions. You will also receive notifications when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | Yes |
| Realtek HD Audio Manager | U | RtHDVCpl.exe | Realtek HD Audio Manager, installed with the 32-bit 7/Vista drivers for on-board Realtek HD audio codecs. Provides a default (but optional) System Tray icon which allows you to manage audio device settings and gives you access to the Sound Manager and other multimedia functions. You will also receive notifications when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | Yes |
| Realtek Semiconductor | X | RtHDVCpl.exe | Detected by Sophos as Troj/FakeAV-FYI and by Malwarebytes Anti-Malware as Worm.Dorkbot. Note that this is the valid Realtek HD Audio Manager process which shares the same filename as is located in %ProgramFiles%\Realtek\Audio\HDA. This one is located in %Windir% | No |
| RtHDVCpl | U | RtHDVCpl.exe | Realtek HD Audio Manager, installed with the 32-bit 7/Vista drivers for on-board Realtek HD audio codecs. Provides a default (but optional) System Tray icon which allows you to manage audio device settings and gives you access to the Sound Manager and other multimedia functions. You will also receive notifications when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | Yes |
| msMGR | X | rtkmsg.exe | Added by the SDBOT-BPY WORM! | No |
| Realtek HD Audio Manager | U | RtkNGUI.exe | Realtek HD Audio Manager, installed with the 32-bit 7/Vista drivers for on-board Realtek HD audio codecs. Manages audio device settings and gives you notifications (if enabled) when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | No |
| RTHDVCPL | U | RtkNGUI.exe | Realtek HD Audio Manager, installed with the 32-bit 7/Vista drivers for on-board Realtek HD audio codecs. Manages audio device settings and gives you notifications (if enabled) when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | No |
| Realtek HD Audio Manager | U | RtkNGUI64.exe | Realtek HD Audio Manager, installed with the 64-bit 7/Vista drivers for on-board Realtek HD audio codecs. Manages audio device settings and gives you notifications (if enabled) when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | No |
| RTHDVCPL | U | RtkNGUI64.exe | Realtek HD Audio Manager, installed with the 64-bit 7/Vista drivers for on-board Realtek HD audio codecs. Manages audio device settings and gives you notifications (if enabled) when devices are plugged into and removed from the jacks (such as headphones and a microphone). In some cases, if this is not running when such a device is plugged it it may not be detected and therefore may not work | No |
| rtl.exe | X | rtl.exe | Added by the TIOTUA-J TROJAN! | No |
| RtlAudio | X | RtlAudio.exe | Added by the GRAYBIR-U TROJAN! | No |
| 00401C6XX500 | X | RTLCPL.exe | Detected by McAfee as PWS-Zbot.gen.zy and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| 4M6002Y7G4C2 | X | RTLCPL.exe | Detected by McAfee as PWS-Zbot.gen.zy and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| FF4NJ6C2IIND | X | RTLCPL.exe | Detected by McAfee as PWS-Zbot.gen.zy and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| [various names] | X | RtlFindVal.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| RtlMon.exe | N | RtlMon.exe | Monitor for RealTek network card | No |
| WG111v2 Smart Wizard Wireless Setting | U | RtlWake.exe | Netgear WG111 54 Mbps Wireless-G USB Adapter configuration utility | No |
| RTMonitor | Y | RTMonitor.exe | Real-time monitor for Cheyenne AntiVirus - acquired by CA and no longer available | No |
| rtos | X | rtos.exe | IRC trojan | No |
| Remote Terminal Task | X | rtsbsvc.exe | Added by the IRCBOT.AUZ BACKDOOR! | No |
| ertyuop | X | rttrwq.exe | Added by the AUTORUN-APA WORM! | No |
| Microsoft | X | rtvcscan.exe | Added by the RBOT-GGU WORM! | No |
| RtkOSD | ? | RtVOsd.exe | Installed with the 32-bit 7/Vista drivers for on-board Realtek HD audio codecs. The exact purpose is unknown at present but based upon the filename it may be used to provide on-screen volume level changes | No |
| RtkOSD | ? | RtVOsd64.exe | Installed with the 64-bit 7/Vista drivers for on-board Realtek HD audio codecs. The exact purpose is unknown at present but based upon the filename it may be used to provide on-screen volume level changes | No |
| rtvscn95 | Y | RTVSCN95.EXE | Real-time virus scanner component of Norton Anti-Virus Corporate Edition | No |
| AirLive WL1600USB Wireless Lan Utility | U | RtWLan.exe | Air Live WL1600USB Wireless USB Adapter configuration utility (based upon a Realtek chipset) | No |
| AirLive WL-1700USB Wireless Lan Utility | U | RtWLan.exe | Air Live WL-1700USB Long Distance Wireless USB Adapter configuration utility (based upon a Realtek chipset) | No |
| AirLive WL-5480USB WLAN USB Utility | U | RtWLan.exe | Air Live WL-5480USB Wireless USB Adapter configuration utility (based upon a Realtek chipset) | No |
| AWUS036H Wireless LAN Utility | U | RtWLan.exe | Alfa AWUS036H Wireless LAN USB adapter configuration utility (based upon a Realtek chipset) | No |
| Edimax 11n USB Wireless LAN Utility | U | RtWLan.exe | Edimax Wireless USB Adapter configuration utility (based upon a Realtek chipset) | No |
| Micronet SP907GK Wireless Network Utility | U | RtWLan.exe | Micronet SP907GK Wireless LAN USB Adapter configuration utility (based upon a Realtek chipset) | No |
| Micronet Wireless Network Utility | U | RtWLan.exe | Micronet wireless network configuration utility (based upon a Realtek chipset) | No |
| REALTEK RTL8185 Wireless LAN Utility | U | RtWLan.exe | wireless LAN configuration utility for Realtek RTL8185 chipsets built in to some computers | No |
| REALTEK RTL8187 Wireless LAN Utility | U | RtWLan.exe | wireless LAN configuration utility for Realtek RTL8187 chipsets built in to some computers | No |
| REALTEK RTL8187SE Wireless LAN Utility | U | RtWLan.exe | wireless LAN configuration utility for Realtek RTL8187SE chipsets built in to some computers | No |
| RtWLan | U | RtWLan.exe | Netgear WG111 54 Mbps Wireless-G USB Adapter configuration utility (based upon a Realtek chipset) | No |
| TP-LINK Wireless Utility | U | RtWLan.exe | TP-LINK Wireless configuration utility (based upon a Realtek chipset) | No |
| Quicktlme | X | ru.exe | QuickPage - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-A TROJAN! | No |
| RubeL | X | RubeL.exe | Added by the RUBY-B TROJAN! | No |
| LIU | N | Rubicon.exe | Logitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway | No |
| Ruby13 | X | Ruby13.exe | Added by the MEXER.E WORM! | No |
| Ruby14 | X | Ruby14.exe | Added by the FIGHTRUB-A WORM! | No |
| rubymeafarca | X | rubymeafarca.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% | No |
| Showme | X | Ruden.vbs | Added by the HANDLE-A VIRUS! | No |
| McAfee.InstantUpdate.Monitor | U | RuLaunch.exe | Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis | No |
| RuLaunch | U | RuLaunch.exe | Instant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis | No |
| run.exe | X | run.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.RNGen. The file is located in %Temp% - see here | No |
| runs | X | run.exe | Added by the RBOT-BWF WORM! | No |
| sc | U | run.exe | All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file | No |
| SPP | ? | run.exe | ?? | No |
| Windows | X | run.exe | Added by the SPYBOT.OFN WORM! | No |
| cg | U | run.vbs | Detected by Malwarebytes Anti-Malware as PUP.BitCoinMiner and associated with Bitcoin. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\cg. Remove unless you installed it yourself | No |
| Run32.dll | X | Run32.exe | Detected by Sophos as Troj/VB-FLO and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| run32.exe | X | run32.exe | Detected by Malwarebytes Anti-Malware as Trojan.AutoIt. The file is located in %Temp% | No |
| system | X | run32.exe | Detected by Malwarebytes Anti-Malware as Trojan.AutoIt. The file is located in %Temp% | No |
| Windows Executable | X | run32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System% | No |
| System | X | run322.exe | Added by the LANFILT TROJAN! | No |
| klp | U | run32dll.exe | PAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online | No |
| run32 | X | run32dll.exe | Added by the SDBOT-CWB WORM! | No |
| winstro | X | RUN32DLL.exe | Added by the FTP_ANA TROJAN! | No |
| adsmini | X | runadsmini.exe | Detected by Dr.Web as Trojan.DownLoader7.20916 and by Malwarebytes Anti-Malware as Trojan.DownLoader | No |
| Introduction-Registration | N | RUNALL.EXE | For Compaq PC's. Should only run on first use for PC Introduction and Compaq registration | No |
| runAP | N | runAP.exe | Not required but what is it? | No |
| runAPI68 | X | runAPI35.exe | Detected by Dr.Web as Trojan.Inject.57495 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| runAPI78 | X | runAPI47.exe | Added by the MDROP-DRE TROJAN! | No |
| runAPI83 | X | runAPI68.exe | Detected by McAfee as Generic.bfr!ei and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| runAPI35 | X | runAPI82.exe | Added by the MSILDYN-C MALWARE! | No |
| runAPI35 | X | runAPI92.exe | Detected by Dr.Web as Trojan.Siggen3.5133 and by Malwarebytes Anti-Malware as Trojan.Agent.ND | No |
| Microsoft Dll | X | runapidll.exe | Added by the RBOT-GRG WORM! | No |
| Runapp32 | X | Runapp32.exe | Added by the NEODURK TROJAN! | No |
| AlfaAntivirus | X | runbst.exe | AlfaAntiVirus rogue security software - not recommended | No |
| Taskbell.exe | X | Rund1.exe | Added by the YIPID TROJAN! | No |
| Rund11 | X | Rund11.EXE | Added by the MARIO-C WORM! | No |
| Avptask | X | rund1132.exe | Added by the AGENT.PKZ TROJAN! | No |
| Ravshell | X | rund1132.exe | Added by the AGENT.OKZ TROJAN! | No |
| ravtask | X | rund1132.exe | Added by the DLOADER.IYT TROJAN! | No |
| rund1132 | X | rund1132.exe | Added by the DOPBOT-A WORM! | No |
| Rund1132.exe | X | Rund1132.exe | Added by the STARTPA-HS TROJAN! | No |
| sys001 | X | rund1132.exe | Added by the SMALL-DLD TROJAN! | No |
| Tencent QQ | X | Rund1132.exe qq.dll,Rundll32 | Added by the QQPASS.F TROJAN! | No |
| runddlfile | X | runddl.exe | Detected by Kaspersky as Trojan-PSW.Win32.Delf.d | No |
| Local Service | X | runddl32.exe | Added by the RBOT.ACJ WORM! | No |
| Rundll32 | X | RUNDDLL32.EXE | Added by the STARTPAGE.AXH TROJAN! | No |
| SysDeskqqfx | X | Runddll32.exe | Added by the CHANGGAME TROJAN! | No |
| Windows AutomaticUpdater | X | runddls.exe | Added by a variant of Win32/Rbot | No |
| Windows Explorer | X | RundII.exe | Detected by Trend Micro as WORM_WOOTBOT.BX | No |
| filename process | X | Rundil16.exe | Added by the GAOBOT.ZX WORM! | No |
| ctfnom | X | rundIl32.exe | Detected by Sophos as Troj/LegMir-AW and by Malwarebytes Anti-Malware as Backdoor.Agent. Note that the letter after the "d" in the filename is an upper case "i" | No |
| LoadPowerProfile | X | rundl.exe | Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll | No |
| RUN DLL | X | rundl1.exe | Detected by McAfee as Downloader-MX and by Malwarebytes Anti-Malware as Trojan.Downloader.MH | No |
| PowerPrifile | X | rundl132 kenel.dll,PowerProfileEnable | Added by the INMOTA WORM! | No |
| load | X | rundl132.exe | Added by the LOOKED-CK WORM! | No |
| ryy | X | rundl132.exe | Added by the PWS-ANA TROJAN! | No |
| [random name] | X | rundl13a.exe | Added by the GAMPASS-L TROJAN! | No |
| NvCpl | X | rundl32.exe | Added by the AGOBOT-TO WORM! Note - the valid version of this entry has the command line as "rundll32.exe NvCpl.dll,NvStartup" | No |
| RUNDLL32 | X | rundl32.exe | Added by the DEMOTRY-A WORM! | No |
| startwindowskeyuser | X | rundle2.exe | Detected by Symantec as W32.JavaKiller.Trojan | No |
| LTM2 | X | RundlI.exe | Added by the MULTIDRP.BG TROJAN! | No |
| rundli32 | X | rundli32.exe | Added by the LADE WORM! | No |
| Windows TM | X | rundlI32.exe | Detected by Microsoft as Backdoor:Win32/Rbot.EL | No |
| Captcha7 | X | rundll captcha.dll | Added by the TINY.WRE TROJAN! | No |
| Taskbar Display Controls | N | RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY | Only appears in MSCONFIG if you have a Display Settings icon in the System Tray allowing resolution changes on the fly. Can also be disabled under Control Panel → Display → Settings → Advanced → General. Also appears if you have Win95 with the QuickRes "Powertoy" installed | No |
| DNE Binding Watchdog | Y | rundll dnes.dll,DnDneCheckBindings | Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work | No |
| DNE DUN Watchdog | Y | rundll dnes.dll,DnDneCheckDUN13 | Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work | No |
| @ | X | RUNDLL.EXE | Added by the SPYBOT-DN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| Microsoft | X | rundll.exe | Added by the RBOT-GSJ WORM! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| Microsoft Service | X | rundll.exe | Added by the POPO-A WORM! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| MSTray | X | rundll.exe | Added by the BAMER-B TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| recover.bmp.exe | X | Rundll.exe | Detected by Sophos as Troj/AnaFTP-01. Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| RegistryConfig | X | rundll.exe | Added by the AGOBOT-KN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| RunDll | X | RunDll.exe | Added by the QQPASS-AH TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| RunDLL Kernel File Core | X | rundll.exe | Added by a variant of the RBOT WORM! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| RundllSvr | X | Rundll.exe | Added by the HUAYU WORM! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| Win32 USB Driver | X | rundll.exe | Added by the FORBOT-BN WORM! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| Windows Config | X | RUNDLL.EXE | Added by the SPYBOT-DX WORM! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| Windows Firevall Control C | X | rundll.exe | Detected by Microsoft as Backdoor:Win32/Gaertob.A and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Windows Firevall Control Center | X | rundll.exe | Detected by Kaspersky as Trojan.Win32.Buzus.clef and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Windows Upate | X | rundll.exe | Added by the HAKO TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| Windows32 | X | rundll.exe | Added by the AGOBOT-LK or AGOBOT-ND WORMS! Note - this is NOT the Win9x/Me system file of the same name as described here | No |
| LoadPowerProfile | X | Rundll.exe powerprof.dll | Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses "Rundll.exe" whereas the uninfected version uses "Rundll32.exe" | No |
| clnwall | ? | rundll.exe setupx.dll,InstallHinfSection ..delwall.inf | ?? | No |
| LLMODCL2 | ? | rundll.exe setupx.dll,InstallHinfSection ..LLMODCL2.INF | ?? | No |
| AAACLEAN | ? | rundll.exe setupx.dll,InstallHinfSection AAACLEAN.INF | ?? | No |
| AAAKeyboard | ? | rundll.exe setupx.dll,InstallHinfSection KBDCLEAN.INF | ?? | No |
| ZIBMACC | U | rundll.exe setupx.dll,InstallHinfSection ZIBMACC.INF | ZIBMACC.INF is an IBM file that is only loaded and installed under a recovery operation. The file is a support file for IBM access to the system if needed. You may delete this file. This is as from IBM Technical Support (USA - 800-887-7435) | No |
| Sound | X | rundll1.exe | Detected by Dr.Web as Trojan.DownLoader8.12938 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Windows Running DLL Service | X | rundll128.exe | Added by the IRCBOT.XDH BACKDOOR! | No |
| Regro | X | rundll132.exe | Added by the OKARAG TROJAN! | No |
| RDLL | X | RunDll16.exe | Added by the SDBOT.F TROJAN! | No |
| Rundll16 | X | Rundll16.exe | Added by a number of VIRUSES, WORMS and TROJANS! | No |
| RUNDLL32 | X | RUNDLL16.EXE | Detected by Malwarebytes Anti-Malware as Backdoor.Qdoor. The file is located in %System% | No |
| svchost | X | rundll16.exe | Added by the STARTPA-PB TROJAN! | No |
| SYSTEM | X | RUNDLL16.exe | Added by the DELF-EW BACKDOOR! | No |
| Win32 USB2.0 Driver | X | rundll16.exe | Added by the WOOTBOT.H WORM! | No |
