| Status | Autorun name | Command | Description |
| U | Referee | referee.exe | MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run |
| U | Reflex Vision | ReflexVision.exe | Reflex Vision from Increment Software. "A background application for Windows XP that makes switching windows faster and easier" |
| N | Refresh | Refresh.exe | (Iomega) Refresh - loads the Iomega desktop icons at startup |
| X | Reg | Reg.hta | Passon homepage hi-jacker |
| ? | Reg Check | lpt.exe | Related to Supanet ISP software - what does it do and is it required? |
| X | Reg Service | winsy.exe | Added by a variant of the SPYBOT WORM! |
| X | Reg Service | winslogon.exe | Added by the AGOBOT-SC WORM! |
| X | Reg Service | ipcfg.exe | Added by the AGOBOT-SO WORM! |
| X | Reg Service | REGSRV32.EXE | Added by the RBOT.ZW WORM! |
| X | Reg Service | WinnConfig.exe | Added by the AGOBOT-PF WORM! |
| X | Reg Service | NT32.exe | Added by the AGOBOT.G BACKDOOR! |
| X | Reg Services | Winboot32.exe | Added by the RBOT.PB WORM! |
| X | Reg Tool | Reg Tool.exe | RegTool rogue registry cleaner - not recommended, removal instructions here |
| X | reg_key | FUKULAMER.exe | Added by the BEAGLE.AH WORM! |
| X | reg_key | loader_name.exe | Added by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS! |
| X | reg_run | Systen.exe | Added by the BANCOS-BS TROJAN! |
| X | reg_run | [path to trojan] | Added by the BANKER-BQ TROJAN! |
| X | Reg_WFT | Regsysw.com | Added by the WILSEF VIRUS! |
| X | Reg_WFT | scanreg32.com | Added by the SENNASPY-F TROJAN! |
| X | Reg_WFT | Regsysw.exe | Added by the WILSEF.A WORM! |
| X | reg1.reg | vuamgard.exe | Added by a variant of the IRCBOT TROJAN! |
| U | reg2.0 | SVCH0ST.EXE | eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase "o" |
| X | Reg32 | Reg32.exe | Hijacker - redirecting to only-virgins.com |
| X | reg32 | reg32.exe | Added by the NOUPDATE.B TROJAN! |
| X | Reg32 | reg33.exe | CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN! |
| U | RegBar | regsvr32.exe bocaitoolbar.dll | BocaiToolbar adware. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "bocaitoolbar.dll" file is found in %ProgramFiles%\blogmark |
| X | Regcheck | ~CAB001.EXE | Added by the CYBRSPY.13A or CYBRSPY.13B BAKCDOORS! |
| X | regcheck | [path to file] | Added by the SERVPAM TROJAN! |
| X | RegClean | RegClean.exe | RegClean rogue registry cleaner - not recommended |
| U | RegClean Expert Scheduler | RCHelper.exe | "Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free" |
| U | RegClean Expert Scheduler | RCScheduler.exe | "Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry, your system will run faster and error free" |
| X | RegCleaner | SYSio32.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - do not confuse this with the popular RegCleaner registry cleaner freeware |
| X | RegCompres | Regcpm32.exe | Added by the POLDO.B TROJAN! |
| X | RegCompres | REGCPM32.EXE | Added by the DASMIN-E TROJAN! |
| X | Regcxdinaf | REGCXDINAF.EXE | Added by the BANCOS-BW TROJAN! |
| X | Regcxmarq | REGCXMARQ.EXE | Added by the BANCOS.DK TROJAN! Note that the filename has a leading space, ie, " REGCXMARQ.EXE" |
| X | Regcxn | Regcxn.exe | Added by the COIBOA-D TROJAN! |
| U | regdefend | regdefend.exe | "RegDefend is a configurable, kernel based registry protection system, designed to intercept selected changes before they occur, thus also preventing malicious software like viruses, trojans and worms from using the registry to their advantage" |
| X | regdiit | winxp.exe | Added by the RUNAUTO.F WORM! |
| X | regdiit | win.exe | Added by the VBSAUTO-A WORM! |
| X | RegDone | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | RegDone | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| X | RegDone Ex | csrss.exe | Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup! |
| X | RegDoneEx | lsass.exe | Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup! |
| X | regedit | regedit.exe | Added by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in %Windir$ and will not figure in Msconfig/Startup! This version resides in %System% |
| X | REGEDIT | Regsrv32.com | Added by the SOUTHGHOST WORM! |
| X | regedit | autoexe.exe | Added by a variant of the RBOT WORM! |
| X | regedit | svchost.exe ccRegVfy | Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is also located in %System% but has a space at the beginning of the filename |
| X | regedit | regedit.exe | Added by the GANBATE.A WORM! Note that the legitimate Windows registry editor (regedit.exe) is located %Windir% and will not figure in Msconfig/Startup! This one is located in %Windir%\security\Database |
| X | Regedit | regedits.exe | Added by the BANCBAN-QV TROJAN! |
| X | RegEdit32 | RegEdit32.exe | Added by the VOUMIT-A WORM! Note - this is not the legitimate regedit32.exe application which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a "mirc32" folder |
