| Status | Autorun name | Command | Description |
| U | RDClient | RDCLIENT.EXE | Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection |
| U | rdirector | [path to adware] | Redir adware |
| X | RDListener | RDListener.exe | RegDefense rogue registry cleaner - not recommended |
| X | RDLL | RunDll16.exe | Added by the SDBOT.F TROJAN! |
| U | RDM+ Control Panel | rdmpserv_cpanel.exe | Remote Desktop for Mobiles - "Access remotely your computer even through NAT and Firewall from mobile. You can send and receive emails, edit word documents, surf web, manage files and folders and do hundreds of other things that you usually do sitting in front of your home or office computer" |
| X | RDPlatinum v5 | RDPlatinumv5.exe | Registry Defender Platinum rogue registry cleaner - not recommended, removal instructions here |
| X | rdvs | [worm filename] | Added by the ULTIMAX.B WORM! |
| U | RE.exe | RE.exe | RegistryEasy registry cleaner - regarded by Symantec as a potentially unwanted application, see here |
| X | Reactor3 | [random name]32.exe | Added by the BOFRA.A WORM! |
| X | Reactor5 | [random name]32.exe | Added by the BOFRA.D WORM! |
| X | Reactor6 | [random name]32.exe | Added by the BOFRA.C WORM! |
| X | Reactor7 | [random name]32.exe | Added by the BOFRA.B WORM! |
| X | Reactor8 | [random name]32.exe | Added by the BOFRA.E WORM! |
| X | Reactor9 | [random name]32.exe | Added by the BOFRA.E WORM! |
| X | readdb40 | rundll32.exe readdb40.dll, EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "readdb40.dll" file is found in %System% |
| X | reader_s | reader_s.exe | Added by the AGENT-IUT TROJAN! |
| N | Reader_sl | Reader_sl.exe | Speeds up the time it takes to load the free Adobe Reader PDF file viewer. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Adobe Reader to function properly |
| U | readericon | readericon45G.exe | Tray icon to set various configuration settings for Sunkist (and maybe other) media card readers |
| ? | readericon10 | readericon10.exe | Related to a multimedia card reader - possibly based upon an Alcor Micro chipset. What does it do and is it required? |
| N | REAL | realjbox.exe | Real Jukebox - MP3 and music files player |
| X | Real Internet Player | Reaiplay.exe | Added by a variant of the SPYBOT WORM! |
| X | Real Media Player | realplayer2.exe | Added by a variant of the RBOT WORM! |
| X | Real player updater | realupd.exe | Added by the PARLAY TROJAN! |
| X | real scheduler.hta | RealAudio.exe | Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player |
| U | Real Spy Monitor | Winrsm.exe | Realspy keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | Real Statics Agent | ccreal.exe | Added by a variant of the RBOT WORM! |
| X | Real-Tens | Real-Tens.exe | DownloadWare adware |
| X | RealAudio | RealAudio.exe | Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player |
| X | Realaudio Player | realaudio32.exe | Added by the AGOBOT.AFR WORM! |
| X | RealAV.exe | RealAV.exe | Real Antivirus rogue security suite - not recommended, removal instructions here |
| N | RealDownload | RealPlay.exe | Download manager. Available via Start -> Programs |
| X | RealDownload Express | npnzdad.exe | Advertising spyware |
| N | Reality Fusion GameCam SE | RFTRay.exe | Reality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs |
| N | RealJukeboxSystray | tsystray.exe | System Tray icon for RealJukebox |
| X | realone_nt2003 | moniker.exe | Added by the SNONE.A WORM! |
| X | RealP1ayer | [path to file] | Added by the RPLAY.A TROJAN! Note that the name has a number "1" in place of the second lower case "L" |
| N | realplay | realplay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
| X | realplay lptt01 | realplay.exe | RapidBlaster variant (in a "realPlay" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not RealPlayer which can have the same executable name |
| X | realplay ml097e | realplay.exe | RapidBlaster variant (in a "realPlay" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not RealPlayer which can have the same executable name |
| N | RealPlayer | realplay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
| X | RealPlayer Ath Check | rnathchk.exe | Added by the MYTOB.AG WORM! |
| X | RealPlayer Ath Check | mathchk.exe | Added by the MYDOOM-AJ WORM! |
| X | Realplayer Codec Support | realsched.exe | Added by the AGOBOT-AAD WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
| X | Realplayer One | realplay.exe | Added by the RBOT-NK WORM! |