| Windows DLL Loader | X | RUNDLL16.EXE | Added by the DOMWIS TROJAN! | No |
| Microsoft Update Module | X | rundll24.exe | Added by the RBOT-PS WORM! | No |
| sp | X | rundll32 (Path to Trojan DLL),DllInstall | Added by the ABLANK-W and ABLANK-Z TROJANS! | No |
| gvagfxj | X | rundll32 ...gvagfxj.dll | Unidentified adware, spyware or virus | No |
| drvupd | X | rundll32 ..drvupd.inf | Hijacker - drvupd.inf file installs a "searchforge.com" hijack | No |
| rundll32 | X | rundll32 .exe | Detected by Sophos as W32/Ainslot-Q and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| AME_CSA | N | rundll32 amecsa.cpl,RUN_DLL | Loads ADSL modem Control Panel applet | No |
| Arucer | X | rundll32 Arucer.dll,Arucer | Provides support for the Energizer UsbCharger (Energizer UsbCharger.exe) utility that detects and shows the charging status for the Energizer® Duo USB/mains battery charger. Note - it appears that the product has now been withdrawn from the Energizer product line-up after it was discovered that this file contains the ARUGIZER TROJAN | No |
| Arucer Dynamic Link Library | X | rundll32 Arucer.dll,Arucer | Provides support for the Energizer UsbCharger (Energizer UsbCharger.exe) utility that detects and shows the charging status for the Energizer® Duo USB/mains battery charger. Note - it appears that the product has now been withdrawn from the Energizer product line-up after it was discovered that this file contains the ARUGIZER TROJAN | No |
| AudCtrl | ? | RunDll32 AudCtrl.dll,RCMonitor | Audio control panel? | No |
| AUNPS2 | X | RUNDLL32 AUNPS2.dll,_Run@16 | AUNPS adware | No |
| AxFilter | ? | Rundll32 AXFILTER.dll,Rundll32 | ?? | No |
| C6501Sound | N | RunDll32 c6501.cpl,CMICtrlWnd | System tray control panel for C-Media CM6501 based soundcards - often included on popular motherboards with in-built audio. Available via Start → Settings → Control Panel | No |
| Cmaudio | N | Rundll32 cmicnfg.cpl,CMICtrlWnd | System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start → Settings → Control Panel | No |
| Rundll32 cmicnfg | N | Rundll32 cmicnfg.cpl,CMICtrlWnd | System tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start → Settings → Control Panel | No |
| CmPCIaudio | U | RunDll32 CMICNFG3.CPL,CMICtrlWnd | Registers the Control Panel applet for a C-Media PCI sound card | No |
| babeie | X | rundll32 CNBabe.dll,DllStartup | CommonName Toolbar spyware | No |
| Zenet | X | rundll32 CNBabe.dll,DllStartup | CommonName.Zenet search hijacker | No |
| gfxtray | X | rundll32 ctccw32.dll,findwnd | Added by the AGENT.AOU BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ctccw32.dll" is located in %System% | No |
| MBMon | U | Rundll32 CTMBHA.DLL,MBMon | Creative Filter AudioControlMB Module - installed with the Creative Audigy line of sound cards and processors. Can be disabled without causing a problem | No |
| SoundFusion | ? | RunDll32 cwaprops.cpl,CrystalControlWnd | Control panel item for a Terratec soundcard (Start → Settings → Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? | No |
| SoundFusion | ? | rundll32 cwcprops.cpl,CrystalControlWnd | Control panel item for the Terratec DMX Xfire 1024 soundcard (Start → Settings → Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? | No |
| autoupdate | X | rundll32 DATADX.DLL,SHStart | Added by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "DATADX.DLL" file is found in %System% | No |
| RunDll32 essprops | Y | RunDll32 essprops.cpl,TaskbarIconWnd | Associated with a Logitech mouse - required for proper operation | No |
| sta | X | rundll32 fjzkp.dll | Added by the MDROP-CSP TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "fjzkp.dll" file is located in %System% | No |
| GsiFinal | ? | rundll32 gspndll.dll,postInstall final | USB DSL modem related. What does it do and is it required? | No |
| Bluetooth HCI Monitor | ? | RunDll32 HCIMNTR.DLL,RunCheckHCIMode | Related to the Bluetooth short-range wireless communications technology. For more information on Bluetooth see here. What does it do and is it required? | No |
| SoundFusion | ? | rundll32 hercplgs.cpl,BootEntryPoint | Control panel item for Hercules Fortissimo soundcards (Start → Settings → Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time? | No |
| xkstartup | ? | RunDll32 InstZ82.dll,SetUsbPrinterPort | On a system with a Lexmark printer | No |
| ControlPanel | X | rundll32 internat.dll,LoadKeyboardProfile | CoolWebSearch parasite variant | No |
| jx_Key | U | Rundll32 JXKey.dll,Rundll32Main | Boolospy keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| kernctl32 | X | rundll32 kctl32.dll,initialize | Added by the AGENT.AT TROJAN! | No |
| WinXPLoad | U | Rundll32 LoadDll, LoadExe WinXPLoad.exe | Compaq hotkey related - required if you use the hotkeys | No |
| bipro | X | rundll32 mmduch.dll | Added by the MDROP-CVM TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mmduch.dll" file is located in %Windir%\$NtUninstallMTF1011$ | No |
| MMhid | U | rundll32 mmhid.dll,StartMmHid | Human Interface Device Server for Win98 which is required only if you are using USB Audio Devices you can disable via Msconfig. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in XP/Me/2K/98SE | No |
| NVCLOCK | ? | rundll32 nvclock.dll,fnNvclock | Overclocking utility for nVidia based graphics cards? | No |
| P17Helper | U | Rundll32 P17.dll,P17Helper | ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality | No |
| P17RunE | ? | RunDll32 P17RunE.dll,RunDLLEntry | Related to drivers for the Creative Sound Blaster Audigy & Audigy 2 soundcards. What does it do and is it required? | No |
| RSS | X | rundll32 RSSToolbar.dll,DllRunMain | "Related Sites" toolbar - SearchAndClick hijacker variant | No |
| SbUsb AudCtrl | U | RunDll32 sbusbdll.dll,RCMonitor | Control for Soundblaster MP3 external (USB) sound card | No |
| SysPnP | X | rundll32 setupapi, InstallHinfSection [varies] oemsyspnp.inf | CoolWebSearch PnP parasite variant | No |
| keymgrldr | X | rundll32 setupapi, InstallHinfSection... keymgr3.inf | CoolWebSearch Oemsyspnp parasite variant | No |
| SOProc_RegSoAlertWxLiteNnAj | X | rundll32 shell32.dll,ShellExec_RunDLL [path] soproc.exe | SoftwareOnline Intelligent Downloader - "Bundle engine to enable download of end user approved third party applications and reporting of installs for billing purposes only". Said to monitor user's browsing habits and display pop-up ads | No |
| P17Helper | ? | Rundll32 SPIRun.dll,RunDLLEntry | Related to Creative audio products. What does it do and is it required? | No |
| SPIRun | ? | Rundll32 SPIRun.dll,RunDLLEntry | Related to Creative audio products. What does it do and is it required? | No |
| SRFirstRun | ? | rundll32 srclient.dll,CreateFirstRunRp | Created by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. Does this indeed need to run at every bootup? | No |
| autoupdate | X | rundll32 SUPDATE.DLL,SHStart | Added by a variant of the QOOLOGIC TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SUPDATE.DLL" file is found in %System% | No |
| Tweak UI | X | RunDLL32 tweakUI.dll, TWEAKUI /tweakmeup | Detected by Symantec as Backdoor.Subwoofer. Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup". Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| winupdate | X | rundll32 winnew.dll,run2 | Added by unidentified malware - see here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "winnew.dll" file is found in %AppData% | No |
| 9d3b | X | rundll32 [path] 9d3b.dll | Detected by Quick Heal as TrojanDropper.Agent.zac. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "9d3b.dll" is located in %Windir%\Downloaded Program Files | No |
| anshgey | X | rundll32 [path] anshgey.dll | Detected by Sophos as Troj/Symmi-H and by Malwarebytes Anti-Malware as Trojan.Agent.PRX. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "anshgey.dll" file is located in %LocalAppData% | No |
| mscfs | U | RUNDLL32 [path] cfsys.dll,cfs | AllSum adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cfsys.dll" file is found in %System%\msibm | No |
| exe2stub | X | rundll32 [path] ddesexnt.dll | Detected by Malwarebytes Anti-Malware as Backdoor.Papras. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ddesexnt.dll" file is located in %System% | No |
| expastub | X | rundll32 [path] debuexnt.dll | Detected by Malwarebytes Anti-Malware as Backdoor.Papras. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "debuexnt.dll" file is located in %System% | No |
| expagent | X | rundll32 [path] debumsg.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent.NR. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "debumsg.dll" file is located in %System% | No |
| expaator | X | rundll32 [path] debusdtc.dll | Detected by Malwarebytes Anti-Malware as Backdoor.Papras. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "debusdtc.dll" file is located in %System% | No |
| expadctr | X | rundll32 [path] debusync.dll | Detected by Malwarebytes Anti-Malware as Backdoor.Papras. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "debusync.dll" file is located in %System% | No |
| DLBTCATS | Y | rundll32 [path] DLBTtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| DLBUCATS | Y | rundll32 [path] DLBUtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| DLBXCATS | Y | rundll32 [path] DLBXtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| DLCCCATS | Y | rundll32 [path] DLCCtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll). If you use the 964 printer, Dell recommends leaving dlcctime.dll in place as it fixes compatibility issues on some Dell systems. If you receive an error message on system startup that reads: "Error in C:\WINDOWS\System32\spool\drivers\W32\x86\3DLCCtime.dll Missing entry: RunDLLEntry" Dell offers help here | No |
| DLCDCATS | Y | rundll32 [path] DLCDtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| DLCFCATS | Y | rundll32 [path] DLCFtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| DLCGCATS | Y | rundll32 [path] DLCGtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| DLCICATS | Y | rundll32 [path] DLCItime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| DLCJCATS | Y | rundll32 [path] DLCJtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| DLCQCATS | Y | rundll32 [path] DLCQtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| DLCXCATS | Y | rundll32 [path] DLCXtime.dll,_RunDLLEntry@16 | Resolves a timing problem where a Dell service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| PopularScreensaversWallpaper | X | rundll32 [path] F3SCRCTR.DLL,LES | MyWebSearch parasite - see here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "F3SCRCTR.DLL" file is located in %ProgramFiles%\MyWebSearch\bar\*.bin - where * represents a number or letter | No |
| kiopulo | X | rundll32 [path] kiopulo.dll,kiopulo | Detected by Dr.Web as Trojan.DownLoader6.45475 and by Malwarebytes Anti-Malware as Trojan.Winlogon. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "kiopulo.dll" file is found in %LocalAppData% | No |
| kpueraf | X | rundll32 [path] kpueraf.dll | Detected by Dr.Web as Trojan.DownLoader7.591 and by Malwarebytes Anti-Malware as Trojan.Symmi. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "kpueraf.dll" file is located in %LocalAppData% | No |
| LXBSCATS | Y | rundll32 [path] LXBStime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXBTCATS | Y | rundll32 [path] LXBTtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXBUCATS | Y | rundll32 [path] LXBUtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXBXCATS | Y | rundll32 [path] LXBXtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXBYCATS | Y | rundll32 [path] LXBYtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCCCATS | Y | rundll32 [path] LXCCtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCDCATS | Y | rundll32 [path] LXCDtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCECATS | Y | rundll32 [path] LXCEtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCFCATS | Y | rundll32 [path] LXCFtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCGCATS | Y | rundll32 [path] LXCGtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCICATS | Y | rundll32 [path] LXCItime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCJCATS | Y | rundll32 [path] LXCJtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCQCATS | Y | rundll32 [path] LXCQtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCRCATS | Y | rundll32 [path] LXCRtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCTCATS | Y | rundll32 [path] LXCTtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXCYCATS | Y | rundll32 [path] LXCYtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXDBCATS | Y | rundll32 [path] LXDBtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXDCCATS | Y | rundll32 [path] LXDCtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details | No |
| LXDDCATS | Y | rundll32 [path] LXDDtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXDICATS | Y | rundll32 [path] LXDItime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| LXDJCATS | Y | rundll32 [path] LXDJtime.dll,_RunDLLEntry@16 | Resolves a timing problem where the Lexmark Communications service tries to communicate with the printer but Windows is too busy - by either delaying the start of the service or restarting if the service failed to load. See here for more details on a similar Lexmark DLL entry (LXDCtime.dll) | No |
| MyWebSearch Plugin | X | rundll32 [path] M3PLUGIN.DLL,UPF | MyWebSearch parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "M3PLUGIN.DLL" file is located in %ProgramFiles%\MyWebSearch\bar\*.bin - where * represents a number or letter | No |
| ndmsi | X | rundll32 [path] ndmsi.dll | Detected by Malwarebytes Anti-Malware as Trojan.Medfos. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ndmsi.dll" file is located in %AppData% | No |
| New.net Startup | X | rundll32 [path] NEWDOT~1.dll,ClientStartup | NewDotNet foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| New.net Startup | X | rundll32 [path] NEWDOT~1.dll,NewDotNetStartup | NewDotNet foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| New.net Startup | X | rundll32 [path] NEWDOT~2.dll,ClientStartup | NewDotNet foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| New.net Startup | X | rundll32 [path] NEWDOT~2.dll,NewDotNetStartup | NewDotNet foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| nscsr | X | rundll32 [path] nscsr.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "nscsr.dll" file is located in %AppData% | No |
| MYQDBBL | X | rundll32 [path] pgnfled.b | Detected by McAfee as Generic.IL. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "pgnfled.b" file is located in %AppData%\Microsoft\Protect | No |
| primnog | X | rundll32 [path] primnog.dll | Detected by Dr.Web as Trojan.DownLoader6.55143 and by Malwarebytes Anti-Malware as Trojan.Dropper. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "primnog.dll" file is located in %LocalAppData% | No |
| prituus | X | rundll32 [path] prituus.dll | Detected by Dr.Web as Trojan.DownLoader7.13863 and by Malwarebytes Anti-Malware as Trojan.Notify. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "prituus.dll" file is located in %LocalAppData% | No |
| psdsr | X | rundll32 [path] psdsr.dll | Detected by Dr.Web as Trojan.DownLoader6.42724. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "psdsr.dll" file is located in %AppData% | No |
| BMMGAG | U | RunDll32 [path] pwrmonit.dll,StartPwrMonitor | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. This entry displays the battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to the proprietary power saving settings and to a battery information window | Yes |
| pwrmonit | U | RunDll32 [path] pwrmonit.dll,StartPwrMonitor | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. This entry displays the battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to the proprietary power saving settings and to a battery information window | Yes |
| ntlfreedom | N | rundll32 [path] RyDial.dll,QuickStart | NTL Freedom dial-up ISP software - not required | No |