| X | Regedit32 | regedit.exe | Added by the MDROP-CMO TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System% |
| X | Regexit | runlli32.exe | Added by the QQPASS-U TROJAN! |
| X | Regexit | Updadv.exe | Added by the QQPASS-N TROJAN! |
| X | RegFreeze | regfreeze.exe | RegFreeze rogue spyware remover - not recommended, removal instructions here |
| X | reggsdg | spoolserv.exe | Added by the SDBOT-MS WORM! |
| X | reggsdg | spoolsrv.exe | Added by the SDBOT-DI WORM! |
| U | RegHelp | svchosts.exe | SpyGraphica spy software - "Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world." |
| X | reghost | reghost.exe | SpyPal surveillance software. Uninstall this software unless you put it there yourself |
| X | RegiFast | RFManager.exe | RegiFast adware |
| ? | reginfo32 | reginfo32.exe | ?? |
| X | Regional Value | isng.exe | Added by the SDBOT-OW WORM! |
| U | REGIST~1 | REGIST~1.EXE | Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
| X | Register Manager | RegistryManage.exe | Added by the SDBOT.AYH WORM! |
| N | Register MediaRing Talk | register.exe | If you don't want to register MediaRing and be reminded about it every bootup disable it |
| ? | Register SeqChk | regsvr32.exe ..csseqchk.dll | ?? |
| U | RegisterDropHandler | REGIST~1.EXE | Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation |
| X | Registration Service | toker.exe | Added by the SDBOT-BB WORM! |
| X | Registration Service | msvdm6.exe | Added by the SDBOT-HE TROJAN! |
| N | Registration-Studio 8 | RegTool.exe | Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems |
| X | Registry | wscript.exe ShakiraPics.jpg.vbs | Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "ShakiraPics.jpg.vbs" file is located in %Windir% |
| U | Registry | class0117[random].exe | Blackbox captures emails and chat logs, and monitors Internet activity - remove if you didn't intentionally install it |
| X | Registry Checker | Regrun.exe | Added by the SDBOT TROJAN! |
| X | Registry Checkup | winreg.exe | Added by an unidentified WORM or TROJAN! |
| X | Registry Checkup System326a Monitor | Winregs326a.exe | Added by a variant of the SDBOT WORM! |
| X | Registry Cleaner | Regclean.exe | Registry Cleaner misleading security software - not recommended, see here |
| X | Registry Integrity Checker | regintmon.exe | Added by a variant of the AGOBOT/GAOBOT WORM! |
| X | Registry Integritycheck | WCPDT.EXE | Added by the AGOBOT-RF WORM! |
| X | Registry Loader | regloadr.exe | Added by the GAOBOT.AO WORM! |
| X | Registry Loader | winhlpp32.exe | Added by the GAOBOT.AO WORM! |
| N | Registry Mechanic | RegMech.exe | Part of Registry Mechanic from PC Tools - which "is an advanced registry cleaner for Windows that can safely clean, repair and optimize your registry in a few simple mouse clicks!". This entry is created when Registry Mechanic is installed on XP and loads the System Tray icon and runs a registry scan at startup - if either are enabled. Run manually at regular intervals |
| N | Registry Mechanic Vista Tray | RMTray.exe | Part of Registry Mechanic from PC Tools - which "is an advanced registry cleaner for Windows that can safely clean, repair and optimize your registry in a few simple mouse clicks!" This entry is created when Registry Mechanic is installed on Vista and loads the System Tray icon (RegMech.exe) and runs a registry scan at startup - if either are enabled. Run manually at regular intervals |
| X | Registry Monitor | regmon.exe | Added by the BCKDR-QKH BACKDOOR! |
| X | Registry oidet | win32.exe | Added by the RBOT.BMT WORM! |
| X | Registry Protector | regprotect.exe | Added by the ARIVER.A WORM! |
| X | Registry Scanner | regscanr.exe | Added by a variant of the OPTIX TROJAN! |
| X | Registry Serv | regsvr.exe | Added by the WEBMONEY-G TROJAN! |
| X | Registry Server | regsrv32.exe | Added by the RBOT-GM WORM! |
| X | Registry Server | regserv.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Registry Service | regsvc.exe | Added by the IRCBOT-ZM BACKDOOR! |
| X | Registry Service | REGSRV32.EXE | Added by a variant of the RBOT WORM! |
| X | Registry Service | resvs.exe | Added by the DELBOT-I WORM! |
| X | Registry Services | Registry.exe | Added by the CILE TROJAN! |
| X | Registry Startup Check | checkreg.exe | Added by the REMLOAD-A or DANMEC-B TROJANS! |
| X | Registry System | Regsys.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Registry System16 Checkup Monitor | SystemReg16.exe | Added by the RBOT.AGD WORM! |
| X | Registry System166 Checkup Monitor | SystemReg166.exe | Added by the RBOT.ATN WORM! |
| X | Registry Value Name | roses.exe | Added by the RBOT-AFT WORM! |
| X | Registry Value Name | service.exe | Added by the RBOT-AHT WORM! |
| X | Registry Value Name | winapi32.exe | Added by a variant of the RBOT WORM! |