| X | Realplayer Video | RealPlay.exe | Added by a variant of the RBOT WORM! |
| X | Realplayer.exe | Realplayer.exe | Added by the DELF.CNV TROJAN! |
| N | RealPlayer2 | MsgCenterExe | RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way |
| X | RealPlayerUpdater | realupd32.exe | Added by the LOHAV-T TROJAN! |
| ? | Realpopup | Realpopup.exe | RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor" |
| N | Realsched | realsched.exe | Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry |
| U | RealSPEED | RealSPEED.Exe | RealSPEED - tweaking utility to speed-up your internet connection |
| U | Realtek AC97 Audio - Event Monitor | ALCMTR.EXE | Realtek Azalia Audio - Event Monitor, installed with the XP/2K drivers for on-board Realtek HD audio codecs. Some users believe that Realtek uses this file in order to gather data about the customer but it's exact purpose is unknown and it doesn't run on an ALC885 based test system or try to access the internet. Some users report problems with their on-board sound if this is disabled - hence the "U" recommendation |
| N | Realtek HD Audio Manager | RAVCpl64.exe | Realtek HD Audio Manager, installed with the 64-bit Vista/7 drivers for on-board Realtek HD audio codecs. Unless you have the default (but optional) System Tray icon enabled, the only purpose this entry serves is to detect and allow you to configure any devices plugged into the jacks - such as headphones and a microphone. With the System Tray icon enabled it will also inform you when devices are removed and give you access to the Sound Manager and other multimedia functions. The Sound Manager is also available via the Control Panel and this entry is therefore only required if you regularly change sound schemes |
| N | Realtek HD Audio Manager | RtHDVCpl.exe | Realtek HD Audio Manager, installed with the Vista/7 drivers for on-board Realtek HD audio codecs. Unless you have the default (but optional) System Tray icon enabled, the only purpose this entry serves is to detect and allow you to configure any devices plugged into the jacks - such as headphones and a microphone. With the System Tray icon enabled it will also inform you when devices are removed and give you access to the Sound Manager and other multimedia functions. The Sound Manager is also available via the Control Panel and this entry is therefore only required if you regularly change sound schemes |
| N | Realtek HD Audio Sound Effect Manager | RTHDCPL.EXE | Realtek HD Audio Control Panel, installed with the XP/2K drivers for on-board Realtek HD audio codecs. Unless you have the default (but optional) System Tray icon enabled, the only purpose this entry serves is to detect and allow you to configure any devices plugged into the jacks - such as headphones and a microphone. With the System Tray icon enabled it will also inform you when devices are removed and give you access to the Sound Manager and other multimedia functions. The Sound Manager is also available via the Control Panel and this entry is therefore only required if you regularly change sound schemes |
| U | Realtek HD Sound Manager | SOUNDMAN.EXE | Realtek Sound Manager, installed with the drivers for on-board Realtek HD audio codecs. On an ALC885 based test system it doesn't run after the drivers have been installed and the startup entry is then removed. Disabling it appears to have no ill effects but it's exact purpose is unknown - hence the "U" recommendation |
| X | Realtek Sound Manager | Tecompntwx.exe | Added by a variant of the IRCBOT BACKDOOR! |
| U | Realtek Voice Manager | Skytel.exe | Realtek Voice Manager, installed with the drivers for on-board Realtek HD audio codecs. On an ALC885 based test system it doesn't run after the drivers have been installed and the startup entry is then removed. Disabling it appears to have no ill effects but it's exact purpose is unknown - hence the "U" recommendation |
| U | Realtime Audio Engine | mmrtkrnl.exe | Associated with ALCATech BPM Studio |
| Y | Realtime Monitor | realmon.exe | Real-time scanner part of the now discontinued eTrust Antivirus/InoculateIT version 6 virus scanners from CA |
| X | RealTimeProtector | winlogon.exe | Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder |
| ? | RealTimeUpdate | RealTimeUpdate.exe | Product description in properties is "InternetExplorerCommunicationAgent Module" ? |