| Tesco.net | N | rundll32 [path] RyDial.dll,QuickStart | Tesco.net dial-up ISP software - not required | No |
| SurfBuddy | X | rundll32 [path] sbuddy.dll | SurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| UEWUQWE | X | rundll32 [path] seivtb.sf | Detected by McAfee as Generic.IL. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "seivtb.sf" file is located in %AppData%\Microsoft\Protect | No |
| Update | X | rundll32 [path] Sophosup.dll | Added by the HILOTI-CY TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Sophosup.dll" file is found in %AppData%\Sophos\SophosUpdate | No |
| WebSpecials | X | rundll32 [path] webspec.dll | WebSpecials adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| SystemWin | X | rundll32 [path] win.dll,run | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "win.dll" file is found in %LocalAppData% | No |
| SystemWin2 | X | rundll32 [path] win2.dll,run | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "win2.dll" file is found in %LocalAppData% | No |
| Adobe Update | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| AppleProfileProfile | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| DisplayProfilePolicy | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| Intel Update | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| JavaNotifierProfile | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| Local Update | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| MicrosoftBackupVerifier | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| MicrosoftVerifierPolicy | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| Netscape Update | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| ODBC Update | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| Update | X | rundll32 [path] [filename].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AA and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[filename].dll" file is found in %AppData% | No |
| Image | X | rundll32 [path] [trojan filename],Install | Detected by Trend Micro as TROJ_WINSHOW.Y | No |
| System32 | X | rundll32-.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| NT security | X | rundll32.com | Added by the RBOT-AJC WORM! | No |
| Microsoft Update | X | rundll32.dll | Added by the CIADOOR.GN BACKDOOR! | No |
| _rx | X | rundll32.exe | Added by the LINEAG-B TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\command | No |
| Adobe32 ARM | X | rundll32.exe | Detected by Kaspersky as Trojan.Win32.Swisyn.arlt. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %WinDir%\Adobe32 ARM | No |
| ca84c702-c758-4421-974e-b02662e76d7c_6 | X | rundll32.exe | Antimalware Defender rogue security software - not recommended, removal instructions here! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| d9347bb67c3915d4b4f4b318a915057b | X | rundll32.exe | Detected by Dr.Web as Trojan.Siggen4.33560 and by Malwarebytes Anti-Malware as Worm.Agent. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Temp% | No |
| HKCU | X | rundll32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %System%\install | No |
| HKCU | X | rundll32.exe | Detected by Kaspersky as Backdoor.Win32.Bifrose.dumi and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\install | No |
| HKCU | X | rundll32.exe | Detected by McAfee as Generic.bfr!cc and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Root%\dir\install\rundll32.exe\install\rundll32.exe | No |
| HKLM | X | rundll32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %System%\install | No |
| HKLM | X | rundll32.exe | Detected by Kaspersky as Backdoor.Win32.Bifrose.dumi and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\install | No |
| HKLM | X | rundll32.exe | Detected by McAfee as Generic.bfr!cc and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Root%\dir\install\rundll32.exe\install\rundll32.exe | No |
| Host-process Windows (Rundll32.exe) | X | rundll32.exe | Detected by Dr.Web as Trojan.DownLoader6.47266 and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %AppData%\System32 | No |
| Host-process Windows (Rundll32.exe) | X | rundll32.exe | Detected by Dr.Web as Trojan.DownLoader6.51189 and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %AppData% | No |
| Ljx | X | rundll32.exe | Detected by Sophos as Troj/Lineag-ABD. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\inf | No |
| load | X | rundll32.exe | Detected by Symantec as Infostealer.Wowcraft. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %ProgramFiles% | No |
| Loadhg | X | rundll32.exe | Added by the LINEAG-ABX TROJAN! | No |
| loadMecq3 | X | rundll32.exe | Detected by Sophos as Troj/LegMir-AS. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Root% | No |
| loadMect2 | X | rundll32.exe | Detected by Malwarebytes Anti-Malware as Spyware.OnLineGames. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %ProgramFiles% | No |
| loadMefs | X | rundll32.exe | Detected by Sophos as Troj/LegMir-JB. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\inf | No |
| LoadPowerProfile | X | Rundll32.exe | Detected by Symantec as W32.Miroot.Worm. Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line | No |
| LTT2 | X | rundll32.exe | Detected by Sophos as Troj/Lineage-BI | No |
| microsoft | X | rundll32.exe | Detected by McAfee as Generic.mfr and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %System%\microsoft | No |
| Microsoft (R) Windows DLL Loader | X | rundll32.exe | Detected by Symantec as Backdoor.Ranky.W. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\dll | No |
| Microsoft Setup Initializazion | X | rundll32.exe | Detected by Symantec as W32.Randex.gen. Note that this modifies the file rundll32.exe, which is otherwise a legitimate Microsoft file used to launch DLL file types | No |
| Microsoft Update 32 | X | rundll32.exe | Added by the RBOT.AIE BACKDOOR! Note that this BACKDOOR modifies the file rundll32.exe, which is otherwise a legitimate Microsoft file used to launch DLL file types | No |
| NET Framework | X | Rundll32.exe | Detected by McAfee as RDN/Ransom and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %AppData%\Microsoft | No |
| Policies | X | rundll32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %System%\install | No |
| Policies | X | rundll32.exe | Detected by Kaspersky as Backdoor.Win32.Bifrose.dumi and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\install | No |
| Policies | X | rundll32.exe | Detected by McAfee as Generic.bfr!cc and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Root%\dir\install\rundll32.exe\install\rundll32.exe | No |
| Regrx | X | rundll32.exe | Added by the WAYIC-A TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir% | No |
| Rhg | X | rundll32.exe | Added by the LINEAG-BIT TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\inf | No |
| RKrx | X | rundll32.exe | Added by a variant of the LINEAG-ADA TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\inf | No |
| RKrx | X | rundll32.exe | Added by the LINEAG-ADA TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\down | No |
| Rr2 | X | rundll32.exe | Added by the LINEAG-ADI TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\addins | No |
| rro | X | rundll32.exe | Added by the LINEAG-AAE TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %ProgramFiles%\Microsoft | No |
| Rundll32 | X | Rundll32.exe | Added by a variant of the DVLDR TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\Fonts | No |
| rundll32 | X | rundll32.exe | Added by the AGENT-EZ TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %System%\SHELLEXT | No |
| rundll32 | X | rundll32.exe | Added by the SANKER WORM! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir% | No |
| rundll32 | X | rundll32.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.LSM. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %AppData% | No |
| RUNDLL32 | X | RUNDLL32.EXE | Detected by Dr.Web as Trojan.Siggen5.4677. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\inf | No |
| rundll32 | X | rundll32.exe | Detected by Kaspersky as Trojan-Dropper.Win32.Injector.pmb and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %UserTemp% | No |
| Rundll32 | X | Rundll32.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %AllUsersProfile%\Start Menu\MSDCSC | No |
| rx | X | rundll32.exe | Added by the LINEAGE-BP TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir% | No |
| rzt | X | rundll32.exe | Detected by Trend Micro as TSPY_LINEAGE.BDP and by Malwarebytes Anti-Malware as Trojan.Agent.TZ. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %Windir%\Intel | No |
| SunJavaUpdateSched | X | rundll32.exe | Added by the VBKRYPT.FNL TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (Windows 7/Vista/XP/2K/NT). This one is located in %AppData% | No |
| sys | X | rundll32.exe | Added by the LINEAG-G TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\Intel | No |
| SysWy | X | rundll32.exe | Added by the LINEAGE-JH TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP) | No |
| TaskMan | X | Rundll32.exe | Added by the DVLDR TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\Fonts | No |
| Tray | X | rundll32.exe | Added by the LINEAG-ADR TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\command | No |
| UPDATEHOOK | ? | Rundll32.exe | ?? | No |
| Win32 Rundll Loader | X | Rundll32.exe | Added by the SDBOT.A BACKDOOR! Note - this is not to be confused with the legitimate rundll32.exe file! | No |
| Windows DLL Loader | X | rundll32.exe | Added by the WHIPSER-B WORM! Note - this is not the legitimate rundll32.exe process | No |
| Windows Firewall | X | rundll32.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| Windows Update | X | rundll32.exe | Detected by Symantec as W32.Addnu and by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %LocalAppData%\Microsoft | No |
| zhtngyzTdd | X | rundll32.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). This one is located in %UserTemp% | No |
| zt | X | rundll32.exe | Added by the LINEAG-ABA TROJAN! Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (98/ME) or %System% (NT/2K/XP). This one is located in %Windir%\Intel | No |
| InfoData | X | rundll32.exe ********.dll,realset [* = random char] | Added by the VUNDO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System% | No |
| lhttseng | N | rundll32.exe ..lhttseng.inf, RemoveCabinet | Left over after installation of the British English version of the Lernout & Hauspie Text To Speech (TTS) Engine | No |
| Rundll32_8 | X | rundll32.exe 1.dll,DllRunServer | Detected by Symantec as Adware.BrowserAid. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "1.dll" file is located in %Root% | No |
| VoodooBanshee | U | rundll32.exe 3DBBps.dll,BansheeLoadSettings | Loads the configuration settings for a 3dfx Voodoo Banshee chipset based graphics card. If you change some of the settings from default you probably need this - otherwise maybe not | No |
| 3dfx Tools | Y | rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot | Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards | No |
| 56a10a26-dc02-40f3-a4da-8fa92d06b357_33 | X | rundll32.exe 56a10a26-dc02-40f3-a4da-8fa92d06b357_33.avi | Security Defender rogue security software - not recommended, removal instructions here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "56a10a26-dc02-40f3-a4da-8fa92d06b357_33.avi" file is located in %CommonAppData% | No |
| ctfmon.exe | X | rundll32.exe 9wwil.dat | Detected by Sophos as Troj/Ransom-QV. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). Both files are located in %CommonAppData% | No |
| delsubmit | X | rundll32.exe advpack.dll,DelNodeRunDLL32 submit.exe | CoolWebSearch parasite variant | No |
| WinDLL (algs.exe) | X | rundll32.exe algs.exe,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "algs.exe" file is found in %System% | No |
| Windows rundll32 updater | X | Rundll32.exe Amti.dll | Added by the AMTIAN VIRUS! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Amti.dll" file is located in %Windir%\Amti | No |
| KB926239 | Y | rundll32.exe apphelp.dll,ShimFlushCache | Microsoft KB926239 fix. Windows Media Player 10 may close unexpectedly on a Windows XP-based computer | No |
| ApplePolicyBackup | X | rundll32.exe ApplePolicyBackup.dll | Added by the MDROP-DUQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ApplePolicyBackup.dll" file is found in %AppData% | No |
| WinDLL (asdfsa.exe) | X | rundll32.exe asdfsa.exe,start | Added by the SDBOT.GAV WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "asdfsa.exe" file is found in %System% | No |
| PostSetupCheck | X | Rundll32.exe atgban.dll | TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "atgban.dll" file is found in %System% | No |
| autochk | X | rundll32.exe autochk.dll,_IWMPEvents@16 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "autochk.dll" file is found in %System% | No |
| ctfmon.exe | X | rundll32.exe awibdo.dat | Detected by Dr.Web as Trojan.DownLoader8.31997. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). Both files are located in %CommonAppData% | No |
| BCMHal | U | rundll32.exe bcmhal9x.dll,bcinit | BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings | No |
| WinDLL (bee.dll) | X | rundll32.exe bee.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bee.dll" file is found in %System% | No |
| Systems Restart | X | Rundll32.exe beem.dll,DllRegisterServer | Browser hijacker - the file serves to register a dll implemented as a browser plugin. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| WinDLL (bix.exe) | X | rundll32.exe bix.exe,start | Added by the KOLAB.OL WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Bix.exe" file is found in %System% | No |
| Systems Restart | X | Rundll32.exe boln.dll,DllRegisterServer | Added by the STARTPAGE.J TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| BookedSpace | X | RunDLL32.EXE bs2.dll,DllRun | BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bs2.dll" file is located in %Windir% | No |
| Bsx3 | X | RunDLL32.EXE bs3.dll,DllRun | BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bs3.dll" file is located in %Windir% | No |
| bxsx5 | X | RunDLL32.EXE bsx5.dll,DllRun | BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bsx5.dll" file is located in %Windir% | No |
| BluetoothAuthenticationAgent | U | rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent | If your system has Bluetooth (either integrated or via an adapter) and use's Microsoft's support software/drivers, this entry is required in order to successfully "pair" your system with a Bluetooth device (such as a mobile phone, PDA, headset) using this wireless protocol (via a PIN) | Yes |
| rundll32 | U | rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent | If your system has Bluetooth (either integrated or via an adapter) and use's Microsoft's support software/drivers, this entry is required in order to successfully "pair" your system with a Bluetooth device (such as a mobile phone, PDA, headset) using this wireless protocol (via a PIN) | Yes |
| BTMTrayAgent | U | rundll32.exe btmshell.dll,TrayApp | Provides support for Bluetooth short-range wireless products from Intel and Motorola (and maybe others). If you don't use any Bluetooth devices (such as mice, keyboards, headsets and phones) with your PC you can disable this | Yes |
| Intel PROSet\Wireless Bluetooth | U | rundll32.exe btmshell.dll,TrayApp | Provides support for Bluetooth short-range wireless products from Intel. If you don't use any Bluetooth devices (such as mice, keyboards, headsets and phones) with your PC you can disable this | Yes |
| bxxs5 | X | RunDLL32.EXE bxxs5.dll,dllrun | BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bxxs5.dll" file is located in %Windir% | No |
| ca84c702-c758-4421-974e-b02662e76d7c_6 | X | rundll32.exe ca84c702-c758-4421-974e-b02662e76d7c_6.avi | Antimalware Defender rogue security software - not recommended, removal instructions here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ca84c702-c758-4421-974e-b02662e76d7c_6.avi" file is located in %System% and %AppData% | No |
| calc | X | rundll32.exe calc.dll,_IWMPEvents@0 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "calc.dll" file is located in %System% | No |
| WildTangent CDA | ? | RUNDLL32.exe cdaEngine0400.dll,cdaEngineMain | Part of the WildTangent on-line games system. What does it do and is it required? | No |
| ExFilter | X | Rundll32.exe cdnspie.dll,ExecFilter | CNNIC Update pest. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cdnspie.dll" file is located in %ProgramFiles%\CNNIC\Cdn | No |
| cfgmgr51 | X | RunDLL32.EXE cfgmgr51.dll,DllRun | BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cfgmgr51.dll" file is located in %Windir% | No |
| cfgmgr52 | X | RunDLL32.EXE cfgmgr52.dll,DllRun | BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cfgmgr52.dll" file is located in %Windir% | No |
| RegistryCheck | X | rundll32.exe chkreg.dll,CheckRegistry | Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| PostSetupCheck | X | Rundll32.exe cpmsky.dll | TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cpmsky.dll" file is found in %System% | No |
| CPU Watcher | X | rundll32.exe cpu.dll,load | Added by the DLOADER-LO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cpu.dll" file is located in %Windir% | No |
| CrazyTalk Serve | N | rundll32.exe CrazyTalk.dll,DIIServeMediaFile | CrazyTalk from Reallusion - "the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph, complete with emotions." Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS | No |
| WinDLL (csmss.exe) | X | rundll32.exe CSMSS.EXE,start | Detected by Trend Micro as WORM_AKBOT.U. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "CSMSS.EXE" file is found in %System% | No |
| WinDLL (ctfmonm.exe) | X | rundll32.exe ctfmonm.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ctfmonm.exe" file is found in %System% | No |
| Control | X | rundll32.exe ctrlpan.dll,Restore ControlPanel | CoolWebSearch Msconfd parasite variant | No |
| 98D0CE0C16B1 | X | rundll32.exe D0CE0C16B1,D0CE0C16B1 | BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| dabrun | X | rundll32.exe dabapi.dll,Rundll32 | SinaUpdateCenter adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dabapi.dll" file is found in %System% | No |
| WinDLL (dasada.exe) | X | rundll32.exe dasada.exe,start | Added by the SDBOT.GAV WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dasda.exe" file is found in %System% | No |
| WinDLL (dasda.com) | X | rundll32.exe dasda.com,start | Added by the SDBOT.GAV WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dasda.com" file is found in %System% | No |
| DeadAIM | N | rundll32.exe DeadAIM.ocm, ExportedCheckODLs | DeadAIM - feature enhancing product for AOL's Instant Messenger program | No |
| WinDLL (diem.exe) | X | rundll32.exe diem.exe,start | Detected by Trend Micro as WORM_AKBOT.E. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "diem.exe" file is found in %System% | No |
| WinDLL (dlfksdld.exe) | X | rundll32.exe dlfksdld.exe,start | Added by the IRCBOT.BPM BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dlfksdld.exe" file is found in %System% | No |
| .Net Recovery | X | rundll32.exe dotnetfx.dll,repair | Added by the DELEZIUM VIRUS! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "winsys16_070813.dll" file is found in %System% | No |
| drkly16j | U | rundll32.exe drkly16j.dll,ServiceCheck | KidsWatch Time Control parental control software | No |
| CTDrive | X | rundll32.exe drv[random].dll,startup | Added by a variant of Trojan:Win32/Adialer.OP! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drv[random].dll" file is found in %System% | No |
| MSDisp32 | X | rundll32.exe drv[random].dll,startup | Added by a variant of Trojan:Win32/Adialer.OP! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drv[random].dll" file is found in %System% | No |
| MSDrive | X | rundll32.exe drv[random].dll,startup | Added by a variant of Trojan:Win32/Adialer.OP! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drv[random].dll" file is found in %System% | No |
| A70F6A1D-0195-42a2-934C-D8AC0F7C08EB | X | rundll32.exe E6F1873B.dll, D9EBC318C | Detected by Symantec as Adware.BrowserAid. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "E6F1873B.DLL" file is located in %System% | No |
| Encrypted Disk Auto Mount | Y | rundll32.exe edshell.dll,MountAll | "Paragon Encrypted Disk is a set of system drivers, plug-ins, wizards and utilities to store your data in an encrypted form but use these data in a common way as if they are not encrypted" | No |
| Instant Access | X | rundll32.exe EGCOMLIB_****.dll,InstantAccess [**** = digits] | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Instant Access | X | rundll32.exe EGCOMSERVICE_****.dll,InstantAccess [**** = digits] | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Instant Access | X | rundll32.exe EGDACCESS_****.dll,InstantAccess | InstantAccess premium rate adult content dialler variant - where **** represents for digits. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The DLL file is located in %System% | No |
| Instant Access | X | rundll32.exe EGDHTML_1023.dll,InstantAccess | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Instant Access | X | rundll32.exe eg_auth_****.dll,InstantAccess [**** = digits] | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Microsoft® Windows® Operating System | N | RunDLL32.exe ehuihlp.dll,BootMediaCenter | Starts Windows Media Center every time Vista (Home Premium or Ultimate) or Windows 7 (Home Premium, Professional or Ultimate) boots. Disable by unchecking the "Start Windows Media Center when Windows Starts" option via Windows Media Center → Tasks → Settings → General → Startup and Window Behaviour | Yes |
| Windows Media Center | N | RunDLL32.exe ehuihlp.dll,BootMediaCenter | Starts Windows Media Center every time Vista (Home Premium or Ultimate) or Windows 7 (Home Premium, Professional or Ultimate) boots. Disable by unchecking the "Start Windows Media Center when Windows Starts" option via Windows Media Center → Tasks → Settings → General → Startup and Window Behaviour | Yes |
| ctfmon.exe | X | rundll32.exe f4e1.dat | Detected by Sophos as Troj/Reveton-CP. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). Both files are located in %CommonAppData% | No |
| fstsvc | X | rundll32.exe fstsvc.dll,start | Added by the AKBOT-AA WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "fstsvc.dll" file is found in %System% | No |
| ftutil2 | U | rundll32.exe ftutil2.dll,SetWriteCacheMode | Related to Promise Technology's FastTrak SX4030/4060 PCI ATA Raid 5 controller (and possibly others) | No |
| wupipenimi | X | Rundll32.exe fumitoga.dll,s | Added by the MONDER.BZEA TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "fumitoga.dll" file is found in %System% | No |
| Gddlib | X | rundll32.exe gddlib.dll,start | Detected by Trend Micro as WORM_AKBOT.EG. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "gddlib.dll" file is found in %System% | No |
| postSetupCheck | X | Rundll32.exe gzmrt.dll | TrafficSol adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "gzmrt.dll" file is found in %System% | No |
| HBService | X | Rundll32.exe HBmhly.dll,StartService | Added by the ONLINEGAMES.SKNV TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "HBmhly.dll" file is found in %System% | No |
| he3bbcff | X | rundll32.exe he3bbcff.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "he3bbcff.dll" file is found in %System% | No |
| he3e3fc4 | X | rundll32.exe he3e3fc4.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "he3e3fc4.dll" file is found in %System% | No |
| wupipenimi | X | Rundll32.exe hupojoyu.dll,s | Added by the MONDER.BZEA TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "hupojoyu.dll" file is found in %System% | No |
| icdd7ee6 | X | rundll32.exe icdd7ee6.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "icdd7ee6.dll" file is found in %System% | No |
| icddefff | X | rundll32.exe icddefff.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "icddefff.dll" file is found in %System% | No |
| ICSDCLT | U | rundll32.exe Icsdclt.dll,ICSClient | Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines | No |
| iel2cde8 | X | rundll32.exe iel2cde8.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "iel2cde8.dll" file is found in %System% | No |
| ielcaabe | X | rundll32.exe ielcaabe.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ielcaabe.dll" file is found in %System% | No |
| Msn | X | rundll32.exe ilss32.dll,network | Added by the BANLO-E TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Rundll32_8 | X | rundll32.exe inetp60.dll,DllRunServer | BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "inetp60.dll" file is located in %System% | No |
| BluetoothAuthenticationAgent | U | rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent | If your system has Bluetooth (either integrated or via an adapter) and use's Microsoft's support software/drivers, this entry is required in order to successfully "pair" your system with a Bluetooth device (such as a mobile phone, PDA, headset) using this wireless protocol (via a PIN). Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here for more information | Yes |
| rundll32 | U | rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent | If your system has Bluetooth (either integrated or via an adapter) and use's Microsoft's support software/drivers, this entry is required in order to successfully "pair" your system with a Bluetooth device (such as a mobile phone, PDA, headset) using this wireless protocol (via a PIN). Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here for more information | Yes |
| iSecurity applet | X | rundll32.exe iSecurity.cpl,SecurityMonitor | Added by the DLOADER.UZO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| WinDLL (jbi32.dll) | X | rundll32.exe jbi32.dll,start | Detected by Trend Micro as WORM_AKBOT.E. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "jbi32.dll" file is found in %System% | No |
| wupipenimi | X | Rundll32.exe jinorije.dll,s | Added by the VUNDO.JD.DLL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "jinorije.dll" file is found in %System% | No |
| jmudkve.dll | X | rundll32.exe jmudkve.dll,mzrwkwf | Added by the AGENT-DJD TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "jmudkve.dll" file is found in %System% | No |
| DisableKeybaord | X | Rundll32.exe Keyboard,Disable | Added by the VB-HE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| kw3eef76 | X | rundll32.exe kw3eef76.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "kw3eef76.dll" file is found in %System% | No |
| WinDLL (lcass.exe) | X | rundll32.exe lcass.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "lcass.exe" file is found in %System% | No |
| li01f948 | X | rundll32.exe li01f948.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "li01f948.dll" file is found in %System% | No |
| LibGLTime | X | Rundll32.exe LibGLTime.dll | Detected by Sophos as Troj/Sefnit-B. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "LibGLTime.dll" file is located in %LocalAppData%\SystemMapPlay | No |
| libtec | X | rundll32.exe libtec.dll,start | Added by the AKBOT-AI WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "libtec.dll" file is found in %System% | No |
| ltssvc | X | rundll32.exe ltssvc.dll,start | Added by the AKBOT-AG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ltssvc.dll" file is found in %System% | No |
| wupipenimi | X | Rundll32.exe luyenofe.dll,s | Added by the VUNDO.JD.DLL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "luyenofe.dll" file is found in %System% | No |
| MigrationVendorSetupCaller | ? | rundll32.exe migrate.dll,CallVendorSetupDlls | ?? | No |
| LicCtrl | Y | rundll32.exe MMFS.DLL,Service | Part of the eLicense Copy Protection scheme employed by some software and games. If it is not running the eLicense wrapper is unable to extract and execute the program. The "MMFS.DLL" file is located in %Windir% | No |
| MMSystem | X | rundll32.exe mmsystem.dll,RunDll32 | Added by the FUNNER-A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mmsystem.dll" file is found in %System% | No |
| DisableMouse | X | Rundll32.exe Mouse,Disable | Added by the VB-HE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Dialer | X | rundll32.exe MSA32CHK.dll,Reg | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA32CHK.dll" file is located in %System% | No |
| ChansonsMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| ConnectAndDownload | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| ContentDownload | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| CoolDownloads | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| CoolMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| DescargaBromas | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| DesktopUpdate | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| DownloadLegalMusic | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| DownloadMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| DownloadsAndMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| EntraOcio | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| FastDownloads | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| FreeMP3download | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| GetitAll | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| GetMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| GetTheMusic | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| GreatDownloads | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| LosMejoresMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| LotsOfGames | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| LotsOfJokes | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MainDownloads | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MoreContent | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MP3Collection | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MP3download | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MP3files | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MP3freeDownload | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MP3freeDownloads | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MP3nice | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MP3Themes | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| MP3ToTheMax | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| NewDownloads | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| NewMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| NiceDownloads | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| NiceMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| NumberOneMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| ScreenSaverPlus | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| SearchMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| TakeMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| TheBestMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| ThemeMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| UtilitiesAndSoftware | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| YourMP3 | X | rundll32.exe MSA64CHK.dll,DllMostrar | Matrix parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% | No |
| Desktop | X | rundll32.exe msconfd.dll,Restore ControlPanel | Added by the BOOKMARKER TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "msconfd.dll" file is found in %System% | No |
| Mass storage check registry | N | rundll32.exe MSDServ.dll,check registry | Used with a USB based smartmedia card reader | No |
| Rundll32_7 | X | rundll32.exe msiefr40.dll,DllRunServer | Detected by Symantec as Adware.BrowserAid. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "msiefr40.dll" file is located in %System% | No |