| X | realtpsk | realsched.exe | Chinese originated adware - detected by Panda as NewWeb. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name and this file is located in %System% |
| N | RealTray | RealPlay.exe | System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences |
| X | RealUpdater | realupd.exe | Added by the PARLAY or MITGLIEDER.I TROJANS! |
| X | RealVaccineMain | RealVaccine.exe | RealVaccine rogue security software - not recommended, removal instructions here |
| X | REAnti.exe | REAnti.exe | REAnti rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | RebateNation0 | RebateNation0.exe | RebateNation adware |
| N | Reboot | Reboot.exe | MS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards |
| U | Receiver | PcfaxRcv.exe | Incorporated on multifunction digital copiers (such as the MX-3500NM), Sharp's innovative PC fax driver enables users to send fax documents right from their desktop |
| Y | Recguard | recguard.exe | On HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense |
| X | Recguard | recguard.exe | Added by the LAZAR.B TROJAN! Note - this is not the legitimate HP recovery partition utility with the same filename which is located in %Windir%\SMINST. This one is located in %ProgramFiles%\HP |
| N | Reclip | reclip.exe | Reclip Popup Clipboard manager |
| U | Reclusa | razerhid.exe | Microsoft Reclusa (by Razer) gaming keyboard driver - required if you use the additional features and programmed keys/macros |
| X | Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} | RH.DLL | SmartPops search hijacker |
| N | RecordNow | RecordNow.exe | RecordNow! CD-writing utility from Sonic Solutions |
| N | Recorte de tela e Iniciador do OneNote 2007 | ONENOTEM.EXE | System Tray access to MS Office OneNote 2007 - an electronic notebook that allows you to create free-form notes, including text, graphics and audio/video. When running, ONENOTEM.EXE also enables the WINDOWS KEY combinations - such as WINDOWS KEY+N (new Side Note) and WINDOWS KEY+S (insert screen grab into a note). Leave the icon enabled in OneNote but move the shortcut from Start → All Programs → Startup to the desktop or elsewhere on the Start menu and run when needed. Portuguese version |
| N | Recover | N/A | Added during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete |
| X | recover.bmp.exe | Rundll.exe | Added by the ANAFTP-01 TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here |
| N | RecoverFromReboo | RECOVE~1.EXE | Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
| N | RecoverFromReboo | RecoverFromReboot.exe | Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
| N | RecoverFromReboot | RECOVE~1.EXE | Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
| N | RecoverFromReboot | RecoverFromReboot.exe | Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched, this entry may be left in the registry |
| X | Recoveru system | svchast.exe | Added by a variant of the LINEAGE-AV TROJAN! |
| X | Recoveru systems | svchost.exe | Added by the SMALL.DDX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp% |
| N | RecShe | RecSche.exe | Recording scheduler for WatchTV Capture Card (TV Tuner card) |
| X | Recycle | Recycle.exe | Added by the SCAR.BTHF TROJAN! |
| X | Recycle Bin Handler | recycler.exe | Added by the SHUCKBOT-A TROJAN! |
| X | Recycle Bin Handler 2005 | system.exe | Added by the BDOOR-HO BACKDOOR! |
| U | RecycleBinEx | RecycleBinEx.exe | RecycleBinEx by FTweak Inc - "a powerful and easy to use recycle bin manager for Windows Operating System. It extends and enhances the Windows recycle bin, and let you use many extra features in it" |
| X | Recycler | explored.exe | Added by the JORIK.ASD TROJAN! |
| X | Recycler DO NOT MODIFY | recyclecl.exe | Added by the RBOT.DDA WORM! |
| X | RecycleSTR | msreg32.exe | Added by the RBOT-TC WORM! |
| N | Red Flag | redflag.exe | PMS prediction program with modes for guys and girls - no longer available |
| U | Red Swoosh EDN Client | RSEDNClient.exe | Red Swoosh distributed networking software - a desktop client that enables users to download and stream files from each other, rather than from webservers |
| X | redirect | redirect*.exe | Dotcomtoolbar/Linksummary hijacker installer - where * is a random digit |
| N | Redline Taskbar | taskbar.exe | Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards |
| X | Reeg_ | [path to trojan] | Added by the BANCBAN-AW TROJAN! |
| X | REEGRUN | [path to file] | Added by the SECDROP.AI TROJAN |
| X | Reek 32 Server | reek32.exe | Added by the RANDEX.AL WORM! |