| R | X | rundll32.exe msprt.dll | Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Protected Storage | X | RUNDLL32.EXE MSSIGN30.DLL ondll_reg | Added by the LOVGATE-F WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| VFW Encoder/Decoder Settings | X | RUNDLL32.exe MSSIGN30.DLL ondll_reg | Added by the LOVGATE-F WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| zsmscc | X | rundll32.exe mycc071208.dll mymain | Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mycc071208.dll" file is found in %System% | No |
| WinDLL (mysnlive.exe) | X | rundll32.exe mysnlive.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mysnlive.exe" file is found in %System% | No |
| NAVUpd | X | rundll32.exe navupd.dll,Startup | Added by the NAVU TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| notepad | X | rundll32.exe notepad.dll,_IWMPEvents@0 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "notepad.dll" file is found in %System% | No |
| notepad | X | rundll32.exe notepad.dll,_NtLoad@0 | Added by the AGENT-NJZ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "notepad.dll" file is found in %System% | No |
| RFX_auto_upgrade | N | rundll32.exe npvpg005.dll | A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade | No |
| notepad | X | rundll32.exe ntload.dll,_IWMPEvents@0 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ntload.dll" file is found in %UserProfile% | No |
| NvCpl | U | RUNDLL32.EXE NvCpl.dll,NvStartup | If you use a utility (such as RivaTuner) to overclock any of the default display settings (system clock, memory clock, etc) for NVIDIA based graphics chipsets and want to apply these new settings at startup then this entry will maintain these. Leaving this entry enabled doesn't appear to have an impact on startup time. Not required if you use default settings and if you disable this entry you may also have to disable the associated "NVIDIA Display Driver Service" or "NVIDIA Driver Helper Service". Included with drivers since late 2002 | Yes |
| NvCplDaemon | U | RUNDLL32.EXE NvCpl.dll,NvStartup | If you use a utility (such as RivaTuner) to overclock any of the default display settings (system clock, memory clock, etc) for NVIDIA based graphics chipsets and want to apply these new settings at startup then this entry will maintain these. Leaving this entry enabled doesn't appear to have an impact on startup time. Not required if you use default settings and if you disable this entry you may also have to disable the associated "NVIDIA Display Driver Service" or "NVIDIA Driver Helper Service". Included with drivers since late 2002 | Yes |
| NVIDIA Compatible Windows Vista Display driver, Version * | U | RUNDLL32.EXE NvCpl.dll,NvStartup | If you use a utility (such as RivaTuner) to overclock any of the default display settings (system clock, memory clock, etc) for NVIDIA based graphics chipsets and want to apply these new settings at startup then this entry will maintain these. Leaving this entry enabled doesn't appear to have an impact on startup time. Not required if you use default settings and if you disable this entry you may also have to disable the associated "NVIDIA Display Driver Service" or "NVIDIA Driver Helper Service". Included with drivers since late 2002 | Yes |
| NVIDIA Compatible Windows7 Display driver, Version * | U | RUNDLL32.EXE NvCpl.dll,NvStartup | If you use a utility (such as RivaTuner) to overclock any of the default display settings (system clock, memory clock, etc) for NVIDIA based graphics chipsets and want to apply these new settings at startup then this entry will maintain these. Leaving this entry enabled doesn't appear to have an impact on startup time. Not required if you use default settings and if you disable this entry you may also have to disable the associated "NVIDIA Display Driver Service" or "NVIDIA Driver Helper Service". Included with drivers since late 2002 | Yes |
| NVHotkey | U | rundll32.exe nvHotkey.dll | Enables the use of "hot keys" for changing setting on Nvidia graphics | No |
| NVIEW | U | rundll32.exe nview.dll,nViewLoadHook | Part of NVIDIA's NVIEW Display Management Software - included in drivers for consumer and professional graphics products. In earlier drivers this entry enables the Desktop Manager and makes it's features such as multiple desktops and hot keys available to the user. Available via Control Panel → NVIDIA nView Desktop Manager | Yes |
| rundll32 | U | rundll32.exe nview.dll,nViewLoadHook | Part of NVIDIA's NVIEW Display Management Software - included in drivers for consumer and professional graphics products. In earlier drivers this entry enables the Desktop Manager and makes it's features such as multiple desktops and hot keys available to the user. Available via Control Panel → NVIDIA nView Desktop Manager | Yes |
| NvRegisterMCTray | Y | RUNDLL32.EXE NVMCTRAY.DLL,NvMCRegisterApp NvCpl.dll | Registers the NVIDIA Control Panel (NvCpl.dll) via the NVIDIA Media Center Library (NVMCTRAY.DLL) on the first reboot only after the installation of NVIDIA graphics drivers on Win Me/XP. Added with nVidia graphics drivers since GeForce/ION Driver - Release 186. Both files are located in %System% | Yes |
| NvRegisterMCTrayNview | Y | RUNDLL32.EXE NVMCTRAY.DLL,NvMCRegisterApp nView.dll | Registers the NVIDIA Nview Desktop Manager (nView.dll) via the NVIDIA Media Center Library (NVMCTRAY.DLL) on the first reboot only after the installation of NVIDIA graphics drivers on Win Me/XP. Added with nVidia graphics drivers since GeForce/ION Driver - Release 186. Both files are located in %System% | Yes |
| NVIDIA Media Center Library | U | RunDLL32.exe NvMCTray.dll,NvTaskbarInit | Installed with display drivers for NVIDIA based graphics cards since late 2002, this entry allows the System Tray icon to be displayed - which gives access to (amongst others) the display settings (such as Antialiasing, Rotation and Colour) and the Desktop Manager (nView). If you don't change display settings very often then this is not required and settings can be changed manually via display properties. No tray icon option is available in Vista. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest" | Yes |
| NVMCTRAY | U | RunDLL32.exe NvMCTray.dll,NvTaskbarInit | Installed with display drivers for NVIDIA based graphics cards since late 2002, this entry allows the System Tray icon to be displayed - which gives access to (amongst others) the display settings (such as Antialiasing, Rotation and Colour) and the Desktop Manager (nView). If you don't change display settings very often then this is not required and settings can be changed manually via display properties. No tray icon option is available in Vista. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest" | Yes |
| NvMediaCenter | U | RunDLL32.exe NvMCTray.dll,NvTaskbarInit | Installed with display drivers for NVIDIA based graphics cards since late 2002, this entry allows the System Tray icon to be displayed - which gives access to (amongst others) the display settings (such as Antialiasing, Rotation and Colour) and the Desktop Manager (nView). If you don't change display settings very often then this is not required and settings can be changed manually via display properties. No tray icon option is available in Vista. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest" | Yes |
| RunDLL32 | U | RunDLL32.exe NvMCTray.dll,NvTaskbarInit | Installed with display drivers for NVIDIA based graphics cards since late 2002, this entry allows the System Tray icon to be displayed - which gives access to (amongst others) the display settings (such as Antialiasing, Rotation and Colour) and the Desktop Manager (nView). If you don't change display settings very often then this is not required and settings can be changed manually via display properties. No tray icon option is available in Vista. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest" | Yes |
| NvCplDaemon | U | RUNDLL32.EXE NvQTwk,NvCplDaemon | Installed with display drivers for NVIDIA based graphics cards prior to late 2002, this entry allows the System Tray icon to be displayed - which gives access to (amongst others) the display settings (such as Antialiasing, OpenGL, Direct3D and colour) and Desktop Manager (nView). If you don't change display settings very often then this is not required and settings can be changed manually via display properties | Yes |
| RUNDLL32 | U | RUNDLL32.EXE NvQTwk,NvCplDaemon | Installed with display drivers for NVIDIA based graphics cards prior to late 2002, this entry allows the System Tray icon to be displayed - which gives access to (amongst others) the display settings (such as Antialiasing, OpenGL, Direct3D and colour) and Desktop Manager (nView). If you don't change display settings very often then this is not required and settings can be changed manually via display properties | Yes |
| NvColorInit | ? | rundll32.exe NvQtwk.dll,NvColorInit | Associated with Nvidia based graphics cards | No |
| NvidiaQuickTweak | N | rundll32.exe NvQtwk.dll,NvTaskbarInit | System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties | No |
| NVQuickTweak | N | rundll32.exe NvQtwk.dll,NvTaskbarInit | System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties | No |
| NvInitialize | N | rundll32.exe NvQtwk.dll,NvXTInit | Thought to enable the clock frequency option on nVidia control panels. You can overclock without leaving this enabled | No |
| NVIDIA Driver Helper Service, Version * | U | RUNDLL32.EXE nvsvc.dll,nvsvcStart | Initially installed with Vista display drivers for NVIDIA based graphics cards. This entry replaced the "NVIDIA Display Driver Service" or "NVIDIA Driver Helper Service" in XP - which was used in part to maintain overclocked display settings. In a GeForce 8800GT test system this isn't the case. Disabling it caused no ill effects but it's exact purpose isn't known - hence the "U" recommendation | Yes |
| NvSvc | U | RUNDLL32.EXE nvsvc.dll,nvsvcStart | Initially installed with Vista display drivers for NVIDIA based graphics cards. This entry replaced the "NVIDIA Display Driver Service" or "NVIDIA Driver Helper Service" in XP - which was used in part to maintain overclocked display settings. In a GeForce 8800GT test system this isn't the case. Disabling it caused no ill effects but it's exact purpose isn't known - hence the "U" recommendation | Yes |
| nxgsvc | X | rundll32.exe nxgsvc.dll,start | Detected by Trend Micro as WORM_AKBOT.BA. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "nxgsvc.dll" file is found in %System% | No |
| nxosys | X | rundll32.exe nxosys.dll,start | Detected by Trend Micro as WORM_AKBOT.BD. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "nxosys.dll" file is found in %System% | No |
| OfotoNow USB Detection | N | Rundll32.exe OFUSBS.dll,WatchForConnection OfotoNow | Autodetects when a digital camera is attached to a USB port and launches the OfotoNow imaging software (now Kodak Gallery. Available via Start → All Programs | No |
| oo4 | X | RunDLL32.EXE oo4.dll,DllRun | BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "oo4.dll" file is located in %Windir% | No |
| Microsoft® Windows® Operating System | N | rundll32.exe oobefldr.dll,ShowWelcomeCenter | Shows the Welcome Center every time you boot into Windows Vista - which "pulls all the tasks you'll most likely want to complete when you set up your computer into a single location" | Yes |
| WindowsWelcomeCenter | N | rundll32.exe oobefldr.dll,ShowWelcomeCenter | Shows the Welcome Center every time you boot into Windows Vista - which "pulls all the tasks you'll most likely want to complete when you set up your computer into a single location" | Yes |
| PD0620 STISvc | U | RunDLL32.exe P0620Pin.dll,RunDLL32EP 513 | Related to the Creative WebCam Instant. The "P0620Pin.dll" file description is "Installation Plug-In". What does it do and is it required? | No |
| PD0630 STISvc | ? | RunDLL32.exe P0630Pin.dll,RunDLL32EP 513 | Related to the Creative WebCam Live!. The "P0630Pin.dll" file description is "Installation Plug-In". What does it do and is it required? | No |
| PD0870 STISvc | ? | RunDLL32.exe P0870Pin.dll,RunDLL32EP 513 | Related to the Creative WebCam Live! Motion. The "P0870Pin.dll" file description is "Installation Plug-In". What does it do and is it required? | No |
| Instant Access | X | rundll32.exe p2esocks_****.dll,InstantAccess [**** = digits] | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| USB2Check | N | RUNDLL32.EXE PCLECoInst.dll | Related to products from Pinnacle Systems. CoInstaller - you can execute the USB2.0 interface check program (Usb2Check.exe file) to check if your system is a USB2.0 enabled system | No |
| LoadPowerScheme | X | rundll32.exe powerprof.dll CheckPowerProfile | Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| LoadPowerProfile | U | Rundll32.exe powrprof.dll | Power management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel → Power Options settings | No |
| wupipenimi | X | Rundll32.exe poyimimu.dll,s | Added by the VUNDO.JD.DLL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "poyimimu.dll" file is found in %System% | No |
| autochk | X | rundll32.exe protect.dll,_IWMPEvents@16 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "protect.dll" file is found in %UserProfile% | No |
| PtiuPbmd | U | Rundll32.exe ptipbm.dll,SetWriteBack | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. Tells the drivers that the connected Drives should use the "Write Back" Caching. You can disable this if you don't want to use "Write Back" Caching or if you have not connected any driver to your Promise Controller | No |
| Rundll32 | U | Rundll32.exe ptipbm.dll,SetWriteBack | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. Tells the drivers that the connected Drives should use the "Write Back" Caching. You can disable this if you don't want to use "Write Back" Caching or if you have not connected any driver to your Promise Controller | No |
| Ptipbmf | ? | rundll32.exe ptipbmf.dll,SetWriteCacheMode | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller | No |
| rundll32 | ? | rundll32.exe ptipbmf.dll,SetWriteCacheMode | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller | No |
| SetCacheMode | ? | rundll32.exe ptipbmf.dll,SetWriteCacheMode | Installed with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller | No |
| PTRGMYGK | X | rundll32.exe ptmg1v.dll,DllRunMain | Added by an unidentified TROJAN, WORM or other malware! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| ForceShow | X | rundll32.exe QaBar.dll,ForceShowBar | AdultLinks.QBar parasite related! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "QaBar.dll" file is found in %System% | No |
| qkoszvd.dll | X | rundll32.exe qkoszvd.dll,jwezubg | Added by the DLOADR-AVD TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "qkoszvd.dll" file is located in %System% | No |
| WinDLL (qwex.dll) | X | rundll32.exe qwex.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "qwex.dll" file is found in %System% | No |
| readdb40 | X | rundll32.exe readdb40.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "readdb40.dll" file is found in %System% | No |
| WinDLL (redyLive.exe) | X | rundll32.exe redyLive.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "redyLive.exe" file is found in %System% | No |
| Module Call initialize | X | RUNDLL32.EXE reg.dll,ondll_reg | Detected by Symantec as W32.HLLW.Lovgate.C@mm. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "reg.dll" file is located in %System% | No |
| Remote Procedure Call Locator | X | RUNDLL32.EXE reg678.dll ondll_reg | Detected by Trend Micro as WORM_LOVGATE.F. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| LoadHTML | X | rundll32.exe regsvr32.exe,MShtmpre | MatrixSearch adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| govurarope | X | Rundll32.exe retasevo.dll,s | Detected by Sophos as Troj/BHO-HG. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "retasevo.dll" file is found in %System% | No |
| logonUiInit | X | Rundll32.exe rgtndz.dll | Identified as a variant of the Trojan-Clicker.Win32.Agent.bqy malware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "rgtndz.dll" file is found in %System% | No |
| ctfmon.exe | X | rundll32.exe riwli.dat | Detected by Sophos as Mal/Ransom-AJ. Note - this is not the legitimate rundll32.exe process, which is found in %Windir% (Me/98) or %System% (7/Vista/XP/2K/NT). Both files are located in %CommonAppData% | No |
| rmdrfje.dll | X | rundll32.exe rmdrfje.dll,[random characters] | Added by the DLOADR-ANM TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "rmdrfje.dll" file is located in %Windir% | No |
| run | X | rundll32.exe rsrc.dll | Chinese originated browser hijacker - redirecting to 4199.com Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| RUSBHOLoader | ? | rundll32.exe RUSBHOLoader.dll,AutoRegister | ?? | No |
| saSyncMgr | X | rundll32.exe sasync.dll,SyncWait | Browser hijacker - redirecting to Searchant.com. Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup". Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Savsvc | X | rundll32.exe savsvc.dll,start | Detected by Trend Micro as WORM_AKBOT.BE. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "savsvc.dll" file is found in %System% | No |
| WinDLL (scvhost32.dll) | X | rundll32.exe scvhost32.dll,start | Detected by Trend Micro as WORM_AKBOT.M. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "scvhost32.dll" file is found in %System% | No |
| Compaq Computer Security | ? | Rundll32.exe SECURE32.CPL, Service | ?? | No |
| Network | X | rundll32.exe shell32.dll,Control_RunDLL network.cpl | Detected by Dr.Web as Trojan.DownLoader7.2129 and by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "network.cpl" file is located in %System% | No |
| [random number] | X | rundll32.exe shell32.dll,Control_RunDLL [random number].cpl | Detected by Symantec as W32.Kitro.C.Worm and by Trend Micro as WORM_DANDI.A. Note that rundll32.exe and shell32.dll are legitimate Microsoft files and shouldn't be deleted. The "[random number].cpl" file is located in %Windir% | No |
| si91e44b | X | rundll32.exe si91e44b.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "si91e44b.dll" file is found in %System% | No |
| LoadSIPS | X | rundll32.exe SIPSPI32.dll,SIPSPI32 | 123Mania adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SIPSPI32.dll" file is found in the System folder | No |
| wupipenimi | X | Rundll32.exe siremase.dll,s | Added by the VUNDO.JD.DLL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "siremase.dll" file is found in %System% | No |
| SiSPower | Y | Rundll32.exe SiSPower.dll,ModeAgent | Power scheme manager for Silicon Integrated Systems (SiS) based mobile chipsets | Yes |
| WinDLL (slmss.exe) | X | rundll32.exe slmss.exe,start | Detected by Trend Micro as WORM_AKBOT.AW. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "slmss.exe" file is found in %System% | No |
| WinDLL (slsass.exe) | X | rundll32.exe slsass.exe,start | Detected by Kaspersky as Backdoor.Win32.Akbot.e. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "slsass.exe" file is found in %System% | No |
| WinDLL (smaprnter.exe) | X | rundll32.exe smaprnter.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "smaprnter.exe" file is found in %System% | No |
| Samsung MJC-900 Series Monitor | U | RUNDLL32.EXE SMMASHLL.DLL,AutoUpdatePnPValue | Samsung MJC-900 Series multi-function printer monitor - monitors ink levels, paper present and other parameters | No |
| WinDLL (smms.exe) | X | rundll32.exe smms.exe,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "smms.exe" file is found in %System% | No |
| Systems Restart | X | Rundll32.exe snim.dll,DllRegisterServer | Added by the STARTPAGE.I TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| spa_start | X | Rundll32.exe spads.dll | IconAds adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "spads.dll" file is located in %Windir% | No |
| spa_start | X | Rundll32.exe sprt_ads.dll | Superiorads adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sprt_ads.dll" file is located in %System% | No |
| sre | X | rundll32.exe sre.dll,Register | CoolWebSearch parasite variant - also detected by Kaspersky as the AGENT.FC TROJAN! | No |
| WinDll (sslms.exe) | X | rundll32.exe sslms.exe,start | Added by the AKBOT-AS WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sslms.exe" file is found in %System% | No |
| WinDLL (start0s.exe) | X | rundll32.exe start0s.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "start0s.exe" file is found in %System% | No |
| WinDLL (steam.dll) | X | rundll32.exe steam.dll,start | Detected by Trend Micro as WORM_AKBOT.M. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "steam.dll" file is found in %System% | No |
| WIAWizardMenu | N | RUNDLL32.EXE sti_ci.dll,WiaCreateWizardMenu | Still Image Class Installer - installed with a webcam | No |
| {12EE7A5E-0674-42f9-A76B-000000004D00} | X | rundll32.exe stlb2.dll, DllRunMain | Detected by Symantec as Adware.BrowserAid. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "stlb2.dll" file is located in %System% | No |
| {2CF0B992-5EEB-4143-99C0-5297EF71F444} | X | rundll32.exe stlbdist.dll,DllRunMain | BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "stlbdist.dll" file is found in %System% | No |
| {2CF0B992-5EEB-4143-99C2-5297EF71F44B} | X | rundll32.exe stlbupdt.DLL,DllRunMain | Detected by Symantec as Adware.BrowserAid. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "stlbupdt.dll" file is found in %System% | No |
| stlbupdt | X | rundll32.exe stlbupdt.DLL,DllRunMain | Detected by Symantec as Adware.BrowserAid. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "stlbupdt.dll" file is found in %System% | No |
| AdslTaskBar | Y | rundll32.exe stmctrl.dll,TaskBar | ISP software, initializes DSL modem | No |
| Ccdecode | N | rundll32.exe streamci, StreamingDeviceSetup | Part of the closed caption decdoder/MS VBI codec. Should only run once | No |
| supdate2.dll | X | rundll32.exe supdate2.dll,Run | Added by the ZLOB-VL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "supdate2.dll" file is found in %System% | No |
| WinDLL (svc.exe) | X | rundll32.exe svc.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "svc.exe" file is found in %System% | No |
| WinDLL (svchost.dll) | X | rundll32.exe svchost.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "svchost.dll" file is found in %System% | No |
| System Check | U | Rundll32.exe SysDll32.dll,SystemCheck | XPCSpy Pro keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| SystemHelp | X | RUNDLL32.EXE SystemHper.dll,Install | Added by the WOW.COK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SystemHper.dll" file is found in %System% | No |
| WinDLL (sysx32.dll) | X | rundll32.exe sysx32.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sysx32.dll" file is found in %System% | No |
| wupipenimi | X | Rundll32.exe tamuyiko.dll,s | Added by an unidentified VIRUS, WORM or TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tamuyiko.dll" file is found in %System% | No |
| Tcsvc | X | rundll32.exe tcsvc.dll,start | Detected by Trend Micro as BKDR_AGENT.BCL. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tcsvc.dll" file is located in %System% | No |
| WinDLL (tepmlayer.exe) | X | rundll32.exe tepmlayer.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tepmlayer.exe" file is found in %System% | No |
| WinDLL (tmp.exe) | X | rundll32.exe tmp.exe,start | Added by the KOLAB.L WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tmp.exe" file is found in %System% | No |
| WinDLL (tock24.dll) | X | rundll32.exe tock24.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tock24.dll" file is found in %System% | No |
| WinDLL (tqurity.exe) | X | rundll32.exe tqurity.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tqurity.exe" file is found in %System% | No |
| transys | X | rundll32.exe transys.dll,start | Added by the AKBOT-AE WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "transys.dll" file is found in %System% | No |
| wupipenimi | X | Rundll32.exe tuduriro.dll,s | Added by the MONDER.BZEA TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tuduriro.dll" file is found in %System% | No |
| Tweak UI | U | RUNDLL32.EXE TWEAKUI.CPL,TweakLogon | Automatically logs you on if you have Microsoft's Tweak UI "powertoy" for Win9x/Me/2k installed. This version can also be installed in WinXP but isn't recommended - see here | No |
| Tweak UI 1.33 deutsch | U | RUNDLL32.EXE TWEAKUI.CPL,TweakLogon | Automatically logs you on if you have Microsoft's Tweak UI "powertoy" for Win9x/Me/2k installed - German version. This version can also be installed in WinXP but isn't recommended - see here | No |
| Tweak UI | U | RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp | Restores settings that can't be retained if you have Microsoft's Tweak UI "powertoy" for Win9x/Me/2k installed. This version can also be installed in WinXP but isn't recommended - see here | No |
| Tweak UI 1.33 deutsch | U | RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp | Restores settings that can't be retained if you have Microsoft's Tweak UI "powertoy" for Win9x/Me/2k installed - German version. This version can also be installed in WinXP but isn't recommended - see here | No |
| UCmore XP - The Search Accelerator | U | rundll32.exe UCMTSAIE.dll,DllShowTB | UCmore toolbar - search accelerator | No |
| uhvjsul.dll | X | rundll32.exe uhvjsul.dll,mrpmvyf | Added by the BUSKY-G TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "uhvjsul.dll" file is found in %System% | No |
| ShutDownWindows | X | Rundll32.exe User,ExitWindows | Added by the VB-HE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| utasvc | X | rundll32.exe utasvc.dll,start | Added by the AKBOT-AB WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "utasvc.dll" file is found in %System% | No |
| VF0060 STISvc | ? | RunDLL32.exe V0060Pin.dll,RunDLL32EP 513 | Related to the Creative WebCam Live! Ultra. The "V0060Pin.dll" file description is "Installation Plug-In". What does it do and is it required? | No |
| VF0070 STISvc | ? | RunDLL32.exe V0070Pin.dll,RunDLL32EP 513 | Related to the Creative WebCam Live! Ultra for Notebooks. The "V0070Pin.dll" file description is "Installation Plug-In". What does it do and is it required? | No |
| V128IITV | ? | Rundll32.exe v128iitv.dll,STBTV_SwitchTo640x480 | Loads drivers for some STB graphics cards. May be used for such a card with a TV out option to change the resolution to 640 x 480? | No |
| V128IID | Y | Rundll32.exe v128iitw.dll,STB_InitTweak | Loads drivers for some STB graphics cards such as the STB nVIDIA TNT 16MB. Required if you don't want to experience lock-ups or error messages | No |
| WinDLL (v4mon.dll) | X | rundll32.exe v4mon.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "v4mon.dll" file is found in %System% | No |
| wupipenimi | X | Rundll32.exe vafefudo.dll,s | Added by the MONDER.BZEA TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vafefudo.dll" file is found in %System% | No |
| WinDLL (vdm32.dll) | X | rundll32.exe vdm32.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vdm32.dll" file is found in %System% | No |
| WinDLL (vxd32.dll) | X | rundll32.exe vxd32.dll,start | Detected by Trend Micro as WORM_AKBOT.R. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vxd32.dll" file is found in %System% | No |
| W3KNetwork | X | rundll32.exe w3knet.dll,dllinitrun | Web3000 adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| WinDLL (wchshield.exe) | X | rundll32.exe wchshield.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wchshield.exe" file is found in %System% | No |
| Startwd | X | rundll32.exe wd081025.dll,Hook | Added by the AGENT.DE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wd081025.dll" file is found in %System% | No |
| Winfast2KLoadDefault | U | rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings | Loads default settings for Leadtek Winfast graphics cards | Yes |
| WinFast_Gamma | U | Rundll32.exe wfcpl.dll,DllLoadGammaRampSettings | Loads if you change the gamma settings on Leadtek WinFast graphics cards | No |
| WinFast_Taskbar | U | rundll32.exe wftask.dll,WFDllLoadDefaultSettings | Loads default settings for Leadtek WinFast graphics cards | No |
| WinHacker | N | rundll32.exe wh95.dll,HackMe | WinHacker tweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free | No |
| WinDLL (wimimi.exe) | X | rundll32.exe wimimi.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wimimi.exe" file is found in %System% | No |
| mscheck | X | rundll32.exe wincheck071008.dll mymain | Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wincheck071008.dll" file is located in %System% | No |
| wincls | X | rundll32.exe wincls.dll,start | Added by the AKBOT-AR WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wincls.dll" file is found in %System% | No |
| WinDLL (windns32.dll) | X | rundll32.exe windns32.dll,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "windns32.dll" file is found in %System% | No |
| WindowsNetsDll | X | rundll32.exe WindowsNetsDll.dll | Added by the MDROP-DEK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "WindowsNetsDll.dll" file is located in %UserProfile%\Microsoft | No |
| WinDLL (wingatey32.exe) | X | rundll32.exe wingatey32.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wingatey32.exe" file is found in %System% | No |
| Userinit | X | rundll32.exe winsys16_070813.dll | Detected by Sophos as W32/AutoRun-C and by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "winsys16_070813.dll" file is found in %System% | No |
| WinDLL (wintcp.exe) | X | rundll32.exe wintcp.exe,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wintcp.exe" file is found in %System% | No |
| WinDLL (wintmp.exe) | X | rundll32.exe wintmp.exe,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wintmp.exe" file is found in %System% | No |
| wm41a398 | X | rundll32.exe wm41a398.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wm41a398.dll" file is found in %System% | No |
| wmcbaaca | X | rundll32.exe wmcbaaca.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wmcbaaca.dll" file is found in %System% | No |
| wrclib | X | rundll32.exe wrclib.dll,start | Added by the AKBOT-AH WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wrclib.dll" file is found in %System% | No |
| WinDLL (Wseclayer.exe) | X | rundll32.exe Wseclayer.exe,start | Added by the AKBOT.E BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Wseclayer.exe" file is found in %System% | No |
| WinDLL (wsync32.dll) | X | rundll32.exe wsync32.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wsync32.dll" file is found in %System% | No |
| wtzlank.dll | X | rundll32.exe wtzlank.dll,qttwuwc | DisableKey adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wtzlank.dll" file is found in %System% | No |
| Windows Update Svc | X | rundll32.exe xpupdate.dll | ContraVirus rogue security software - not recommended, removal instructions here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "xpupdate.dll" file is located in %System% | No |
| WinDLL (xvd32.dll) | X | rundll32.exe xvd32.dll,start | Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "xvd32.dll" file is found in %System% | No |
| wupipenimi | X | Rundll32.exe yidurufo.dll,s | Added by the VUNDO.HTI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "yidurufo.dll" file is found in %System% | No |
| Systems Restart | X | Rundll32.exe zolk.dll,DllRegisterServer | Added by a variant of the STARTPAGE TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| zsmscc | X | rundll32.exe zsmscc071001.dll mymain | Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "zsmscc071001.dll" file is found in %System% | No |
| (default) | X | rundll32.exe [path to DLL file],Do98Work | Added by the HESIVE.B TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run, HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| dnheds | X | rundll32.exe [path to trojan] | Added by the ONLINEGAMES.XFCK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| wdvcnx | X | rundll32.exe [path to trojan] | Added by the ONLINEGAMES.XEGT TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| NvCplDaemonTool | X | rundll32.exe [path] adload4C.dll,_IWMPEvents | Added by the AGENT-QXD TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "adload4C.dll" file is located in %System% | No |
| AgerePadClock | X | rundll32.exe [path] AgerePadClock.dll | Added by the SEFNIT TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "AgerePadClock.dll" file is found in %AppData%\acxmapdb | No |
| altsi | X | rundll32.exe [path] altsi.dll,PixelMap | Detected by Malwarebytes Anti-Malware as Spyware.Password. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "altsi.dll" file is found in %AppData% | No |
| apanli | X | rundll32.exe [path] apanli.dll | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "apanli.dll" file is located in %AppData% | No |
| apcat | X | rundll32.exe [path] apcat.dll | Detected by Malwarebytes Anti-Malware as Trojan.RedirRdll2.Gen. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "apcat.dll" file is located in %AppData% | No |
| AW TrayIcon | X | RunDll32.exe [path] arcadeweb32.dll | ArcadeWeb adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "arcadeweb32.dll" file is located in %ProgramFiles%\ArcadeWeb | No |
| ASK | U | rundll32.exe [path] ASK.dll rdl | Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| CognizanceTS | U | rundll32.exe [path] AsTsVcc.dll,RegisterModule | Cognizance Corp Identity And Access Management suite for corporate VPN connections. Enable if you use the VPN software | No |
| BatInfEx | U | rundll32.exe [path] BatInfEx.dll,BMMAutonomicMonitor | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. This entry is needed for the battery information and monitoring program as well as the Battery Maximizer Wizard | Yes |
| BMMMONWND | U | rundll32.exe [path] BatInfEx.dll,BMMAutonomicMonitor | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. This entry is needed for the battery information and monitoring program as well as the Battery Maximizer Wizard | Yes |
| BatLogEx | U | rundll32.exe [path] BatLogEx.DLL,StartBattLog | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. This entry logs changes in battery conditions such as charging, discharging, life, etc | Yes |
| BLOG | U | rundll32.exe [path] BatLogEx.DLL,StartBattLog | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. This entry logs changes in battery conditions such as charging, discharging, life, etc | Yes |
| BIE | X | Rundll32.exe [path] BDSrHook.dll,Rundll32 | BDplugin parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Acronis Popup Blocker | U | RunDll32.exe [path] Blocker.dll,Run | Part of Acronis Privacy Expert - anti-spyware and security suite | No |
| msav | ? | rundll32.exe [path] bnnhjx.dll | Related to Bitrix security products | No |
| brauns | X | rundll32.exe [path] brauns.dll,StrToUintW | Detected by Malwarebytes Anti-Malware as Trojan.Midhos. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "brauns.dll" file is found in %AppData% | No |
| Bridge | X | rundll32.exe [path] Bridge.dll,Load | WinFavorites adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Bridge.dll" file is located in %System% | No |
| RunDLL | X | rundll32.exe [path] Bridge.dll,Load | WinFavorites adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Bridge.dll" file is located in %System% | No |
| cesmain.dll | X | Rundll32.exe [path] cmail.dll,Rundll32 | CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cmail.dll" file is located in %ProgramFiles%\3721\Ces | No |
| CnsMin | X | Rundll32.exe [path] CNSMIN.dll,Rundll32 | CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| cobvcs | X | rundll32.exe [path] cobvcs.dll | Detected by Malwarebytes Anti-Malware as Trojan.RedirRdll2.Gen. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "cobvcs.dll" file is located in %AppData% | No |
| dordi | X | rundll32.exe [path] dordi.dll,Init | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "dordi.dll" file is found in %AppData% | No |
| Netscape | X | Rundll32.exe [path] drjgudct.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "drjgudct.dll" file is located in %LocalAppData%\Netscape | No |
| Eapobjmon | X | rundll32.exe [path] Eapobjmon.dll,WdMapSnap d3dGLCres | Added by the DWNLDR-ITR TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Eapobjmon.dll" file is located in %ApplData%\SystemMapTray | No |
| fpsfx | X | rundll32.exe [path] fpsfx.dll | Detected by Malwarebytes Anti-Malware as Spyware.Password. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "fpsfx.dll" file is located in %AppData% | No |
| fvceg | X | rundll32.exe [path] fvceg.dll | Detected by Malwarebytes Anti-Malware as Trojan.RedirRdll2.Gen. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "fvceg.dll" file is located in %AppData% | No |
| fxapimm | X | rundll32.exe [path] fxapimm.dll | Detected by Sophos as Troj/Mdrop-DKE. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "fxapimm.dll" file is located in %LocalAppData%\appMaindb | No |
| RichMedia | X | rundll32.exe [path] hbcast.dll,WaitWindows | Henbang adware variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| RichMedia | X | Rundll32.exe [path] HBHelper.dll | HenBang adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "HBHelper.dll" file is located in %ProgramFiles%\hbclient | No |
| helper.dll | X | rundll32.exe [path] helper.dll | CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "helper.dll" file is located in %ProgramFiles%\3721 | No |
| Disker | X | rundll32.exe [path] HIMYM.DLL | Detected by Dr.Web as Trojan.DownLoader4.63430 and by Malwarebytes Anti-Malware as Trojan.Onlinegames. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "HIMYM.DLL" file is found in %Temp% | No |
| IKL | U | rundll32.exe [path] IKL.dll | IKL surveillance software. Uninstall this software unless you put it there yourself | No |
| Egiciwuvubom | X | rundll32.exe [path] ilscac.dll | Added by the HILOTI-CS TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ilscac.dll" file is located in %Windir% | No |
| IWL | U | rundll32.exe [path] IWL.dll | IKL surveillance software. Uninstall this software unless you put it there yourself | No |
| *J7PugHy | X | rundll32.exe [path] IZsROY7X.-MP | Detected by Trend Micro as WORM_MORCUT.A. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "IZsROY7X.-MP" file is located in %UserProfile%\Local Settings\jlc3V7we | No |
| Egiciwuvubom | X | rundll32.exe [path] kbinph.dll | Added by the HILOTI-CL TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "kbinph.dll" file is located in %Windir% | No |
| KEI | U | rundll32.exe [path] KEI.dll | IKL surveillance software. Uninstall this software unless you put it there yourself | No |
| lpc | X | rundll32.exe [path] kwbn45.dll | Added by the BANKSUN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "kwbn45.dll" file is located in %AppData%\Sun | No |
| [8 characters] | X | rundll32.exe [path] laa.dll | Detected by Malwarebytes Anti-Malware as Spyware.Banker. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "laa.dll" file is located in %AppData% | No |
| lpsps | X | rundll32.exe [path] lpsps.dll | Detected by Malwarebytes Anti-Malware as Trojan.RedirRdll2.Gen. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "lpsps.dll" file is located in %AppData% | No |
| manec | X | rundll32.exe [path] manec.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent.DKY. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "manec.dll" file is located in %AppData% | No |
| Egiciwuvubom | X | rundll32.exe [path] marpapv.dll | Added by the HILOTI-BV TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "marpapv.dll" file is located in %Windir% | No |
| MicrosoftOnlineOnline | X | rundll32.exe [path] MicrosoftOnlineOnline.dll | Added by the TRACUR-C MALWARE! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MicrosoftOnlineOnline.dll" file is found in %CommonAppData% | No |
| mpapr | X | rundll32.exe [path] mpapr.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mpapr.dll" file is located in %AppData% | No |
| Disker | X | rundll32.exe [path] MS2011Helper.DLL | Detected by Dr.Web as Trojan.DownLoader2.64512 and by Malwarebytes Anti-Malware as Trojan.Onlinegames. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MS2011Helper.DLL" file is found in %Temp% | No |
| Egiciwuvubom | X | rundll32.exe [path] msftrelg.dll | Added by the AGENT-TEN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "msftrelg.dll" file is located in %Windir% | No |
| msPathTime | X | rundll32.exe [path] msPathTime.dll | Detected by Malwarebytes Anti-Malware as IPH.Trojan.Blueinit. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "msPathTime.dll" file is located in %AppData%\mfcGLCtrl | No |
| MSxmlHpr | X | RUNDLL32.EXE [path] msxm192z.dll,w | Added by the Infostealer.Wowcraft keylogger! | No |
| muryne | X | rundll32.exe [path] muryne.dll | Detected by Malwarebytes Anti-Malware as Trojan.Midhos. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "muryne.dll" file is located in %AppData% | No |
| Netscape | X | Rundll32.exe [path] mxtfrulf.dll | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "mxtfrulf.dll" file is located in %LocalAppData%\Netscape | No |
| BelNotify | U | rundll32.exe [path] NPBelv32.dll,RunDll32_BelNotify | "BelTech from Belarc enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service" | No |
| calc | X | rundll32.exe [path] ntuser.dll,_IWMPEvents@0 | Added by the OPACHKI.A TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ntuser.dll" file is located in %UserProfile% | No |
| odbcMouseSvcs | X | rundll32.exe [path] odbcMouseSvcs.dll,winEventlib | Detected by Sophos as Troj/Sefnit-J. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "odbcMouseSvcs.dll" file is located in %LocalAppData%\mfcobjPlay | No |
| psext | X | rundll32.exe [path] psext.dll | Detected by Malwarebytes Anti-Malware as Trojan.RedirRdll2.Gen. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "psext.dll" file is located in %AppData% | No |
| rerap | X | rundll32.exe [path] rerap.dll | Detected by Dr.Web as Trojan.DownLoader7.16415. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "rerap.dll" file is located in %AppData% | No |
| rfdvng | X | rundll32.exe [path] rfdvng.dll | Detected by Dr.Web as Trojan.DownLoader7.10023 and by Malwarebytes Anti-Malware as Trojan.Medfos. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "rfdvng.dll" file is located in %AppData% | No |
| sbasc | X | rundll32.exe [path] sbasc.dll | Detected by Malwarebytes Anti-Malware as Trojan.RedirRdll2.Gen. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "sbasc.dll" file is located in %AppData% | No |
| setoc | X | rundll32.exe [path] setoc.dll | Detected by Malwarebytes Anti-Malware as Trojan.RedirRdll2.Gen. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "setoc.dll" file is located in %AppData% | No |
| smx4pnp | X | rundll32.exe [path] smx4pnp.dll | Added by the SASFIS.VR TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| srePostpone | ? | rundll32.exe [path] srescan.dll,DoSpecialAction | Related to ZoneAlarm. What does it do and is it required? | No |
| StopSignSsFwMon | U | Rundll32.exe [path] ssfwmon.dll,VerifyStatus | eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendation | No |
| byywttsys | X | rundll32.exe [path] ssrstu.dll | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ssrstu.dll" file is located in %System% | No |
| gedcbbsys | X | rundll32.exe [path] ssrstu.dll | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ssrstu.dll" file is located in %System% | No |
| StopSignSsSsMon | U | Rundll32.exe [path] ssssmon.dll,VerifyStatus | eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendation | No |
| StopSignSsTsMon | U | Rundll32.exe [path] sstsmon.dll,VerifyStatus | eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendation | No |
| stipc | X | rundll32.exe [path] stipc.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "stipc.dll" file is located in %AppData% | No |
| StopSignStatus | U | Rundll32.exe [path] stopsinfo.dll,VerifyStatus | Installer for eAcceleration Stop-Sign security software - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendation | No |
| strFree | X | rundll32.exe [path] strFree.dll | Detected by Sophos as Troj/Mdrop-DRG. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "strFree.dll" file is located in %UserProfile%\Microsoft | No |
| SWL | U | rundll32.exe [path] SWL.dll rdl | StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Sysmppcvppp | X | rundll32.exe [path] SysTdSvr.dll | Detected by Kaspersky as AdWare.Win32.NewWeb.x. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "SysTdSvr.dll" file is found in %System% | No |
| systemdrea | X | rundll32.exe [path] systemdrea.dll | Added by the AGENT-RKB TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "systemdrea.dll" file is located in %UserProfile%\Microsoft | No |
| SystemKey | U | rundll32.exe [path] SystemKey.dll rdl | Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| SystemMessenger | X | rundll32.exe [path] SystemMessenger.dll | Stealth Chat Monitor spyware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| SystemWeb | U | rundll32.exe [path] SystemWeb.dll rdl | StealthWeblog surveillance software. Uninstall this software unless you put it there yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| IE Menu Extension toolbar | X | rundll32.exe [path] tbextn.dll DllShowTB | IEMenuExt trackware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Games toolbar | X | rundll32.exe [path] tbGame.dll DllShowTB | Topconverting.com/180Search "Games Toolbar" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Authentic-ID Toolbar | Y | rundll32.exe [path] ToolbarATL.dll,LoadTrayIcon | Authentic-ID Toolbar - website authentication utility. Warns you when a site is recognized for phishing or isn't authentic, for example | No |
| IDAVLab | X | Rundll32.exe [path] ueqfjttz.dll | Detected by Malwarebytes Anti-Malware as Trojan.Reveton. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ueqfjttz.dll" file is located in %LocalAppData%\IDAVLab | No |
| Rundll32 | X | Rundll32.exe [path] unicode2.nls | Detected by Dr.Web as Trojan.Siggen4.39246 and by Malwarebytes Anti-Malware as Trojan.Backdoor. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "unicode2.nls" file is located in %AppData%\Microsoft\Windows | No |
| Egiciwuvubom | X | rundll32.exe [path] upesvt.dll | Added by the AGENT-TEO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "upesvt.dll" file is located in %Windir% | No |
| upnits | X | rundll32.exe [path] upnits.dll | Detected by Malwarebytes Anti-Malware as Trojan.RedirRdll2.Gen. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "upnits.dll" file is located in %AppData% | No |
| V3smx4pnp | X | rundll32.exe [path] V3smx4pnp.dll | Detected by Symantec as Trojan.Smaxin. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "V3smx4pnp.dll" file is found in %UserProfile%\Microsoft | No |
| vdAHBMyiRUZlHK | X | rundll32.exe [path] vdAHBMyiRUZlHK.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "vdAHBMyiRUZlHK.dll" file is located in %UserTemp%\vdAHBMyiRUZlHK | No |
| wehloi | X | rundll32.exe [path] wehloi.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wehloi.dll" file is located in %AppData% | No |
| wilsg | X | rundll32.exe [path] wilsg.dll,ARawDecodeInit | Detected by Dr.Web as Trojan.DownLoader8.18141. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wilsg.dll" file is located in %AppData% | No |
| wilsg | X | rundll32.exe [path] wilsg.dll,New | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wilsg.dll" file is located in %AppData% | No |
| wilsg | X | rundll32.exe [path] wilsg.dll,SetScissorRect | Detected by Dr.Web as Trojan.DownLoader8.15853. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wilsg.dll" file is located in %AppData% | No |
| WindosSysDrivers | X | rundll32.exe [path] WindosSysDrivers.dll | Added by the PWS-BOB TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "AgerePadClock.dll" file is found in %UserProfile%\Microsoft | No |
| WinFlyer32.dll | X | rundll32.exe [path] WinFlyer32.dll | Detected by Trend Micro as TROJ_AGENT.NFD. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "WinFlyer32.dll" file is found in %System% | No |
| winhelp | X | rundll32.exe [path] winhelp.dll,get | Added by the MDROP-DCW TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "winhelp.dll" file is found in %System% | No |
| wmdnte | X | rundll32.exe [path] wmdnte.dll | Detected by Malwarebytes Anti-Malware as Trojan.Medfos. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wmdnte.dll" file is located in %AppData% | No |
| TactXCI | X | rundll32.exe [path] wmshlp.dll | Detected by Symantec as Infostealer.Proxydown and by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wmshlp.dll" file is located in %AppData%\Microsoft\CommonFiles | No |
| THXAudio | X | rundll32.exe [path] wmshlp.dll | Detected by Dr.Web as Trojan.DownLoader6.40916 and by Malwarebytes Anti-Malware as Trojan.Proxy. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wmshlp.dll" file is located in %CommonAppData%\MSICRD | No |
| NvCplDaemonTool | X | rundll32.exe [path] wtload08.dll,_IWMPEvents | Added by the SINOWA-GEN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wtload08.dll" file is located in %System% and %UserProfile% | No |
| byvtroaudio | X | rundll32.exe [path] wvtsrs.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wvtsrs.dll" file is located in %System% | No |
| gebawtaudio | X | rundll32.exe [path] wvtsrs.dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "wvtsrs.dll" file is located in %System% | No |
| lpc | X | rundll32.exe [path] zxvd32.dll | Added by the BANKSUN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "zxvd32.dll" file is located in %AppData%\Sun | No |
| svchost64 | X | rundll32.exe [path] [12 hex characters].dll | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this entry loads from the Windows Startup folder and rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The DLL file is located in %Temp% | No |
| Network | X | rundll32.exe [path] [dropped DLL] | Added by the CYXORP TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Disker | X | rundll32.exe [path] [name].DLL | Detected by Dr.Web as Trojan.PWS.Wow.2045 and by Malwarebytes Anti-Malware as Trojan.Onlinegames. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The DLL file is typically found in %Temp% | No |
| Egiciwuvubom | X | rundll32.exe [path] [random name].dll | Detected by Sophos as W32/AutoRun-BHY. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The DLL file is located in %Windir% | No |
| GPLv3 | X | rundll32.exe [path] [random name].dll | Detected by Microsoft as Win32/Vundo. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| MemoryManager | X | rundll32.exe [path] [random name].dll | Detected by Microsoft as Win32/Vundo. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| SLDT | X | rundll32.exe [path] [random].cpl | Detected by Microsoft as TrojanDownloader:Win32/Bebeber.A and by Malwarebytes Anti-Malware as Spyware.Password. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].cpl" file is located in %Temp% | No |
| JavaSoft | X | rundll32.exe [path] [random].dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent.JSGen. Note - this entry loads from the Windows Startup folder and rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The DLL file is located in %LocalAppData%\JavaSoft | No |
| Pwulinubesida | X | rundll32.exe [path] [random].dll | Detected by Malwarebytes Anti-Malware as Trojan.Agent.HL. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The DLL file is located in %Windir% | No |
| Apple | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Backup | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Directx | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Display | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No | |
| Intel | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Java | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Keyboard | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Manager | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Microsoft | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Mouse | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Notifier | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Policy | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Profile | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Service | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Tray | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Update | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Verifier | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Windows | X | rundll32.exe [path] [random].dll,DllRegisterServer | Detected by Microsoft as Trojan:Win32/Tracur.AK and by Malwarebytes Anti-Malware as Trojan.SHarpro. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %AppData%\[folder name]\[folder name] | No |
| Rundll | X | rundll32.exe [random filename].dll | Added by the MYTOB.IG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System% | No |
| winupd | X | RUNDLL32.EXE [random value].dll,_mainRD | Added by the MOTA.A WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %Windir% | No |
| winupdt | X | RUNDLL32.EXE [random.dll] | Detected by Kaspersky as Email-Worm.Win32.Mabutu.a and by Malwarebytes Anti-Malware as Trojan.Downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %Windir% | No |
| mlkkhesys | X | rundll32.exe [random].dll | Added by the MDROP-CPA TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" file is found in %System% | No |
| MSServer | X | Rundll32.exe [random].dll,#1 | Unidentified malware! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The file is typically found in either %System% or the %UserTemp% folder | No |
| Remote System Protection | X | rundll32.exe [random].dll,HUI_proc | Detected by Microsoft as Trojan:Win32/Ertfor.B. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random].dll" is located in %System% | No |
| yahoo! | X | rundll32.exe [random]don.dll,Set | Detected by Trend Micro as TROJ_AGENT.HOZZ. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "[random]don.dll" file is found in %UserTemp% | No |
| winabc | X | rundll32.exe [Temp]\[ORIGFILENAME].DLL,InstallLaunchEv | Added by the LINEAGE-PN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted | No |
| Windows Security Assistant | X | rundll32.vbe | CoolWebSearch Alfasearch parasite variant - also detected as the STARTPA-U TROJAN! | No |
| stlbdist | X | rundll32exe stlbdist.dll,DllRunMain | Hijacker pointing to www.searchandclick.com | No |
| xccinit | X | rundll33.exe xccdf16_090131a.dll | Added by the BUZUS-AD TROJAN! Note - the "rundll33.exe" file is located in %System%\inf and the "xccdf16_090131a.dll" file is located in %Windir% | No |
| xccinit | X | rundll33.exe xccdf16_090305a.dll | Added by the BUZUS-AF TROJAN! Note - the "rundll33.exe" file is located in %System%\inf and the "xccdf16_090305a.dll" file is located in %Windir% | No |
| Microsoft Install Shield Services | X | rundll64 | Added by the RBOT-FSH WORM! | No |
| Rundll64 | X | Rundll64 | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| MSConfigs | X | RUNDLL64.dll.vbs | Added by the WEKODE-B WORM! | No |
| rundll32 | X | rundll64.exe | Added by the DELF.BKC TROJAN! | No |
| Windows Running DLL Service | X | rundll64.exe | Added by the SLENFBOT.HV WORM! | No |
| Mircrosoft Windows Config DLL | X | rundllc32b.exe | Added by the RBOT-ZY WORM! | No |
| PowerManagement | X | Rundlll.exe | Added by the SURDUX TROJAN! | No |
| RundllQQ32 | X | RundllQQ32.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %Windir%\inf | No |
| Microsoft Windows Update | X | rundlls.exe | Added by the HABRACK WORM! | No |
| Rundllsystem32 | X | Rundllsystem32.exe | Added by the NETDEVIL.B BACKDOOR! | No |
| Run05 | X | rundll_32.exe | Added by the BANCOS-DT TROJAN! | No |
| Rundll | X | Rundll~.exe | Added by the DELF-KT TROJAN! | No |
| RUNDNB | X | Rundnb.exe | Added by the DIALER-C dialler! | No |
| Rundnm | X | Rundnm.exe | Added by the DELF-HA TROJAN! | No |
| MICROSOFTSECURITYUPDATEAGENT | X | rundrv32.exe | Detected by McAfee as RDN/Spybot.bfr!d and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| AdobeManager | X | rundtl.exe | Added by the INJECT.IB TROJAN! | No |
| Microsoftf DDEs ContDLL | X | rune.pif | Added by the RBOT-AGF WORM! | No |
| system32 | X | runescape.exe | Added by the AGENT-XB MALWARE! | No |
| fc | X | runfc.exe | Added by the CAMPURF WORM! | No |
| Java Runtime Value | X | runjava.exe | Added by the RBOT-DDJ WORM! | No |
| chope | X | runlli32.exe | Added by the QQPASS-U TROJAN! | No |
| HKEYok | X | runlli32.exe | Added by the QQPASS-U TROJAN! | No |
| Regexit | X | runlli32.exe | Added by the QQPASS-U TROJAN! | No |
| Rundil32 | X | runlli32.exe | Added by the QQPASS-U TROJAN! | No |
| [various names] | X | runload32.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Microsoftf DDEs ContrDL | X | runm.pif | Detected by Sophos as W32/Rbot-AFQ | No |
| NumLock | X | runme.exe | Added by the DELF-IO WORM! | No |
| Open2Enter | X | runme.exe | First2Enter - Switch dialer and hijacker variant, see here | No |
| Open2Enter | X | runme2.exe | First2Enter - Switch dialer and hijacker variant, see here | No |
| KODAK Software Updater | N | runner.exe | Software updater for Kodak products - automatically detects an internet connection and downloads any available updates | No |
| OLEDb Service | X | runoledb32.exe | Added by the SPYRE.B TROJAN! | No |
| mdac_runonce | N | runonce.exe | Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe". | No |
| RunOnce | U | RUNONCE.EXE | Part of MS Data Access Components - only required if you use these | No |
| Runonce | X | runouce.exe | Added by the CHIR-B WORM! | No |
| Paperport | N | runppdrv.exe | Loads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see here | No |
| PCDrProfiler | U | RunProfiler.exe | Part of PC Doctor software installed for some machines. Disabling or enabling it is down to your preference | No |
| zxcd | X | runr.exe | Detected by Dr.Web as Trojan.DownLoader6.46754 and by Malwarebytes Anti-Malware as Trojan.Yoddos | No |
| Microsoftf DDos Contr0l | X | runs.pif | Detected by Sophos as W32/Rbot-AMH | No |
| LicCtrl | Y | runservice.exe | Part of the eLicense Copy Protection scheme employed by some software and games. If it is not running the eLicense wrapper is unable to extract and execute the program. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| Micosoft Data Core | X | runservice.exe | Detected by Trend Micro as WORM_IRCBOT.BK | No |
| runsql | X | runsql.exe | Added by the DELF.ZWK TROJAN! | No |
| Adware.Srv32 | X | runsrv32.exe | Detected by Trend Micro as TROJ_RENOS.AV | No |
| Srv32 spool service | X | runsrv32.exe | Topantispyware adware | No |
| runsvc | X | runsvc.exe | Added by the SMALL-CF TROJAN! | No |
| RunServices | X | runsvc32.exe | Detected by Trend Micro as WORM_AGOBOT.QJ | No |
| RunSysd32 | U | RunSysd32.exe | DesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within | No |
| setupa | X | runt32.exe | Added by the QQPASS-K TROJAN! | No |
| runtime.exe | X | runtime.exe | Added by a variant of the Tibs malware | No |
| smrtdrv | X | runtime.exe | Detected by Sophos as W32/Agobot-MN | No |
| RunTray | U | RunTray.exe | Detected by Malwarebytes Anti-Malware as HackTool.DDoS. The file is located in %System% | No |
| runwin32 | X | runwin32.exe | Added by the ESEARCH-A TROJAN! | No |
| Windosupdate manager | X | runwin32.exe | Added by the SDBOT.NNS BACKDOOR! | No |
| startkey | X | RunWinRaR.exe | Added by a variant of the BIFROSE-LV TROJAN! | No |
| preload | N | RUNXMLPL.exe | Software found on Acer computers from Wistron. Information suggests it maps keyboard buttons to operating system functions | No |
| Classes | X | run_21.exe | First2Enter - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-A TROJAN! | No |
| Open2Enter | X | run_21.exe | First2Enter - Switch dialer and hijacker variant, see here | No |
| Run_cd | X | Run_cd.exe | Added by the GHOST.23 BACKDOOR! | No |
| MSTask | X | run_dll.exe | Yuupsearch adware | No |
| Rupsw32 | U | Rupsw32.exe | MegaTec Rups, UPS monitoring software - monitor and control DB9 UPS running on either Windows & Novell NetWare (with RUPS 2000) or Unix (with RUPS for Unix / Plus) operating systems | No |
| NAV | X | RuxDLL32.exe | Added by the MAPSON.D WORM! | No |
| Remote Access Adapter | X | rvasvc.exe | Added by the IRCBOT.BIF BACKDOOR! | No |
| RVCHOST.EXE | X | Rvchost.exe | Added by the DELF-AC BACKDOOR! | No |
| AdobeReaderPro | X | rvdjlefr.exe | Added by the RBOT-CQZ WORM! | No |
| Yahoo Messengger | X | RVHIOST.exe | Added by the SOHANNA-AC WORM! | No |
| Yahoo Messengger | X | RVHOST.exe | Added by the SILLYFDC-G WORM! | No |
| Windows LoL Layer | X | rvinfjz.exe | Added by the KOLAB.FXX WORM! | No |
| updmgr | X | rvupdmgr.exe | KeenVal adware | No |
| [14 random numbers] | X | rwg.exe | Green AV rogue security software - not recommended, removal instructions here. The most common entry has the number 03874569874596 | No |
| rwo | X | rwo.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.Kkore. The file is located in %Windir% | No |
| Soar | X | Rwon.exe | PurityScan adware | No |
| Remote Access Tool | X | rwosvc.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Ussi | X | rwsa.exe | PurityScan adware | No |
| WNSI | X | rwsa.exe | PurityScan adware | No |
| {**-**-**-**-**} | X | rwwnw64d.exe | ZenoSearch adware variant where ** are random characters | No |
| DW_Start | X | rwwnw64d.exe | ZenoSearch adware variant | No |
| Microsoft Update Machine | X | rxhost.exe | Added by the RBOT.FC WORM! | No |
| RoxioAudioCentral | N | RxMon.exe | Part of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. "Includes a player, media manager, ripper, tag and sound editor - integrated in a single application". Not required for Roxio to work properly. | No |
| RxMon | N | rxmon9x.exe | Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail" | No |
| RxUser | N | RxUser.exe | Part of Dell Resolution Assistant - "a diagnostic program that allows you to contact Dell. When factory-installed by Dell, it allowed you to perform hardware and software diagnostics that provided alerts to potential problems and enabled real-time communication with Dell RA techs. You can now use RA only to contact Dell by e-mail" | No |
| Microsoft Update DLL | X | rxxhost.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Microsoft Update Machine | X | rxxhost.exe | Added by the RBOT.EP WORM! | No |
| rydanmxe.exe | X | rydanmxe.exe | Added by the DLOADR-AZZ TROJAN! | No |
| ryiixhp | X | ryiixhp.exe | Added by the IRCBOT-ABR BACKDOOR! | No |
| rysvizqopyni | X | rysvizqopyni.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| Rytcuyyuvnfwmnwh.exe | X | Rytcuyyuvnfwmnwh.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeAdobe. The file is located in %AppData% | No |
| SB13mini | X | RYZO32.EXE | Added by the SPYBOT-EJ WORM! | No |
| rz.scr | X | rz.scr | Added by the SILLYFDC-AY WORM! | No |
| MSConfig | X | rzbt.exe | Detected by McAfee as PWS-FAGF!7D599D3A541A and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Winds Sersc Agts | X | rzrzncrtz.exe | Added by the RBOT-GTV WORM! | No |
| Razer Synapse | U | RzSynapse.exe | Razer Synapse - "is a groundbreaking application that instantly stores your custom settings and Razer add-ons online in the cloud and lets you retrieve them at will from any location. It completely eliminates the painstaking reconfiguration process and lets you spend more time dominating the competition" | No |
| Windows Device Installer | X | rzzvwcjiy.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeChrome. The file is located in %CommonFiles%\Windows Device Installer.{GUID} | No |
| R_server | Y | r_server.exe | Radmin - remote admistrator server. Note - the file is located in %ProgramFiles%\Radmin | No |
| r_server | X | r_server.exe | Added by the HACDEF-DR TROJAN! Note - do not confuse with the valid Radmin file with the same name which is located in %ProgramFiles%\Radmin. This one is located in %System% | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
| Privacy Policy | Site Map | Home |